CC10 - Network Forensics Analysis

preview_player
Показать описание
CactusCon 10 (2022) Talk
Network Forensics Analysis
Rami Al-Talhi

Advanced Persistent Threat (APT) groups do not like to have the evidence of their crime into their targets, usually, they would develop or use file-less malware to not leave any fingerprints traces proof their crime and unleashed their operations. Network forensics analysis became an essential skills to uncover APTs operation and identify what has happened by utilizing Wireshark and other open-source tools to analyze network packet captures (PCAP). In this lecture, we will introduce couple of APT attack scenarios and walk-through how to analyze them.

Rami has experience across different information security and cybersecurity fields for over 13years. Worked as Incident Response Expert in the past for four years to handle different cyber incident and events. Provided DFIR and Cyber Range training for different regions in the world (Europe, Asia, Middle East and US). Dealt with different sophisticated APT cyber incident cases that ranging from cyber espionage until data destruction.
Рекомендации по теме
Комментарии
Автор

An hash based on a TLS handshake and matching with a MD5 emotet or trickbot C2 response hash.... sweet!

Gksec-lrxg