How Retained NetFlow Found a Five-Year APT Nobody Else Saw
Georgetown CISO Micah Czigan explains calm incident response, early escalation, role clarity, and critical thinking when runbooks stop matching reality.
Every incident plan is written for an incident that somebody imagined in advance. The one that actually arrives tends to put a screen in front of an analyst who has never seen anything like it, at an hour when that analyst is on their own.
Micah Czigan has been on both sides of that screen. On his first incident-manager shift at Symantec, he was the one who hesitated until a CISO asked him a question he has repeated to himself ever since. In government, he was the executive at the other end of an escalation that took far too long to arrive, because a junior analyst was still trying to work out what they were looking at. What connects those two moments is the skill he names when asked what incident response most undervalues.
Micah is Chief Information Security Officer at Georgetown University, where he has worked since 2020. Before that he was Director of Defensive Cyber Operations at Symantec, and before that Associate Deputy CISO for Cybersecurity at the Department of Energy, following a run of roles across the Department of Defense.
On Episode 16 of the Full Metal Packet podcast, hosts Yegor Sak and Alex Paguis keep returning to one question in different forms. When the breach hits and everybody wants answers immediately, how does a leader create calm before the team can create control?
TL;DR
- Train past the runbook. A tabletop is where preparation starts, not where it finishes. Run the same scenario live afterward to see whether the plan survives contact, and rehearse the pivot for a vector nobody wrote down.
- Put somebody between the SOC and the executives. An incident manager who tracks the response and translates it upward keeps leadership pressure off the analysts, and at Georgetown that is often an IT director rather than a security specialist.
- Make the 2AM call free, then prove it. A junior analyst on a month-old SIEM sat on a real government alert while trying to understand it. Tell people to escalate when they are unsure, and never make an example of the one who does.
- Spend nothing before you spend anything. Knowing what you own, which systems matter and what of yours is reachable from the internet costs time and no money. When Micah does spend, he aims hardware keys at the assistant who reads the executive's email.
- Keep flow data long enough to hunt through it. A NetFlow hunt at the Department of Energy surfaced malware sending one TCP packet every couple of days to the same address, still there as far back as five years of records reached.
Train Like You're Gonna Fight
Yegor starts with the room on fire. Something has happened, people are panicking, and somebody has to steady them. Micah's answer begins months earlier, with a line he brought out of the military.
"Train like you're gonna fight because you're gonna fight like you train."
That means playbooks, runbooks, tabletop exercises and red team work. Where a lot of organizations treat all of it as a nice to have, he treats it as a necessity, and he is just as firm that a tabletop on its own proves very little. Paper is where preparation starts. The point is to then test the thing live and see whether the plan survives contact, and he has watched plenty of teams finish the discussion, declare themselves ready and never get that far.
"You didn't actually try it."
Yegor pushes on the obvious limit, which is that you can drill an enemy arriving from the east and then watch them come from the west. Micah moves the target rather than defending the drill. A team that understands its own perimeter and the techniques being used against it can pivot when the vector is unfamiliar, which is why he keeps landing on critical thinking as the thing that actually carries a response. Randolph Barr runs into the same problem in Episode 5, where a well-practiced playbook goes stale because the threat moved underneath it.
Preparation only carries a team so far, and Micah is candid about what fills the rest. The leader starts performing.
"Sometimes you're kind of faking it. You may not really know what to do, but I'm gonna act like I do."
Composure buys the team enough confidence to keep working, and he thinks a leader has no standing to offer less, because whatever the team does lands on him anyway. He learned where that lands during his first incident at Symantec, as the incident manager on duty, so anxious about getting it wrong that he worked through the procedures until the response slowed to a crawl. His CISO cut across him.
"Are you gonna own this or not?"
The question stuck because it drew a line he had not seen. Owning an incident means making calls on incomplete information and living with them, which is a different job from following the document correctly.
The Analyst Who Froze Overnight
He has also been on the receiving end of the same hesitation. This was in government, at a headquarters operations center taking data from an entire department, in the early hours when the queue is usually quiet. The team had recently brought in an analyst who was fairly new to this work, not yet a decade in, and had moved onto a new SIEM about a month before.
The alert that arrived matched nothing the analyst recognized. Runbooks existed and the event type had been practiced, but rather than escalate, they sat with it and tried to work it out alone.
"They really waited a pretty long amount of time trying to process."
