Clustering Attacker Behavior: Connecting the Dots in the RaaS Ecosystem

  Рет қаралды 1,374

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

4 ай бұрын

As ransomware-as-a-service (RaaS) offerings arose on the scene, the volume and variety of ransomware attacks greatly expanded. Now, dozens of affiliates are deploying the same variant, leading to differing attack chains depending on who's behind the intrusion. This session walks through organizational clustering efforts when it comes to the messy world of ransomware affiliates and highlights how to separate the common tactics from the narrow details that may be indicative of a specific affiliate. Featuring case studies of two Threat Activity Clusters (TACs) tracking ransomware affiliates, this session will demonstrate how identifying unique indicators in attacks can assist in connecting the dots across incidents, thus allowing us to determine a pattern of attacker behavior independent of the ransomware variant deployed. In this talk, analysts will learn how to compare attack chains across incidents and identify overlaps in TTPs and indicators, in turn enabling them to generate actionable intelligence to form effective detections and more quickly identify malicious activity before ransomware is deployed.
View upcoming Summits: www.sans.org/u/DuS
SANS Cyber Threat Intelligence Summit 2024
Clustering Attacker Behavior: Connecting the Dots in the RaaS Ecosystem
Morgan Demboski, Threat Intelligence Analyst, Sophos

Пікірлер: 1
@Lionking24484
@Lionking24484 3 ай бұрын
Very Informational, Threat activity clustering is a unique way to categorise behaviours and mitigate the risks of unauthorized access to the organisations
SANS Threat Analysis Rundown (STAR)
59:41
SANS Digital Forensics and Incident Response
Рет қаралды 1,1 М.
Thinking DFIRently From Entry to Specialty
1:37:51
SANS Digital Forensics and Incident Response
Рет қаралды 2,4 М.
1❤️
00:17
Nonomen ノノメン
Рет қаралды 4,5 МЛН
Tom & Jerry !! 😂😂
00:59
Tibo InShape
Рет қаралды 60 МЛН
Must-have gadget for every toilet! 🤩 #gadget
00:27
GiGaZoom
Рет қаралды 11 МЛН
Exploring Ransomware Builders
50:00
Cyber from the Frontlines
Рет қаралды 2,6 М.
How Threat Intelligence Helped Us Defend and Respond to a Nation-State-Sponsored Threat Actor
29:56
SANS Digital Forensics and Incident Response
Рет қаралды 517
SANS Threat Analysis Rundown (STAR)
1:03:45
SANS Digital Forensics and Incident Response
Рет қаралды 1 М.
RaaS Services On The Dark Web
43:38
CYBER RANGES
Рет қаралды 2,1 М.
FOR528: Ransomware & Cyber Extortion Course Overview
22:38
SANS Digital Forensics and Incident Response
Рет қаралды 793
FOR589: Cybercrime Intelligence Overview
5:47
SANS Digital Forensics and Incident Response
Рет қаралды 1,5 М.
Best mobile of all time💥🗿 [Troll Face]
0:24
Special SHNTY 2.0
Рет қаралды 1,6 МЛН
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00
Корнеич
Рет қаралды 3,4 МЛН
Hisense Official Flagship Store Hisense is the champion What is going on?
0:11
Special Effects Funny 44
Рет қаралды 2,4 МЛН