I took the recertification exam for my SANS GIAC Certified Intrusion Analyst today. Passed with 93% which is better than I did on both practice exams.
Four more years.
Well, GSEC is up in 2025, then GCIH in 2027.
That leaves 2026 to get a new cert in. Thinking about GMLE, actually.
If I never have to manually dissect packets or do bitmasking again, it will be too soon. I actually almost understand bitmasking now. If I ever fully grasp it I think I will poof out of existence, having fulfilled my special purpose.
It was cool to play with Zeek (formerly Bro) and SiLK again. I don't get to use the command line for analysis much day-to-day.
I felt personally called out when they lamented those orgs that try to bolt cross-session, multi-application correlation and alerting onto SEIM instead of using security tools designed to do it for you.
#InfoSec #SANS #GIAC #GCIA #Zeek #SiLK