48Ronnie Tokazowski

Photograph of Ronnie Tokazowski.

“The unsung heroes of blue teams are the engineering departments that spend countless hours troubleshooting and installing network appliances and testing security logging, not to mention ruined holidays when a critical security appliance goes down to ensure 99.9 percent uptime for responders.”

Twitter: @iHeartMalwareWebsite: www.linkedin.com/in/ronnietokazowski

Ronnie Tokazowski, aka iHeartMalware, is a senior threat researcher with Agari who specializes in BEC intelligence. Ronnie also has experience reverse engineering APT malware and finds enjoyment by messing with threat actors.

How do you define a blue team?

When asked about what the definition of what a blue teamer is, the first role that comes to mind is incident response. While this is partially true that a blue teamer is an incident responder, there are a lot of other moving parts behind the scenes. The unsung heroes of blue teams are the engineering departments that spend countless hours troubleshooting and installing network appliances and testing security logging, not to mention ruined holidays when a critical security appliance goes down to ensure 99.9 percent uptime for responders.

A blue team is all of these things working together as one, with responders analyzing the logs and data to protect the company, while providing intelligence and feedback to engineering teams to help mitigate ...

Get Tribe of Hackers Blue Team now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.