Group Purchasing
Group Purchasing

Phill Moore

Certified InstructorPrincipal Security Researcher at Microsoft

Specialities

Digital Forensics and Incident Response

Connect with Phill

Phill Moore

About Phill Moore

Whether providing evidence to prosecute an offender, stopping an attacker, or saving a business, Phill says that the impact his DFIR work has on people's lives makes it all feel worthwhile. He has extended his footprint through his research and his work as a SANS as FOR500: Windows Forensic Analysis and FOR528: Ransomware and Cyber Extortion course instructor.

"On a number of occasions, I've had people reach out to me to say that something I've shared or research I've done has helped them with a conviction, and that's really rewarding," Phill explains.

Throughout his career, Phill has analyzed digital evidence on thousands of devices - assisting in criminal and civil investigations, as well as all things threat hunting and incident response. Phill specialized in business email compromise and ransomware investigations and now works at Microsoft as a Principal Security Researcher.

Phill has also maintained the essential community and award-winning resource, This Week in 4n6, for over a decade; "I try to keep as close to the people pushing the industry forward as I can," he says. "We can all get better by encouraging our peers to document the research they're doing and share it to help the community validate and improve our understanding."

He is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition.

"The SANS DFIR curriculum is aggressively updated and provides an artifact-first, tool-agnostic approach that ensures people aren't relying on the output of their tools, especially when their tools only get them so far," he explains. "SANS courses encourage students to use the best tools for the job, and to go beyond them when they don't present all the information necessary for an investigation."

In his classes, Phill's goal is to help students become effective during their investigations by showing them how much can be achieved by combining free tools, great training, a solid understanding of the operating system/file system, and some grit.

"At the end of the day, you're responsible for your investigations," he notes. "There are a lot of great tools out there, but they all have their shortcomings."

He sees the biggest challenge for students as simply keeping up with the relentless pace of device, operating system, and application updates. "The number of devices and data sources is increasing, and being able to effectively cut through the noise to identify what happened on a system is key," he says.

To keep up with innovations, Phill encourages students to keep testing, training, learning, and sharing information. In this regard, he can draw on personal experience. During a former police investigation, Phill uncovered information on a suspect showing that the individual was committing other, very serious offenses that investigators were unaware of. In that case, Phill points to a combination of luck and persistence that identified passwords across devices and ultimately to an arrest and successful prosecution.

Phill has a bachelor's degree in business IT from the University of New South Wales, a postgraduate certificate in computer forensics from the University of South Australia, and a master's degree in cybersecurity (digital forensics) from the University of New South Wales.

Phill's research, including his repository of Business Email Compromise resources (Awesome-BEC) and Really Useful Logging and Event Repository (RULER) Project, can be found on his website, ThinkDFIR.

While Phill's primary interests revolve around forensics and family, he also likes all things superhero, from comic books to TV and movies, and stays active at the gym and on the soccer field. When he's not reading about superheroes or being a DFIR superhero in real life, he enjoys spending time with his wife and children and is constantly searching for more time to hone his guitar-playing skills.

Certifications
  • GIAC Certified Forensic Examiner (GCFE)
  • IACIS Certified Forensic Computer Examiner (CFCE)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Battlefield Forensics and Acquisition (GBFA)
  • Magnet Certified Forensics Examiner (MCFE)
  • GIAC Cloud Forensics Responder (GCFR)
  • GIAC Enterprise Incident Response (GEIR)
  • GIAC Experienced Forensic Analyst (GX-FA)
  • GIAC Experienced Forensics Examiner (GX-FE)
  • GIAC Penetration Tester (GPEN)
  • GIAC Security Professional (GSP)

Press & Media