Making sense of SolarWinds through the lens of MITRE ATT&CK | STAR Webcast

preview_player
Показать описание
Almost two months have passed since we first learned about the supply chain compromise of SolarWinds, and the community is still struggling to make sense of all of it. Enter MITRE ATT&CK. The speakers from the ATT&CK team walk through how to use the framework to better organize what we know about the multitude of techniques from SolarWinds and related compromises. They discuss both techniques that were previously known as well as those they recently added to ATT&CK in order to help understand what actions they can take to better defend their networks.

Speaker Bios
Katie Nickels @likethecoins is the Principal Intelligence Analyst for Red Canary. She has worked on cyber threat intelligence (CTI), network defense, and incident response for nearly a decade for the U.S. Department of Defense (DoD), MITRE, Raytheon, and ManTech. She also serves as an instructor for the SANS FOR578: Cyber Threat Intelligence course, enabling her to share her passion for CTI more broadly. Katie hosts SANS Threat Analysis Rundown (STAR), a popular monthly webcast series that discusses the current threat landscape and cyber threats. She is also the Program Manager at Cyberjutsu Girls Academy (CGA), a program for teenage girls that seeks to inspire exploration and learning in cybersecurity and STEM.

Adam Pennington(@_whatshisface) leads ATT&CK at The MITRE Corporation and collected much of the intelligence leveraged in creating ATT&CKs initial techniques. He has spent much of his 12 years with MITRE studying and preaching the use of deception for intelligence gathering. Prior to joining MITRE, Adam was a researcher at Carnegie Mellon's Parallel Data Lab and earned his BS and MS degrees in Computer Science and Electrical and Computer Engineering as well as the 2017 Alumni Service Award from Carnegie Mellon University. Adam has presented and published in a number of venues including FIRST CTI, USENIX Security, and ACM Transactions on Information and System Security.

#STARWebcast #MITREATT&CK
Рекомендации по теме
Комментарии
Автор

Great walk-through. So easy to follow and clear to visualize.

abdops
Автор

32:06 This was published in 1984. That’s 30 years ago. And yet we are where we are. What happened? Sheer stupidity doesn’t provide a credible explanation given that there are enough people who are intelligent enough to understand. The only other possible explanation points to ill intent. The same with this cloud stupid madness.

Even if I could create something-anything, I won’t. Ever. One has to be utterly irresponsible to put anything in the hands of criminals even if they are disguised as defenders. Do you understand?

claudiamanta