• Episode 65: Cody Spooner, Senior Sales Engineer and IR expert, Corelight
    May 28 2026

    In this episode of the Endace Packet Forensic Files, Michael chats with with Cody Spooner, Principal Sales Engineer and DFIR expert at Corelight, about an interesting topic: the subtleties and differences of “Enablers" vs "Behaviors” of a cybersecurity compromise.

    Cody explains that when most people think of threat hunting or incident response investigations, they picture analysts looking for signs of malicious activity. In reality there are critical subtle differences between the “behavior of a compromise” and the underlying “enabler of a compromise” that often go unnoticed or overlooked. He highlights how organizations tend to focus heavily on detecting malicious behaviors - such as data exfiltration or unauthorized logins - but often miss identifying the enabling conditions - such as misconfigurations or legacy protocols - that led to those compromises in the first place.

    Cody shares examples of seemingly harmless issues that can become the doorway to a full compromise, such as configuration issues or outdated or deprecated protocols like NTLMv1 and SMBv1. These often persist in modern environments and Cody suggests that incident responders and threat hunters can usefully focus on identifying and eliminating these enablers to reduce the organisation's risk profile.

    Cody gives advice for security teams on how to shift their mindset from focusing only on behaviors to focusing on enablers as well in their threat hunting activity. He also provides insights into how IR teams should interpret and contextualize indicators of compromise and discusses how the “why” behind an attack can often change or influence the response strategy.

    ABOUT ENDACE
    *****************
    Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance.

    EndaceProbes are deployed on some of the world's largest, fastest and most critical networks. EndaceProbe models are available for on-premise, private cloud and public cloud deployments - delivering complete hybrid cloud visibility from a single pane-of-glass.

    Endace’s open EndaceProbe Analytics appliances (https://www.endace.com/endaceprobe) can be deployed in on-premise locations and can also host third-party security and performance monitoring solutions while simultaneously recording a 100% accurate history of network activity.

    Show More Show Less
    18 mins
  • Episode 65: Andrew Cook, CTO Recon InfoSec
    Mar 3 2026

    In this episode of the @Endace, Packet Forensic Files, Michael Morris chats with Andrew Cook, CTO of Recon InfoSec and host of the Thursday Defensive Podcast about Incident Investigation and Response, and Threat Hunting .

    Andrew has a wealth of experience in high-pressure cyberdefense environments and shares some of the key lessons he's learned along the way, as well as passing some great advice.

    This episode is a must-listen for cybersecurity professionals who want to learn more about the latest incident response and threat hunting tips, tools and techniques.

    ABOUT ENDACE
    *****************
    Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance.

    EndaceProbes are deployed on some of the world's largest, fastest and most critical networks. EndaceProbe models are available for on-premise, private cloud and public cloud deployments - delivering complete hybrid cloud visibility from a single pane-of-glass.

    Endace’s open EndaceProbe Analytics appliances (https://www.endace.com/endaceprobe) can be deployed in on-premise locations and can also host third-party security and performance monitoring solutions while simultaneously recording a 100% accurate history of network activity.

    Show More Show Less
    37 mins
  • Episode 64: Steve Fink, CTO and CISO at Secure Yeti
    Nov 7 2025

    In this episode of the @Endace, Packet Forensic Files, Michael Morris chats with Steve Fink, CTO and CISO of Secure Yeti and architect of the SOCs for Black Hat, RSA Conference, and Cisco Live, for an in-depth look at building effective Security Operations Centers (SOCs).

    With 26 years of cybersecurity experience, Fink shares strategies for leveraging packet data, integrating AI for automation, fostering vendor collaboration, and ensuring scalability and resilience.

    This expert-led discussion is a must-watch for cybersecurity professionals who want to learn how to optimize threat detection and avoid data swamps .

    ABOUT ENDACE
    *****************
    Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance.

    EndaceProbes are deployed on some of the world's largest, fastest and most critical networks. EndaceProbe models are available for on-premise, private cloud and public cloud deployments - delivering complete hybrid cloud visibility from a single pane-of-glass.

