Phill Moore
Certified InstructorPrincipal Security Researcher at Microsoft
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

Whether providing evidence to prosecute an offender, stopping an attacker, or saving a business, Phill says that the impact his DFIR work has on people's lives makes it all feel worthwhile. He has extended his footprint through his research and his work as a SANS as FOR500: Windows Forensic Analysis and FOR528: Ransomware and Cyber Extortion course instructor.
"On a number of occasions, I've had people reach out to me to say that something I've shared or research I've done has helped them with a conviction, and that's really rewarding," Phill explains.
Throughout his career, Phill has analyzed digital evidence on thousands of devices - assisting in criminal and civil investigations, as well as all things threat hunting and incident response. Phill specialized in business email compromise and ransomware investigations and now works at Microsoft as a Principal Security Researcher.
Phill has also maintained the essential community and award-winning resource, This Week in 4n6, for over a decade; "I try to keep as close to the people pushing the industry forward as I can," he says. "We can all get better by encouraging our peers to document the research they're doing and share it to help the community validate and improve our understanding."
He is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition.
"The SANS DFIR curriculum is aggressively updated and provides an artifact-first, tool-agnostic approach that ensures people aren't relying on the output of their tools, especially when their tools only get them so far," he explains. "SANS courses encourage students to use the best tools for the job, and to go beyond them when they don't present all the information necessary for an investigation."
In his classes, Phill's goal is to help students become effective during their investigations by showing them how much can be achieved by combining free tools, great training, a solid understanding of the operating system/file system, and some grit.
"At the end of the day, you're responsible for your investigations," he notes. "There are a lot of great tools out there, but they all have their shortcomings."
He sees the biggest challenge for students as simply keeping up with the relentless pace of device, operating system, and application updates. "The number of devices and data sources is increasing, and being able to effectively cut through the noise to identify what happened on a system is key," he says.
To keep up with innovations, Phill encourages students to keep testing, training, learning, and sharing information. In this regard, he can draw on personal experience. During a former police investigation, Phill uncovered information on a suspect showing that the individual was committing other, very serious offenses that investigators were unaware of. In that case, Phill points to a combination of luck and persistence that identified passwords across devices and ultimately to an arrest and successful prosecution.
Phill has a bachelor's degree in business IT from the University of New South Wales, a postgraduate certificate in computer forensics from the University of South Australia, and a master's degree in cybersecurity (digital forensics) from the University of New South Wales.
Phill's research, including his repository of Business Email Compromise resources (Awesome-BEC) and Really Useful Logging and Event Repository (RULER) Project, can be found on his website, ThinkDFIR.
While Phill's primary interests revolve around forensics and family, he also likes all things superhero, from comic books to TV and movies, and stays active at the gym and on the soccer field. When he's not reading about superheroes or being a DFIR superhero in real life, he enjoys spending time with his wife and children and is constantly searching for more time to hone his guitar-playing skills.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Join Josh and Phill as they discuss the latest trends, practical use cases, and the challenges of integrating AI into modern DFIR workflows.

Ransomware strikes an innocent virtual hard disk leaving its contents unrecoverable… or so we were told.

Ransomware strikes an innocent virtual hard disk leaving its contents unrecoverable… or so we were told.

近年、ランサムウェア攻撃は、個人や企業のみならず、重要インフラをも標的とする大きなな脅威へと進化しています。2023年はランサムウェアにとって大きな年であり、2024年もその勢いが衰えるとは考えられません。このプレゼンテーションでは、ランサムウェアの現状、攻撃時によく見られる手口やテクニック、2023年のランサムウェア攻撃への対応から得られた教訓を包括的にご紹介します。

In this engaging session, participants will have the opportunity to delve into the world of incident response alongside SANS Instructor Phill Moore.

This talk will explore some of the artefacts that, without the knowledge of the user, records more than just metadata.

Windows puts a lot into logs, but it puts even more into forensic artefacts you may not be aware of. This talk will explore some of the artefacts that, without the knowledge of the user, records more than just metadata. I think it's pretty cool, maybe after this talk you will do....or disable it all...or both?

Windowsのログには多くの情報が記録されていますが、それに加えてフォレンジックに活用できる様々なアーティファクトから情報を読み取ることができます。この講演では、ユーザーの知らない間に、単なるメタデータとは言い切れないような情報を記録しているアーティファクトをいくつかご紹介します。この講演を聞いたあと、あなたはキャッシュを無効にしますか?キャッシュの面白さを感じてもらえたら嬉しいです。
