Digital Forensic and Incident Response Strategist

Phil Hagen

Phil engages with the Digital Forensic and Incident Response (DFIR) community to ensure Red Canary’s endpoint security solution fits into DFIR processes at organizations of all sizes. Phil is a SANS Senior Instructor and course lead for SANS FOR572: Advanced Network Forensics. He has also held several previous positions at ManTech CFIA and worked as a communications officer in the US Air Force. He lives in coastal Delaware with his amazing wife and two kids, where he enjoys the local craft beer scene and is often found riding a OneWheel wherever he can.
Passive DNS Monitoring – Why It’s Important for Your IR Team
Improving Incident Response with Autonomous System Numbers
Ransomware is not going away: Prepare or pay up
Fundamental Security for Small Business
Detection Profile: Silent Periodic Activity
The Fallacy of Breach Prevention
20 CIS Critical Security Controls – How Red Canary Stacks Up
Medical Records are an Attractive Data Theft Target