We'll cover a classic "clicked a bad link and got a drive-by exploit kit" scenario to start, followed by DNS tunneling, weird User-Agent strings, and how to look at the plaintext parts of an SSL connection for fun and profit. The MITRE ATT&CK framework as implemented in BZAR, as well as custom instrumentation via "brogramming", will also be examined at a high level. Those seeking further depth, please reach out to the presenter after the talk.