PIPEDREAM - Most Flexible & Capable ICS Malware To Date

Поделиться
HTML-код
  • Опубликовано: 6 июл 2024
  • Rob Lee, founder and CEO of Dragos, gives the opening keynote of S4x22 Day 2 on the ICS malware they call PIPEDREAM. The first third of the keynote focuses on what this means for asset owners and how they should react. Who should prioritize threat hunting ("you don't get to vote if you are a target")?
    The remainder of the talk is on the malware itself and a bit on mitigations. The PLC Proxy capabilities is particularly interesting. Even if you have heard about INCONTROLLER/PIPEDREAM before you will find this a worthwhile watch.
  • НаукаНаука

Комментарии • 11

  • @believe_it712
    @believe_it712 2 года назад +3

    Haha love the final part message to the adversaries

  • @tonio071273
    @tonio071273 2 года назад +2

    Great mapping of Pipedream along Purdue and MITRE, thx Mr. Lee!🙌

  • @aryamarga108
    @aryamarga108 Год назад

    Also a very good point by Robert in regards to predicting threat actors' targeting. It's a waste of time to debate whether you are likely to be targeted or not. Focus on deploying robust security controls and always be prepared for the unexpected.

  • @aryamarga108
    @aryamarga108 Год назад +1

    Schrodinger ICS, haha. Good point to invest more in detection and response as opposed to concentrating all resources on prevention.

  • @HexaSquirrel
    @HexaSquirrel 2 года назад

    Great talk, Rob!

  • @aryamarga108
    @aryamarga108 Год назад +1

    Lateral movement monitoring. Not just what comes in and goes out.

  • @fredericoferreira5581
    @fredericoferreira5581 2 года назад

    Great talk

  • @ranikehat3913
    @ranikehat3913 2 года назад

    Great Talk

  • @aryamarga108
    @aryamarga108 Год назад

    Very interesting that Dragos does not do attribution unless it affects the incident response process. It seems like an efficient way to approach things given that the priority should be to formulate how to properly defend the systems at hand.

  • @aryamarga108
    @aryamarga108 Год назад

    These threat actors are really organized. I didn't know there were separate groups that specialized in access or the activity in itself.

  • @The-Blind-Witch
    @The-Blind-Witch 2 года назад

    Are you certain the adversaries' tradecraft error wasn't intentional as a warning signal from the adversary nation state to the USA?