Micah reads it as tunnel vision more than embarrassment, though he offers both and settles on neither. What eventually reached him amounted to "I think we have something important, but I don't know what I'm looking at." The team absorbed the delay and handled the incident, but the detail that makes it worth telling is what happened next. The senior analyst on shift hesitated in exactly the same way over whether to wake anybody up, and that decision had been practiced too.
"I'd rather you wake me up at two AM and it'd be nothing than you wait till eight when I'm in the office and say, yeah, we had this thing."
Yegor names the culture underneath it. People stay quiet because raising something that turns out to be nothing makes them look foolish in front of colleagues.
Micah's answer is to say out loud and often that the call is always welcome, and Alex is more interested in what happens the first time somebody takes him up on it, since a leader who makes that offer and then bites their head off will never hear from them again.
Micah agrees without hedging. Tearing into someone over a false alarm is a really good way to lose the trust the whole arrangement runs on. His one condition is that nobody dumps a problem in his lap and walks away, since bringing what you have already checked turns it into a shared problem rather than a handover.
Who Runs the Room, and How Technical They Have to Be
Escalation only helps if there is somewhere for it to go. Asked what people most misunderstand about the first hour, Micah describes two groups talking straight past each other. Executives want to know what is happening minute by minute, usually because customers or lawyers are leaning on them, and the technical team cannot tell them, because producing the answer means stopping the work that produces the answer.
Georgetown solves that with a person rather than a process. An incident manager, often not a security specialist at all, pulls in whatever the response needs, keeps a picture of where everything stands and carries it upward.
"Then I can kind of reformulate that into executive speak."
Yegor turns this into the larger question of whether the top security job belongs to a technologist or an executive. Micah flags his answer as a personal opinion before giving it, which is that a CISO who lets go of the technical side will run into trouble, though he stops short of claiming it holds at every scale.
What does not scale away is accountability.
"I am the senior accountable official for cybersecurity."
Being the accountable official means "I don't know what to do" is not an answer available to him mid-incident, and he says he would tell anybody who offered it that they were welcome to leave instead. It commits him to break-glass access that works and enough hands-on knowledge to use it.
Yegor moves the question away from execution, which is the more useful reframing. Most problems do not need the CISO to write code. They need somebody who knows which system is chained to which, and who is willing to interrupt when they lose the thread.
"I don't understand what that acronym means. Tell me what that means so I can understand the context."
When the Outage Belongs to Your Vendor
A live example was sitting in the middle of this conversation. Instructure had detected unauthorized activity in Canvas, the platform Georgetown runs its courses on, in late April 2026, and a second intrusion in early May pushed it into maintenance mode. Universities around the world lost the system, Georgetown among them, with finals coming.
An incident inside somebody else's product produces a different job entirely. Micah's team had no real part in the technical response, so the work became communication, and how much of it was legally available to them.
"Now it's more I gotta put on a business hat."
The obvious question is why there was no failover. His answer turns it into a budget conversation rather than a security one.
"Should we have a failover for all the critical systems? My opinion, yes. CFO's opinion, maybe not."
Low probability, severe impact, and no cost-per-hour-of-outage figure he can produce on demand. The argument that had always won was Canvas's own availability record, since it had never gone down at Georgetown badly enough to stop work. Zach Lewis faced the harder version in Episode 12, where every layer he planned to fall back on failed in turn.
Since this recording, Instructure has brought Canvas back, traced both intrusions to its Free-For-Teacher accounts and discontinued that product, and said the stolen data was returned and destroyed under an agreement with the actor.
One Laptop, No MFA, and the Active Directory Database Gone
Georgetown's own worst incident predates all of that, and predates Micah. It landed shortly before he arrived, which makes it a fair picture of the program before he started rebuilding it. A professor had administrative rights on a server and a laptop with no security software on it. Yegor assumes this must have been a personal machine, and it was not. The university issued it, and the problem was how little control it had over what it issued.
"At many universities, each school is like their own island."
Individual schools ran their own IT, so the standard was whatever each island decided, and on this machine there was effectively none. Somebody most likely clicked a link, malware landed, and the attacker walked away with the credentials.
"We did not have two factor authentication, so all they needed username and password."
Everything after that was mechanical. The credentials opened the server where the account held elevated rights, the server opened a route into an Active Directory that was not well secured, and the attacker left with the hashed credential database before anybody knew they had been there. Devon Ackerman follows the same route in Episode 8, where identity, and never a perimeter device, is what gets handed over.
