SANS Webcast: Effective (Threat) Hunting Techniques

Поделиться
HTML-код
  • Опубликовано: 12 авг 2019
  • Prevention is not everything, and without detection, we're sitting ducks. In this talk, Chris Dale will present on the concept of Threat Hunting and introduce good and effective threat hunting techniques for your security teams. How can we detect the bad guys, even the more notorious and advanced threats; with the goal to kick them out before they can secure their objectives? There will always be a way for a threat actor to find a way inside your network, whether it be criminals after monetization, Advanced Persistent Threats or inside threats. What are effective ways of finding them before damage is done?
    Want to learn more about possible Threat Hunting Techniques? You can take our SEC504 class that focuses on these techniques. More information can be found at www.sans.org/course/hacker-te...
    For information about Chris Dale and to find upcoming courses he's teaching visit: www.sans.org/profiles/chris-d...
    You can also follow Chris on Twitter @ChrisADale

Комментарии • 10

  • @sarthak913
    @sarthak913 5 месяцев назад

    I came across this today. I found this useful. Thanks Chris and SANS for sharing this.

  • @vivayan
    @vivayan 4 года назад +1

    Very useful presentation. Thank you for your share.

    • @ChrisDale
      @ChrisDale 3 года назад

      Glad you liked it :)

  • @vishnuvardhan286
    @vishnuvardhan286 4 года назад +2

    Good insight

  • @lmaoroflcopter
    @lmaoroflcopter 3 года назад +7

    At around 9:00 there is mention of a "beautiful pdf" that discusses TTPs of common threat actors, any chance we can get a link to that?
    To pre-empt the comments. I am already well aware of MITRE. Just looking for commentary.
    Edit:
    In fact there a whole lot of tooling mentioned in this presentation that would be really good to take a look at. Any chance we can get all external tool mentions linked out in the description?
    That jpcert tool analysis tool looks brilliant.

    • @ChrisDale
      @ChrisDale Год назад

      They removed it, but it's on archive org: web.archive.org/web/20201102195334/www.thaicert.or.th/downloads/files/A_Threat_Actor_Encyclopedia.pdf

  • @ImGeoX
    @ImGeoX 3 года назад

    Should've mentioned the Attack Mitre framework and long tail analysis