Ryan Chapman

Ryan Chapman Email and Phone Number

Threat Hunter | Host & Network Forensics | Malware Analysis | SANS Author (FOR528) & Instructor | CactusCon Crew | PluralSight Author @ Palo Alto Networks
Ryan Chapman's Location
Goodyear, Arizona, United States, United States
Ryan Chapman's Contact Details
About Ryan Chapman

I am an Information Security professional with over 20 years of experience in the IT realm, half of which have been in hands-on DFIR roles. I love working with people, sharing knowledge, and absorbing all that I can from others. I have a zest for learning, and I love the fact that the security industry is an ever-evolving creature. Nothing is stale, there is always something new to learn, and I absolutely love what I do. You can't ask for more than that!For the past few years I have had a core focus on ransomware. I've been hyper-focused so much that I ended up authoring a new SANS course on ransomware -- FOR528: Ransomware and Cyber Extortion (sans.org/for528). Though ransomware attacks are a scourge on our computing lives, I relish in the ability to dissect, understand, and protect against these threats.I also enjoy public speaking. I love to run my mouth, and having the opportunity to do so in front of like-minded professionals is a true joy of mine. I have presented at conferences including DefCon, SANS Summits, BSides (Las Vegas | San Francisco), CactusCon, Splunk.Conf, at various universities/clubs, and more. I love engaging with the security community so much that I work as a core staff member for CactusCon, Arizona's hacker/security conference. I served as the conference lead for two years (CC9/CC10) and now serve as the Sponsor/Community Liaison. The more I can help to connect people and foster learning in our realm, the better!You can find more information about me along with presentations, podcasts, articles/press, workshops, and more at my website: https://incidentresponse.training/

