Explore advanced Internet dataset combinations for threat hunting and attack prediction in this 31-minute conference talk from BSidesSF 2017. Learn to move beyond simple Whois and PDNS lookups, and noisy threat feeds. Discover how to combine SSL cert facet data with tracking IDs, host-pair relationships, and technology stack fingerprints to detect, verify, and stop adversaries' next attacks. Gain insights into analyzing potentially compromised users and determining if IP addresses, domain names, or URLs pose threats. The presentation covers traditional and modern data sets, operationalizing data, and includes examples and a demo, concluding with a comparison of techniques.
Advanced Internet Dataset Combinations for Threat Hunting and Attack Prediction