    Endace’s open EndaceProbe Analytics appliances (https://www.endace.com/endaceprobe) can be deployed in on-premise locations and can also host third-party security and performance monitoring solutions while simultaneously recording a 100% accurate history of network activity.

    CHAPTERS
    01:24 Why is your nickname 'Fink' and not Steve?
    02:17 What foundational, architectural principles are essential when designing a next-gen SOC?
    05:43 How do you approach scalability & modularity in NOC/SOC design to accommodate future growth?
    08:57 How have you evolved to integrate cloud native technology or hybrid environments into your SOC and what were the challenges?
    12:04 What role does packet data and centralized logging play in your SOC design and how do you ensure efficient data ingestion and retrieval?
    14:45 How do you architect SOC to support real time threat detection and response across geographically distributed global infrastructures?
    17:55 What strategies do you use for disaster recovery?
    20:35 How do you incorporate AI, ML and automation capabilities into your SOC architecture to enhance threat hunting?
    23:02 What are your best practices for integrating third-party tools?

    Show More Show Less
    26 mins
  • Episode 63: Jack Chan, VP of Product and Field CTO at Fortinet
    Oct 1 2025

    Why NDR is Evolving—And What Enterprises Should Demand From It

    In this episode of the @Endace Packet Forensic Files, Michael Morris is joined by Jack Chan, VP of Product and Field CTO at Fortinet, to unpack what makes a truly effective Network Detection and Response (NDR) solution. Jack shares his perspective on why visibility, historical context, and deep threat hunting capabilities matter more than flashy features.

    They explore how AI and machine learning are transforming NDR—helping detect threats in encrypted traffic and reduce alert fatigue for SOC teams. Jack also talks about integrating NDR with firewalls and EDR tools to improve response decisions and streamline investigations.

    Finally, Jack leaves us with a powerful reminder: security starts with people. From secure coding to user awareness, the human element is often the weakest link—and the best place to strengthen your defences.

    ABOUT ENDACE
    *****************
    Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance.

    EndaceProbes are deployed on some of the world's largest, fastest and most critical networks. EndaceProbe models are available for on-premise, private cloud and public cloud deployments - delivering complete hybrid cloud visibility from a 'single-pane-of-glass'.

    Endace’s open EndaceProbe Analytics appliances (https://www.endace.com/endaceprobe) can be deployed in on-prem locations and can also host third-party security and performance monitoring solutions while simultaneously recording a 100% accurate history of network activity.

    Show More Show Less
    25 mins
  • Episode 62: Jessica (Bair) Oppenheimer, Cisco's Director of Security Operations
    Aug 12 2025

    What does it take to run a world-class Security Operations Center (SOC) in today’s high-stakes, high-speed cybersecurity landscape?

    In this episode of the @Endace, Packet Forensic Files, Michael Morris chats with Jessica (Bair) Oppenheimer, Cisco's Director of Security Operations, for an in-depth look at next-generation Security Operations Centers (SOCs).

    Jessica shares her expertise from securing high-stakes events like the Paris 2024 Olympics, NFL Super Bowl, Black Hat, and RSAC Conference. Discover how her team leverages AI, full packet capture with EndaceProbes, and integrations with Cisco XDR and Splunk to combat AI-driven threats and ensure rapid detection and response.

    This episode is a must-listen for cybersecurity professionals who want to stay ahead of evolving threats. It is packed with insights on balancing automation with human expertise and key KPIs for SOC success.

    ABOUT ENDACE
    *****************
    Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance.

    EndaceProbes are deployed on some of the world's largest, fastest and most critical networks. EndaceProbe models are available for on-premise, private cloud and public cloud deployments - delivering complete hybrid cloud visibility from a single pane-of-glass.

    Endace’s open EndaceProbe Analytics appliances (https://www.endace.com/endaceprobe) can be deployed in on-premise locations and can also host third-party security and performance monitoring solutions while simultaneously recording a 100% accurate history of network activity.

