Breaking the Ransomware Tool Set: When a Threat Actor Opsec

preview_player
Показать описание
SANS Cyber Threat Intelligence Summit 2023

Breaking the Ransomware Tool Set: When a Threat Actor Opsec FailureBecame a Threat Intelligence Gold Mine
Nicklas Keijser

Further, it reveals techniques used to turn off anti-virus and clear out logs, including keys used for locking down computers and much more. To conclude I will look into the threat intelligence part of the intrusion, showing how threat actors copy and stockpile techniques from each other and finish off showing how malware analysis in combination with threat intelligence made it possible to find an undetected spare back door that was deployed in the environment. In this talk I will also share several indicators of compromise as well as tools, tactics, and procedures from an active and aggressive ransomware operator that can serve as inspiration for how malware analysis and threat intelligence can be operationalized to stop an intrusion.

Рекомендации по теме
Комментарии
Автор

Liked your video. What's your twitter handle?

briansmith
visit shbcf.ru