Staff
Since ‎11-16-2022
yesterday

My Stats

  • 151 Posts
  • 27 Solutions
  • 6 Likes given
  • 131 Likes received

jstoner's Bio

I provide security domain expertise on security operations, threat hunting, detection engineering and response. Additionally, I blog about security operations and threat hunting, currently through the New to Chronicle series on https://chronicle.security/blogs. Part of my time is spent creating and developing workshops intended to provide practitioners the opportunity to broaden their skills within SecOps. I also speak at industry symposia including BSides; Vegas and SF; DefCon Packet Hacking Village; FIRST and FIRST Technical Colloquium Amsterdam; SANS THIR, DFIR, Cloud Security Summit and SIEM Summit; Way West Hacking Fest, WiCyS, AISA, Splunk .conf and Google Cloud NEXT. Prior to coming to Google, I was at Splunk and before that ArcSight. I was an APT scenario creator for a Blue Team CTF and can be found on Threads, Bluesky and Mastodon - Infosec Exchange with the same handle as on XTwitter, I just haven't found a permanent home yet.

Badges jstoner Earned

View all badges

Recent Activity

Last year, Google Security Operations added the pivot capability to aggregate and calculate statistics in UDM search. This allowed users the ability to take a UDM search and use an interface to aggregate values, like this. Fast forward to this year, ...
Today we are going to review the third type of reference list that we can use in our YARA-L rules in Google SecOps. This one is focused on regular expressions. Regex reference lists provide additional flexibility because they are not limited to direc...
"New to Google SecOps" is a deep-dive series by Google Cloud Principal Security Strategist John Stoner which provides practical guidance for security teams that are either new to Security Operations Platforms or replacing their Security Operations Pl...
New to Google SecOps" is a deep-dive series by Google Cloud Principal Security Strategist John Stoner which provides practical guidance for security teams that are either new to Security Operations Platforms or replacing their Security Operations Pla...
"New to Google SecOps" is a deep-dive series by Google Cloud Principal Security Strategist John Stoner which provides practical guidance for security teams that are either new to Security Operations Platforms or replacing their Security Operations Pl...