A Practical Case of Threat Intelligence - From IoC to Unraveling an Attacker Infrastructure

  Рет қаралды 5,412

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

Жыл бұрын

SANS Cyber Threat Intelligence Summit 2023
Luna Moth: A Practical Case of Threat Intelligence - From IoC to Unraveling an Attacker Infrastructure
Oren Biderman, Senior Incident Response & Threat Hunting Expert, Sygnia
Noam Lifshitz, Incident Response Team Leader, Sygnia
Pivoting, or being able to move between indicators of compromise and up David Bianco's Pyramid of Pain to uncover the threat actor's tactics, techniques and procedures (TTPs) is a common practice in Cyber threat intelligence (CTI) operations. However, it is sometimes regarded more as a black art than a science. In this talk we will discuss a threat group dubbed "Luna Moth" that leverages call-back phishing techniques, as a case study to walk you through the process of leveraging indicators of compromise identified while responding to several security breaches to uncover the threat actor's infrastructure. The talk will include: 1. An overview of several breaches we investigated focusing on the attacker's modus operandi. 2. A breakdown of two techniques which were used to pivot between IOCs to uncover and track the threat actor infrastructure. 3. Example of employing automation to continuously monitor the threat actor's infrastructure.
View upcoming Summits: www.sans.org/u/DuS
Download the presentation slides (SANS account required) at www.sans.org/u/1iaE

Пікірлер: 2
@dewardvide
@dewardvide 4 ай бұрын
Eye opening. Thank You!
@the-baker
@the-baker 9 ай бұрын
That's very interesting. Thank you very much.
Deconstructing the Analyst Mindset
49:14
SANS Digital Forensics and Incident Response
Рет қаралды 7 М.
My “Aha!” Moment - Methods, Tips, & Lessons Learned in Threat Hunting - SANS THIR Summit 2019
33:41
SANS Digital Forensics and Incident Response
Рет қаралды 13 М.
The child was abused by the clown#Short #Officer Rabbit #angel
00:55
兔子警官
Рет қаралды 15 МЛН
СНЕЖКИ ЛЕТОМ?? #shorts
00:30
Паша Осадчий
Рет қаралды 8 МЛН
Always be more smart #shorts
00:32
Jin and Hattie
Рет қаралды 36 МЛН
Keynote: Cobalt Strike Threat Hunting | Chad Tilbury
45:45
SANS Digital Forensics and Incident Response
Рет қаралды 30 М.
What Does an LLM-Powered Threat Intelligence Program Look Like?
40:11
Human Intelligence Operations in the Age of AI
1:03:30
The Bush School of Government & Public Service
Рет қаралды 3,2 М.
Understanding & Managing Collection to Support Threat Intelligence Analysis - SANS CTI Summit
24:10
SANS Digital Forensics and Incident Response
Рет қаралды 6 М.
Job Role Spotlight: Cyber Threat Intelligence
29:03
SANS Institute
Рет қаралды 10 М.
Hunting Cyber Threat Actors with TLS Certificates
27:07
SANS Digital Forensics and Incident Response
Рет қаралды 4,4 М.
Threat Hunting via DNS with Eric Conrad - SANS Blue Team Summit 2020
54:56
SANS Cyber Defense
Рет қаралды 22 М.
Gizli Apple Watch Özelliği😱
0:14
Safak Novruz
Рет қаралды 4,3 МЛН
Asus  VivoBook Винда за 8 часов!
1:00
Sergey Delaisy
Рет қаралды 1,1 МЛН
How To Unlock Your iphone With Your Voice
0:34
요루퐁 yorupong
Рет қаралды 27 МЛН
Will the battery emit smoke if it rotates rapidly?
0:11
Meaningful Cartoons 183
Рет қаралды 33 МЛН
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00
Корнеич
Рет қаралды 3,2 МЛН