Главная
Study mode:
on
1
Introduction
2
Stealth
3
Network Traffic
4
Spark Lines
5
Lessons
6
Rapidly evolving tactics
7
Three versions of C Daddy
8
Prioritize the unknown
9
Improving indicators
10
Looking at the malware
11
Rapidly evolve
12
Advanced attack techniques
13
WMI usage
14
Event filter
15
PowerShell
16
Module Log
17
Kerberos Ticket Attack
18
Indicators
19
WMI PowerShell
20
Backdoor
21
Lesson
22
The Config
23
Nick Carr
24
Questions
Description:
Explore an in-depth investigation of advanced cyber attack techniques and defense strategies in this 53-minute conference talk from Derbycon 2016. Delve into the complexities of stealthy network traffic, Spark Lines, and rapidly evolving tactics used by sophisticated threat actors. Learn about the three versions of C Daddy, the importance of prioritizing unknown threats, and methods for improving indicators. Examine malware analysis techniques and advanced attack methodologies, including WMI usage, event filtering, PowerShell modules, and Kerberos ticket attacks. Gain valuable insights on detecting and mitigating WMI PowerShell backdoors, understanding attack configurations, and implementing effective defensive measures. Conclude with a Q&A session to further expand your knowledge of cutting-edge cybersecurity practices.

No Easy Breach Challenges and Lessons from an Epic Investigation

Add to list