Nothing in the security stack caught it. What did was an analyst at the MSSP Georgetown had just onboarded, who noticed an odd volume of traffic moving from the laptop to the server and then from the server to Active Directory. No standard alert fired, and Micah's guess is that somebody was bored on a night shift and reading logs.
"I think it was really luck."
By the time anyone investigated there was nothing left to contain, so the insurer brought in a third party to run the whole thing, since the tiny SOC Georgetown had then was in no position to. Today the same attack would meet trained analysts, real telemetry and a response retainer, with the insurer there for cleanup.
The Zero-Dollar Controls, and Who Gets a Hardware Key
Alex asks the question that makes the story useful to anybody who is not Georgetown. What do you do when the SOC is immature, the team is small and there is no tooling? Micah starts with an inventory rather than a purchase.
"Know what your gaps are. That doesn't cost you anything."
Work out what you are responsible for, what is in your infrastructure and which of it matters most. Establish whether you have a firewall at all, since he says plenty of companies still do not. Then find out what of yours is visible from outside, because Shodan will scan your public ranges and most people cannot name their own public addresses.
"That's all you gotta do is just block 3389."
Hardware keys are where the free advice stops. He would hand them to everybody if he could, but at roughly $45 a head for a YubiKey, his own figure, the funding stops appearing at any real headcount.
Alex suggests targeting high-value accounts instead, which is precisely the account type the Georgetown breach turned on. Micah agrees, then makes the move that matters, which is to define high value by the work rather than the title. A new university president was arriving when this was recorded, and telling him to carry a hardware key was never going to happen. His assistant was a different matter, because the assistant is the one who actually reads the email.
"That's the person I want to have the YubiKey, not necessarily the CFO."
None of it is an easy sell. Getting SMS removed as a second factor was a hard push on its own, and he says the tactic of accepting a refusal and pointing at the incident afterward does not work in a university. Konrads Klints ends up in the same place in Episode 15, where budget and org chart, and not technology, decide which controls get deployed.
Five Years of NetFlow, One Packet at a Time
The last incident is one Micah brings up himself, and it starts from a position he knows is unfashionable.
"I'm a big proponent of NetFlow."
Colleagues tell him flow data is worthless next to endpoint telemetry. At the Department of Energy they kept it for years and only reached into the archive during an active investigation, to establish how long an intruder they already knew about had been inside. Nobody had run the process backwards and gone looking in the archive first. After the department moved onto a new SIEM, he handed the SOC a single use case, which was to find something long-term and quiet enough that no alert would ever have fired on it.
"And everyone's like, we're not gonna find that. Like, that's ridiculous."
His recollection is that it took about twelve hours. He came into work to an email from an analyst saying "Hey man, I think we got something." What they had was malware sending a very small amount of data to the same address, roughly one packet every couple of days. Yegor's first guess is DNS, and it was not. Micah is specific that this was a plain TCP packet. NetFlow gave him headers rather than contents, so he had the size, the destination and the sheer persistence of it, and the team traced back through deliberately obscured routing to the server on the other end.
They never established how long it had been running. The five years of retained NetFlow did not go back far enough to date it.
"It was sensitive data. Definitely not something that we wanted to get out."
He is honest about the cost, terabytes across years for one department, and says a smaller organization may reasonably decide it is not worth the money. Asked whether a smash-and-grab like Georgetown's and a five-year implant have anything useful in common for a defender, he says they do not, and would rather derive what to watch from the actors who plausibly threaten him. There are too many possibilities to cover everything, which is the prioritization problem Paul Bleicher works through in Episode 13.
Flow data is not the only cheap record he thinks gets discarded too early. Asked what else goes, he lists signals that cost almost nothing to keep.
| Signal | What he uses it for |
|---|---|
| Server logs, parsed to key process IDs | Many teams never collect them, on the theory that the logs are on the server. Anyone who reaches the server can delete them, so they need offloading. |
| CPU queue alerts | An uncharacteristic spike may be malware, or a script somebody broke. He wants the alert instead of the logs. |
| Drive fill rate | Not that a disk is full, but that it went from 5% to 80% quickly, which suggests something is being staged. |
| DNS logs | An indicator of malware, which is why he wants them. Browsing history is beside the point. |
DNS is the one he is least equivocal about.
"I want DNS logs. I want them all. I want everything."
Critical Thinking Is the Skill Nobody Teaches
Yegor closes on what a calm incident looks like from the inside, given how badly people decide things while tearing their hair out. Micah's version is procedural rather than temperamental. You follow the runbooks you have practiced, and when you reach the part that does not match, you break the problem into what you know, what you do not, what the threat implies and what happens next. Everything else, including the executive asking for an update right now, gets set aside.
