Главная
Study mode:
on
1
Intro
2
Background: By the numbers
3
Dragos Investigation
4
Dragos Timeline
5
Ukrainian Power Outage
6
CRASHOVERRIDE Framework
7
Initial Intrusion
8
Time Stamps Tell a Story
9
Persistence
10
Launcher Module Crash Caller
11
Launcher Module: Wiper Thread
12
Payload Modules
13
IEC 104 Module Execution Flow
14
IEC 104 Module Configuration File
15
Wiper Module: Flow
16
Wiper Module: File Extensions
17
Grid Scenarios: Impact
18
Detecting CRASHOVERRIDE - Host
19
Detecting CRASHOVERRIDE - Yara
20
Defeating CRASHOVERRIDE: Key Nodes
21
CRASHOVERRIDE Resources
22
Dragos Ecosystem
Description:
Explore the analysis and reverse engineering of CRASHOVERRIDE in this 57-minute webcast recording from Dragos: ICS Cybersecurity. Delve into the known and unknown aspects of the CRASHOVERRIDE framework and its impact on grid operations. Gain insights into the background, technical details, and mitigation strategies for this cybersecurity threat. Examine the investigation timeline, Ukrainian power outage incident, and the framework's components including initial intrusion, persistence, launcher modules, and payload modules. Learn about the IEC 104 module execution flow, wiper module functionality, and potential grid impact scenarios. Discover detection methods for CRASHOVERRIDE on host systems and through Yara rules. Understand key nodes for defeating CRASHOVERRIDE and access additional resources provided by Dragos.

Analyzing and Understanding CRASHOVERRIDE - ICS Cybersecurity Webcast

Dragos: ICS Cybersecurity
Add to list