Ryan Chapman's Current Company Details
Palo Alto Networks

Palo Alto Networks

View
Threat Hunter | Host & Network Forensics | Malware Analysis | SANS Author (FOR528) & Instructor | CactusCon Crew | PluralSight Author
Ryan Chapman Work Experience Details
  • Palo Alto Networks
    Team Lead, Managed Threat Hunting
    Palo Alto Networks Sep 2024 - Present
    Santa Clara, California, Us
  • Palo Alto Networks
    Principal Threat Hunter
    Palo Alto Networks Nov 2023 - Sep 2024
    Santa Clara, California, Us
  • Palo Alto Networks
    Principal Consultant, Incident Response
    Palo Alto Networks Nov 2022 - Nov 2023
    Santa Clara, California, Us
  • Sans Institute
    Author & Instructor
    Sans Institute Dec 2019 - Present
    Rockville, Maryland, Us
    Author of SANS FOR528: Ransomware for Incident Responders- See https://for528.com/courseInstructor for SANS FOR610: Reverse-Engineering Malware (Malware Analysis Tools and Techniques)- See https://for610.com/courseTeaching Schedule: https://www.sans.org/profiles/ryan-chapman/Co-chair for SANS Ransomware Summithttps://for528.com/summit23
  • Cactuscon
    Conference Organizer
    Cactuscon Oct 2019 - Present
    Mesa, Az, Us
    CactusCon Lead Organizer for CactusCon 9 & 10 (2021 & 2022)- Lead organizer. Served as project manager for conference and helped guide the actions of our core volunteers.Sponsor & Community Liaison for CactusCon 11 (upcoming, 2023)- Transitioned to working with potential sponsors and the community
  • Pluralsight
    Author & Curriculum Development
    Pluralsight Dec 2016 - Present
    Draper, Ut, Us
    Authored several incident response courses and helped develop the incident response curriculum path/blueprint.
  • Cylance Inc.
    Principal Incident Response & Forensics Consultant
    Cylance Inc. Jul 2019 - Nov 2022
    Waterloo, Ontario, Ca
    As an IR consultant for BlackBerry Security Services, I run and work incidents on behalf of our clients. Our firm provides response, assessment, and training in the digital forensics and incident response (DFIR) realm. My primary case types involve digital forensics investigations (e.g. ransomware cases), compromise assessments, business email compromises, tabletop exercises, and more.
  • Bechtel Corporation
    Senior Incident Response Analyst
    Bechtel Corporation Sep 2017 - Jul 2019
    Reston, Virginia, Us
    - Lead and prioritize CIRT/SOC incident response endeavors- Participate in the Incident Commander rotation during declared incidents- Technical lead/escalation point for SOC- Quality control for SOC work- Technical training development and delivery for IR processes- Daily review of high-priority eventsExample project: SOC Baseline TrainingDeveloped and trained a 5-week curriculum to all SOC team members. Training covered the company, our SIEM, advanced networking concepts, network forensics, host-based forensics, malware analysis, threat hunting, and working with intel. The curriculum all resides within our documentation system and will be used for onboarding new IR analysts going forward.
  • Bechtel Corporation
    Computer Incident Response Team Analyst
    Bechtel Corporation Apr 2015 - Sep 2017
    Reston, Virginia, Us
    - Participate in Incident Commander (IC) rotation, facilitating a governing role to direct response initiative during declared incidents- Function as the CIRT/SOC liaison, serving as a technical lead for the SOC- Perform forensic examinations and cyber intelligence vetting- Research, analyze, and document APT-based tactics, techniques, and procedures- Design, develop, and maintain systems used by the SOC to aid in incident response- Maintain OpenDNS/Umbrella, Splunk, Palo Alto firewalls, FireEye, and GitHub Enterprise - Participate in 24 hour on-call rotation
  • Bechtel Corporation
    Security Operations Center Lead
    Bechtel Corporation Aug 2012 - Apr 2015
    Reston, Virginia, Us
    - Team lead, responsible for two analysts in a 24x7 operating environment (as of December, 2013)- New hire trainer, responsible for training all new hire SOC analysts- Respond to security system alerts (Intrusion Detection System, Malware Runtime Environment, etc.)- Perform real-time monitoring and incident response: Triage, analyze, and remediate incidents- Search infrastructure for signs of malware and malicious events not detected by existing security controls- Perform network- and host-based forensic analysis in a mixed-platform environment using both commercial and open source forensic utilities- Perform malware analysis (code & behavior analysis)- Develop and maintain methods and procedures (M&Ps) along with associated documentation- Utilize a virtualized environment to enable rapid recovery (OSX host running multiple Windows + Linux VMs)Tools: Splunk, FireEye, EnCase, GRR, Wireshark, tcpdump, OllydDbg, IDA, Volatility, MIR, Redline, Snort, and others
  • 2Wire / Pace Americas
    Application Developer
    2Wire / Pace Americas Jan 2012 - Jul 2012
    - Developed and maintained Web-based applications for both internal and external partners- Developed, optimized, secured, and maintained application databases- Wrote and maintained applications written in PHP and SQL on a daily basis- Generated application functionality, risk, and disaster recovery documentation- Guaranteed software security by testing for Web-based vulnerabilities such as SQL injection and XSS- Guaranteed internal applications use proper authentication
  • 2Wire / Pace Americas
    Technical Trainer
    2Wire / Pace Americas Dec 2006 - Jan 2012
    - Trained WAN, xDSL, VoIP, IPTV, and satellite infrastructure, design, and troubleshooting- Trained LAN (TCP/IP, DHCP, DNS, NAT) protocols; firewalls; routing; and the OSI model- Trained advanced 802.3 and 802.11 concepts, setup, and troubleshooting- Trained customer care techniques (e.g. "soft skills")(2Wire Inc. was purchased by Pace Americas in 2010)
  • Chapman Computer Repair
    Owner / Consultant
    Chapman Computer Repair Aug 2001 - Jan 2005
    - Ran own consulting company in the Silicon Valley- Maintained clientele of single office/home office (SOHO) individuals/businesses- Maintained computer systems (Windows & Macintosh primarily)- Designed, implemented, and maintained wired and wireless networks

Ryan Chapman Skills

Security Troubleshooting Computer Security Network Security Firewalls Tcp/ip Information Security Dns Disaster Recovery Software Documentation Active Directory Computer Forensics Wireshark Servers Cissp Os X Vpn Windows Server Networking Internet Protocol Suite Typing Malware Analysis Incident Response Public Speaking Domain Name System Python Shell Scripting Splunk

Ryan Chapman Education Details

  • Regis University
    Regis University
    Information Assurance
  • Regis University
    Regis University
    Computer Networking W/Minor In E-Security

Frequently Asked Questions about Ryan Chapman

What company does Ryan Chapman work for?

Ryan Chapman works for Palo Alto Networks

What is Ryan Chapman's role at the current company?

Ryan Chapman's current role is Threat Hunter | Host & Network Forensics | Malware Analysis | SANS Author (FOR528) & Instructor | CactusCon Crew | PluralSight Author.

What is Ryan Chapman's email address?

Ryan Chapman's email address is rc****@****nce.com

What is Ryan Chapman's direct phone number?

Ryan Chapman's direct phone number is +183180*****

What schools did Ryan Chapman attend?

Ryan Chapman attended Regis University, Regis University.

What skills is Ryan Chapman known for?

Ryan Chapman has skills like Security, Troubleshooting, Computer Security, Network Security, Firewalls, Tcp/ip, Information Security, Dns, Disaster Recovery, Software Documentation, Active Directory, Computer Forensics.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.