"Focus on the task at hand, ignore the noise."
He traces the habit back to military training in working under fire, and it leads straight to the closing question of the episode, on the most underrated skill in incident response.
"Critical thinking. What do I do when I don't know what to do?"
No amount of training covers every scenario, so what he wants are people who can decide on the fly, drop the decision once it turns out to be wrong and recognize the moment to ask for help. He rates that above knowing Python or PowerShell, on the grounds that no two incidents arrive the same way.
"Every fire that you practice for is a new fire. It's never the same."
Asked whether questioning authority survives in a military culture, he says there are times to ask why and times to execute, and then gives the line the episode ends on.
"You can complain all you want to, as long as you're complaining while you're working. Continue to execute. I'll hear it all day long. Just continue to take the hill."
Keeping the Record That Made the Hunt Possible
Micah wants NetFlow and DNS records for the same reason. Both are cheap accounts of where traffic tried to go, and both are worthless if nobody kept them. Alex raises DNS during the NetFlow story as the version most organizations can actually afford, since it needs no software and the volumes are nowhere near terabytes. It is a narrow layer on its own, and the packet at the Department of Energy was not a DNS query, so it would not have caught that particular implant.
Control D covers three parts of that record:
- Real-Time DNS Logging keeps historical query records with device and user attribution, and lets you set where they live and how long they last.
- SIEM data streaming puts DNS activity on the same timeline as firewall and endpoint events while an incident is running.
- Dragonfly returns category, DNS records, TLS data and WHOIS information for a domain the team cannot immediately place.
Continue the Argument
- Episode 5: AI Is Rewriting the Incident Playbook & Most Security Teams Are Still on the Old Version asks what happens when a practiced playbook stops matching the threat.
- Episode 8: Ex-FBI Agent: One Phone Call Gave Hackers Full Network Access follows identity as the path into a network.
- Episode 12: How a University CISO Refused a $1.25M LockBit Ransom Demand shows recovery when the layers you planned to fall back on fail.
- Episode 13: Why Top Security Teams Deliberately Leave Vulnerabilities Unpatched asks how defenders document a risk decision they cannot avoid making.
- Episode 15: Your Incident Response Plan Is Missing One Phone Number argues that budget and structure, and not technology, decide which controls exist when an attack lands.
Common Questions Answered in Episode 16
Are tabletop exercises enough to prepare for a real incident?
No. A tabletop is the paper stage, and the plan only counts once you have tested the same scenario live. A team that finishes the discussion and considers itself prepared has confirmed a document instead of a capability.
Does a CISO need to be technical?
Micah's view is that a CISO who drifts out of the technical role starts losing the thread, since the same person sets the direction of functions they need to understand. He accepts the limit at extreme scale. Accountability does not scale away, which is his argument for keeping working knowledge of the tooling.
What should an organization do when a SaaS vendor is breached?
Communication becomes the primary job, since your team may have no part in the technical response. Decide with legal counsel and leadership what each group needs to hear, and plan continuity alongside it, because users need the service back whoever caused the incident.
How does an attacker get from one laptop to Active Directory?
Usually by collecting credentials from a poorly protected endpoint and then using the access those credentials already carry. Here, malware on an unmanaged laptop produced a username and password with no second factor, the account held administrative rights on a server, and the server offered a route into Active Directory.
Who should get a hardware security key first?
The people who do the work, who are not always the people with the senior titles. An executive assistant reads and acts on the email, and somebody other than the CFO usually signs the payments. Start with accounts holding administrative rights, since those turn one compromised device into a domain-wide problem.
How long should you keep network flow and DNS logs?
Long enough to hunt through them, and not only to alert on them. Quiet, long-dwell activity is invisible in real time and shows up only as a pattern across months or years of retained records. The trade-off is storage, so the question is which sources are cheap enough to keep that long.
Micah Czigan is Chief Information Security Officer at Georgetown University, where he has worked since 2020. He studied marine biology, went to sea on commercial ships, served in the US Navy as a cryptologic communications specialist, and was running the enterprise help desk at the Pentagon when he told his CIO that this cyber thing looked like a real thing and asked to work on it.
Full Metal Packet is hosted by Control D co-founders Yegor Sak and Alex Paguis. Watch Episode 16 on YouTube, or listen on Apple Podcasts and Spotify.