DFIR Summit 2016: Leveraging Cyber Threat Intelligence in an Active Cyber Defense

  Рет қаралды 15,751

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

Күн бұрын

sans.org/dfirsummit
Two useful disciplines are cyber threat intelligence and active cyber defense. However, there is confusion around both of these areas that leads to a perception of hype and cost instead of vital tools for defenders to use. In the case of threat intelligence, many security companies have offered a range of threat intelligence products and feeds but there is confusion in the community as a whole as to how to maximize the value out threat intelligence. With active defense, there has been an attempt to brand this strategy as a hack-back or otherwise offense based practice whereas the strategy for an active defense has existed long before the word ‘cyber’ and is focused around practices such as incident response. This presentation will examine the current state of cyber threat intelligence and active cyber defense as well as provide strategies for leveraging proven cyber intelligence models within active cyber defense operations
Speakers:
Robert M. Lee (@robertmlee), Author & Instructor, SANS Institute
Robert M. Lee is a SANS Certified Instructor and the course author of SANS ICS515: Active Defense and Incident Response and the co-author of SANS FOR578: Cyber Threat Intelligence. Robert is also CEO of Dragos Security, a non-resident National Cyber Security Fellow at New America focusing on policy issues relating to the cybersecurity of critical infrastructure, and a PhD candidate at Kings College London. For his research and focus areas, he was named one of Passcode’s Influencers and awarded EnergySec’s 2015 Cyber Security Professional of the Year. Robert obtained his start in cybersecurity in the U.S. Air Force where he served as a cyber warfare operations officer. He has performed defense, intelligence, and attack missions in various government organizations including the establishment of a first-ofits-kind ICS/SCADA cyber threat intelligence and intrusion analysis mission.
Erick Mandt, Analyst, Air Force Office of Special Investigations (AFOSI)
Erick Mandt is a 25-year intelligence professional with broad experience in cyber counterintelligence, signals intelligence, intelligence analysis, and language analysis. He currently works as an analyst for the Air Force Office of Special Investigations (AFOSI) open-source intelligence team where he supports a full range of law enforcement and counterintelligence investigations and operations. Erick’s research and analytical interests focus on integrating critical thinking and structured analysis processes into active cyber defense operations. Prior to joining AFOSI, Erick served 20 years as a cryptologic linguist for the U.S. Navy. He is proficient in Russian, Bulgarian, Serbian-Croatian, and Macedonian. Erick has an undergraduate degree in Russian Area Studies from Excelsior College and an MS in Cybersecurity from Utica College.
DFIR Summit Agenda:www.sans.org/event-downloads/...
DFIR Summit Brochure:www.sans.org/event-downloads/... .

Пікірлер: 1
@faanross
@faanross Жыл бұрын
Incredible talk that I think FINALLY made me realize the value of models. Good job gents 🤘🏻
Intelligence Preparation of the Cyber Environment - SANS Cyber Threat Intelligence Summit 2018
27:43
SANS Digital Forensics and Incident Response
Рет қаралды 12 М.
LOCKED OUT! Detecting, Preventing, & Reacting to Human Operated Ransomware
56:32
SANS Digital Forensics and Incident Response
Рет қаралды 9 М.
Khó thế mà cũng làm được || How did the police do that? #shorts
01:00
Homemade Professional Spy Trick To Unlock A Phone 🔍
00:55
Crafty Champions
Рет қаралды 59 МЛН
The child was abused by the clown#Short #Officer Rabbit #angel
00:55
兔子警官
Рет қаралды 15 МЛН
DIY DNS DFIR: You’re Doing it WRONG: Threat Hunting Summit 2016
29:33
SANS Digital Forensics and Incident Response
Рет қаралды 8 М.
Espionage and Intelligence
1:03:39
Dartmouth
Рет қаралды 197 М.
Confessions of a cyber spy hunter | Eric Winsborrow | TEDxVancouver
20:49
Job Role Spotlight: Cyber Threat Intelligence
29:03
SANS Institute
Рет қаралды 10 М.
Threat Intelligence and the Limits of Malware Analysis with Joe Slowik - SANS CTI Summit 2020
26:52
SANS Digital Forensics and Incident Response
Рет қаралды 5 М.
AlphaBay Market: Lessons From Underground Intelligence Analysis - SANS CTI Summit 2018
32:40
SANS Digital Forensics and Incident Response
Рет қаралды 19 М.
Threat Hunting via DNS with Eric Conrad - SANS Blue Team Summit 2020
54:56
SANS Cyber Defense
Рет қаралды 22 М.
Хотела заскамить на Айфон!😱📱(@gertieinar)
0:21
Взрывная История
Рет қаралды 4,2 МЛН
Неразрушаемый смартфон
1:00
Status
Рет қаралды 1,9 МЛН
Урна с айфонами!
0:30
По ту сторону Гугла
Рет қаралды 7 МЛН
Lid hologram 3d
0:32
LEDG
Рет қаралды 9 МЛН