    Show More Show Less
    28 mins
  • Episode 61: Jean-Pierre Bergeaux - Federal CTO, GuidePoint Security
    Jun 11 2025

    In this episode of the @Endace Packet Forensics Files, I talk to Jean-Paul Bergeaux, Federal CTO at GuidePoint Security. We unravel the complex world of federal cybersecurity and discuss the critical importance of certifications, the game-changing M-21-31 directives, and how packet capture data is revolutionizing threat detection.

    We also uncover the potential risks and opportunities presented by generative AI in the cybersecurity landscape. From SolarWinds lessons to the emerging generative AI challenge, Jean-Paul provides unprecedented insights into how government agencies fight to stay ahead of sophisticated cyber threats.
    This episode offers a must-watch deep dive into the frontlines of digital defense.

    ABOUT ENDACE
    *****************
    Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance.

    EndaceProbes are deployed on some of the world's largest, fastest and most critical networks. EndaceProbe models are available for on-premise, private cloud and public cloud deployments - delivering complete hybrid cloud visibility from a 'single-pane-of-glass'.

    Endace’s open EndaceProbe Analytics appliances (https://www.endace.com/endaceprobe) can be deployed in on-prem locations and can also host third-party security and performance monitoring solutions while simultaneously recording a 100% accurate history of network activity.

    Show More Show Less
    23 mins
  • Episode 60: James Spiteri - Director of Product Management for Security Analytics at Elastic
    Feb 26 2025

    How Generative AI and Machine Learning are Revolutionizing Cybersecurity

    In this episode of the Endace Packet Forensic Files, Michael Morris explores how advanced technologies like AI and machine learning are transforming security operations with James Spiteri. With extensive experience in cybersecurity and security operations, including leading SOC teams and developing innovative solutions for AI and machine learning, James offers unparalleled insights.

    He delves into the growing sophistication of nation-state threats, the critical role of SIEM tools, and how AI-driven insights are enabling faster, smarter threat detection by prioritizing critical alerts, automating mundane tasks, analyzing complex data patterns, and operationalizing unstructured threat intelligence in real-time.

    Don’t miss this insightful episode, where James shares expert tips on leveraging cutting-edge technology to strengthen your cybersecurity defenses and stay ahead of evolving threats.

    ABOUT ENDACE
    *****************
    Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance.

    For more than two decades, Endace has revolutionized enterprise-class, always-on packet capture. The scalable EndaceProbe Analytics Platform (https://www.endace.com/endaceprobe) delivers deep, unified visibility across on-premise, private, and public cloud networks. Get to forensic evidence quickly, with rapid search and powerful tool integration. Protect your network and accelerate investigation and response with Endace.

    Show More Show Less
    32 mins
  • Episode 59: Matt Bromiley - SANS Author and Instructor | Veteran Threat Hunting Expert
    Nov 7 2024

    Unlock the Power of Network Packet Data in Cybersecurity

    In this episode of the Endace Packet Forensics Files, Michael Morris dives into the critical role of network packet data in cybersecurity with Matt Bromiley, a seasoned threat-hunting expert. Matt shares why robust detection systems and proactive threat hunting are essential, and how network data serves as the “glue” that ties together evidence in cybersecurity investigations.

    The challenges of managing large data volumes, the growing role of AI in threat detection, and the tools needed to stay ahead of emerging threats are explored. Matt provides practical steps to seamlessly integrate packet capture into a threat-hunting toolkit, enabling teams to uncover and respond to even the most elusive threats.

    Matt emphasizes the importance of implementing a comprehensive packet capture strategy and using advanced tools, including AI, to manage data and enhance detection. He also stresses the need for continuous team training to effectively interpret data and respond to real-time threats, strengthening your defense against complex threats.

    Don’t miss this insightful episode, where Matt shares expert tips on optimizing threat hunting and leveraging packet capture to strengthen your cybersecurity defenses.

    Show More Show Less
    39 mins