Explore practical incident response techniques for heterogeneous environments in this BSides Detroit 2018 conference talk. Delve into the challenges of mass-triage in modern cybersecurity and learn about innovative tools like RIFT (Retrieve Interesting Files Tool) and FRAC (Forensic Response Acquisition). Discover the process of building Advanced Indicators of Compromise (AIOCs) through malware analysis, using Trojan.Bisonal as an example. Gain insights into YARA rules and their application in creating AIOCs. Examine the capabilities of ClamAV for malware detection, including custom rule creation, remote scanning, and forensic applications. Understand how to generate ClamAV signatures using IDA with CASC and explore the future direction of incident response methodologies.
Practical Incident Response in Heterogenous Environment