Keynote: Cobalt Strike Threat Hunting | Chad Tilbury

  Рет қаралды 30,227

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

Күн бұрын

Cracked versions of Cobalt Strike have rapidly become the attack tool of choice among enlightened global threat actors, making an appearance in almost every recent major hack, including SolarWinds, the massive Hafnium attacks targeting Microsoft Exchange servers, and a majority of recent ransomware attacks. The use of Cobalt Strike is unsurprising as it provides an all-in-one framework for mounting large-scale network penetrations with an unparalleled amount of flexibility. The bad news is Cobalt Strike can be extremely stealthy. However, the good news is a known threat inevitably provides detection opportunities for defenders, and, currently, there is no larger known threat. Using examples taken directly from an actual enterprise-wide attack used in the SANS FOR508 class, this presentation will demonstrate Cobalt Strike-based attacks from both the attacker and defender perspectives. Attendees will gain insight into how Cobalt Strike operates and artifacts left behind via many of its common attack techniques, leaving with a range of practical detections that can be immediately put to use during incident response and threat hunting.
View upcoming Summits: www.sans.org/u/DuS
Download the presentation slides (SANS account required) at www.sans.org/u/1h3C
#CobaltStrike #ThreatHunting #DigitalForensics

Пікірлер: 14
@AirmanJH
@AirmanJH 2 ай бұрын
You gave me hope. Thank you! Also, you are one of the best presenters I’ve ever seen in this field. Clear, upbeat and interesting.
@normalhispanicdude
@normalhispanicdude Жыл бұрын
This is a world-class presentation. Kudos to Chad.
@mcichocki
@mcichocki 2 жыл бұрын
Highly relevant IR TTP’s and killer delivery.
@utewbisdadevil1594
@utewbisdadevil1594 2 жыл бұрын
Chad always does a great job. Good info here.
@johnnyg3606
@johnnyg3606 Жыл бұрын
Really excellent. Well done
@amilaandarage9734
@amilaandarage9734 2 жыл бұрын
Great stuff.. 👍
@bullethead1953
@bullethead1953 2 жыл бұрын
nice video!
@TheBashir007
@TheBashir007 10 ай бұрын
Pure gold
@andreevianna
@andreevianna 2 жыл бұрын
one question, those examples as refer just about cobalt strike http beacons right?
@Inh4t3
@Inh4t3 2 жыл бұрын
Well the pipe name indicates smb beacons.
@slickis
@slickis 2 жыл бұрын
beacon type at 22min shows beacon is https
@edwardmyers4417
@edwardmyers4417 2 жыл бұрын
Slide link is broken/not working.
@GGHTEAM
@GGHTEAM 2 жыл бұрын
just don't use the default !
@prisccaviana
@prisccaviana 2 жыл бұрын
Think this was a really brilliant talk.. however, as a feedback that microsoft story was totally unneeded.
DFIR 101: Digital Forensics Essentials | Kathryn Hedley
1:16:05
SANS Digital Forensics and Incident Response
Рет қаралды 33 М.
Investigating WMI Attacks
1:00:43
SANS Digital Forensics and Incident Response
Рет қаралды 26 М.
Luck Decides My Future Again 🍀🍀🍀 #katebrush #shorts
00:19
Kate Brush
Рет қаралды 7 МЛН
Climbing to 18M Subscribers 🎉
00:32
Matt Larose
Рет қаралды 35 МЛН
Homemade Professional Spy Trick To Unlock A Phone 🔍
00:55
Crafty Champions
Рет қаралды 57 МЛН
Threat Hunting via Sysmon - SANS Blue Team Summit
51:01
SANS Institute
Рет қаралды 59 М.
NCSAM: Threat Hunting 101
1:02:59
Cisco Talos Intelligence Group
Рет қаралды 2,6 М.
Common misconceptions and mistakes made in Threat Hunting
31:22
SANS Digital Forensics and Incident Response
Рет қаралды 4,1 М.
My “Aha!” Moment - Methods, Tips, & Lessons Learned in Threat Hunting - SANS THIR Summit 2019
33:41
SANS Digital Forensics and Incident Response
Рет қаралды 13 М.
Threat Hunting via DNS with Eric Conrad - SANS Blue Team Summit 2020
54:56
SANS Cyber Defense
Рет қаралды 22 М.
Detecting & Hunting Ransomware Operator Tools: It Is Easier Than You Think!
1:21:16
SANS Digital Forensics and Incident Response
Рет қаралды 22 М.
The Cycle of Cyber Threat Intelligence
1:00:27
SANS Digital Forensics and Incident Response
Рет қаралды 111 М.
CQTools: The New Ultimate Hacking Toolkit
1:01:55
Black Hat
Рет қаралды 177 М.
Will the battery emit smoke if it rotates rapidly?
0:11
Meaningful Cartoons 183
Рет қаралды 31 МЛН
#miniphone
0:16
Miniphone
Рет қаралды 3,6 МЛН
cute mini iphone
0:34
승비니 Seungbini
Рет қаралды 4,8 МЛН
Урна с айфонами!
0:30
По ту сторону Гугла
Рет қаралды 7 МЛН