Skip to Main Content

Steven Erwin

Senior Security Consultant

EXPERIENCE
Steven has over 11 years experience in networking and security and over five years in Incident Response. His industry experience ranges from steel mills and healthcare to small offices and electrical control systems.

EDUCATION & CERTIFICATIONS

  • BS – Information Security Technology – Purdue University
  • GIAC Network Forensic Analyst (GNFA)
  • GIAC Certified Forensic Analyst (GCFA)

PROFESSIONAL AFFILIATIONS

  • GIAC Advisory Board

PASSION FOR SECURITY
Steven has always had an interest in computers. He started his career as a network engineer then transitioned into a network security role. That role drove him to learn as much as possible about security. Making sure to learn from everyone around him, he understands that security requires continuous education and training.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog December 14 2023

Unmasking Business Email Compromise: Safeguarding Organizations in the Digital Age

Business Email Compromises (BEC) within the Microsoft 365 environment are a large threat with nearly $500 Million reported in stolen funds in 2022[1].…

Read about this article
Blog February 07 2023

ESXiArgs: What you need to know and how to protect your data

Threat Overview Around February 03, 2023, a ransomware campaign called “ESXiArgs” emerged that targeted Internet-facing VMware ESXi servers running versions…

Read about this article
Blog November 08 2022

Auditing Exchange Online From an Incident Responder's View

Business Email Compromise (BEC) within the Microsoft 365 environment is becoming a more common attack vector. In case you’re unfamiliar with what exactly BEC…

Read about this article
Webinars March 15 2022

Detections and Defensive Insights From the ContiLeaks

Join Incident Response Consultants Steven Erwin, Ashley Pearson, and Nick Gilberti to understand how to practically use information found in the leak to…

Read about this article
Webinars December 07 2022

Security Lessons Learned from the Global Conflict

Tune in with TrustedSec leaders who are on the front lines of the research, penetration testing, and Incident Response aspects of the conflict to learn how you…

Read about this article
Webinars December 18 2024

The Lost Underground

Join TrustedSec Principal Security Consultant Mike Felch for an eye-opening journey into the lost underground, where ingenuity, disobedience, and complexity…

Read about this article
Webinars December 04 2024

BEC Basics: Your First Step to Thwarting Email Scams

Join Senior Security Consultant Steven Erwin and Security Consultant Caroline Fenstermacher as they cover the basics of BEC analysis, providing participants…

Read about this article
Blog December 03 2024

Discovering a Deserialization Vulnerability in LINQPad

Like most red teamers, I spend quite a lot of time looking for novel vulnerabilities that could be used for initial access or lateral movement. Recently, my…

Read about this article
Blog November 21 2024

A 5-Minute Guide to HTTP Response Codes

If you've done any network scanning or application testing, you've run into your fair share of HTTP response codes. If not, these codes will show up in most…

Read about this article
Events TrustedSec HQ | November 20 2024

WiCyS Ransomware Panel & Networking Event

Join us for an insightful discussion with the Women in Cyber Security (WiCyS) Northeast Ohio Affiliate members!

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.