Business Email Compromise; Office 365 Making Sense of All the Noise

  Рет қаралды 15,329

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

Күн бұрын

Office 365, or O365, has made online applications easier for businesses of all sizes. Its also created a significant attack vector that attackers have been exploiting for years to the tune of BILLIONS a year. Business Email Compromise, or BEC, is the name given to these types of email-based attacks that have cost businesses over $12 billion, and show little sign of slowing down. It's time we turn the tables.
In this webcast, we will examine how and why O365 has become such a successful attack vector. Specifically, we are going to examine examples of spoofed and fraudulent emails and how the attackers work to understand the flow of money within your organization. We will also be going to look at attacker infrastructure and examine sample code that they use to pilfer credentials from your organization.
We are not stopping there we will also talk about how you can defend yourself against these attacks. We've got a brand new tool to release for O365 log analysis - OLAF. We will also talk about what you can do inside O365 RIGHT NOW to protect yourselves against these types of attacks.
Listen to this packed session of attacker tactics, log analysis, defensive mechanisms, and more!
About the presenter:
Matt Bromiley is a SANS Certified Digital Forensics and Incident Response instructor, teaching Advanced Digital Forensics, Incident Response, and Threat Hunting (FOR508: www.sans.org/course/advanced-... ) and Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response (FOR572: www.sans.org/course/advanced-..., and a GIAC Advisory Board member. He is also a principal incident response consultant at a major incident response and forensic analysis company, combining experience in digital forensics, incident response/triage and log analytics. His skills include disk, database, memory and network forensics, as well as network security monitoring. Matt has worked with clients of all types and sizes, from multinational conglomerates to small, regional shops. He is passionate about learning, teaching and working on open source tools.

Пікірлер: 10
@firstsurname8406
@firstsurname8406 5 жыл бұрын
Does OLAF uses MTL logs as well or is there a better tool for MTL?
@JavierCanzobre
@JavierCanzobre 4 жыл бұрын
Thanks!
@argha2091
@argha2091 5 жыл бұрын
What a wonderful presentation. Great work !!
@emmanuelkalu3663
@emmanuelkalu3663 2 жыл бұрын
the hunter and the hunted.
@juancruz-b2715
@juancruz-b2715 3 жыл бұрын
the way this guy knows his craft when he speaks is exactly the kind of guy in cyber i want to be as well. wonder how long it'll take me. >.
@decidermcmolar-mn1kz
@decidermcmolar-mn1kz Жыл бұрын
Mi
@kimballfeeley7672
@kimballfeeley7672 3 жыл бұрын
A
The Cycle of Cyber Threat Intelligence
1:00:27
SANS Digital Forensics and Incident Response
Рет қаралды 110 М.
What Event Logs  Part 2  Lateral Movement without Event Logs
1:01:00
SANS Digital Forensics and Incident Response
Рет қаралды 11 М.
Why You Should Always Help Others ❤️
00:40
Alan Chikin Chow
Рет қаралды 6 МЛН
Email | How to ask for something POLITELY | 2021
7:25
Worldwide Speak
Рет қаралды 101 М.
Incident Response: Business Email Compromise | Virtual Ninja Training with Heike Ritter
29:16
Email Header Analysis and Forensic Investigation
22:59
13Cubed
Рет қаралды 142 М.
Getting Started with the SIFT Workstation Webcast with Rob Lee
1:10:47
SANS Digital Forensics and Incident Response
Рет қаралды 129 М.
SANS DFIR Webcast - Incident Response Event Log Analysis
48:50
SANS Digital Forensics and Incident Response
Рет қаралды 79 М.
Phishing for Funds: Understanding Business Email Compromise
59:45
Top 11 OSINT Tools of 2024 by Ritu Gill  - #3 is Essential
4:38
Forensic OSINT
Рет қаралды 2,8 М.
Introduction to Windows Forensics
1:04:33
13Cubed
Рет қаралды 166 М.
Digital Forensics Truths That Turn Out To Be Wrong - SANS DFIR Summit 2018
34:59
SANS Digital Forensics and Incident Response
Рет қаралды 24 М.
The power button can never be pressed!!
0:57
Maker Y
Рет қаралды 55 МЛН
Mi primera placa con dios
0:12
Eyal mewing
Рет қаралды 458 М.
Nokia 3310 versus Red Hot Ball
0:37
PressTube
Рет қаралды 3,8 МЛН
ЭТОТ ЗАБЫТЫЙ ФЛАГМАН СИЛЬНО ПОДЕШЕВЕЛ! Стоит купить...
12:54
Thebox - о технике и гаджетах
Рет қаралды 132 М.
Дени против умной колонки😁
0:40
Deni & Mani
Рет қаралды 9 МЛН
cool watercooled mobile phone radiator #tech #cooler #ytfeed
0:14
Stark Edition
Рет қаралды 7 МЛН