SESSION ID: CSV-T10 Cloud Threat Hunting Sherri Davidoff Matt Durrin CEO, LMG Security @sherridavidoff Security Consultant, LMG Security @EvilMattXD #RSAC #RSAC Who Are We? Sherri Davidoff, CEO, LMG Security & BrightWise – Training: DoD, Google, Comcast, Mastercard, etc. – Black Hat “Data Breaches” course – NEW! “Data Breaches” book Matt Durrin, LMG Security – Cybersecurity Consultant – Education and training – Black Hat Co-Instructor – Evil, sometimes. 2 #RSAC What's In The Cloud? Hosted Networks Data Storage Web Applications Email And more… https://www.besttechie.com/forums/topic/35241-how-to-find-the-best-cloud-service-provider-for-your-needs/ 3 #RSAC Define the Terms What is “Threat Hunting”? How is this different from IDS? How do we hunt in the cloud? What tools and techniques do we use? https://www.sans.org/reading-room/whitepapers/analyst/build-threat-hunting-capability-aws-39300 4 #RSAC Threat Hunting Times Locations Activities Behavior 5 #RSAC MITRE ATT&CK Framework 6 #RSAC Evil Braelynn Strikes! 7 #RSAC #RSAC Microsoft Audit Log Search 9 #RSAC A Recursive Solution 10 #RSAC Review the Data 11 #RSAC We Can Do Better 12 #RSAC #RSAC Splunk Joins The Hunt! 14 #RSAC Who Logged In From Chicago?!?! Not Part Of The Plan! 15 Check Your Score Office 365 Score 16 #RSAC #RSAC Microsoft Security 17 #RSAC Leaving The Door Open https://www.scmagazineuk.com/44-million-azure-ad-microsoft-accountscompromised-password-problems-highlighted/article/1668138 https://www.helpnetsecurity.com/2019/12/09/compromised-passwords-microsoft-accounts/ 18 #RSAC New Host Configuration 19 #RSAC We’re Not Alone… Tricky! https://www.shodan.io/search?query=Remote+Desktop+org%3A%22Microsoft+Azure%22 20

pdf文档 2020_USA20_CSV-T10_01_Cloud Threat Hunting

安全研究库 > 国外研究报告 > 云安全和虚拟化 > 文档预览
45 页 0 下载 54 浏览 0 评论 0 收藏 3.0分
温馨提示:如果当前文档出现乱码或未能正常浏览,请先下载原文档进行浏览。
2020_USA20_CSV-T10_01_Cloud Threat Hunting 第 1 页 2020_USA20_CSV-T10_01_Cloud Threat Hunting 第 2 页 2020_USA20_CSV-T10_01_Cloud Threat Hunting 第 3 页 2020_USA20_CSV-T10_01_Cloud Threat Hunting 第 4 页 2020_USA20_CSV-T10_01_Cloud Threat Hunting 第 5 页
下载文档到电脑,方便使用
还有 40 页可预览,继续阅读
本文档由 张玉竹2022-04-08 10:19:04上传分享
给文档打分
您好可以输入 255 个字符
安信天行文库的中文名是什么?( 答案:安信天行 )
评论列表
  • 暂时还没有评论,期待您的金玉良言