ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

Detecting & Hunting Ransomware Operator Tools: It Is Easier Than You Think!

Автор: SANS Digital Forensics and Incident Response

Загружено: 2023-03-31

Просмотров: 31006

Описание: Ryan Chapman, SANS Instructor and author of SANS FOR528: Ransomware for Incident Responders, provides an overview of tools leveraged often by ransomware operators. Though a multitude of ransomware operations and affiliate groups exist, we see a great deal of overlap between the tools leveraged by these groups (and that's an understatement!).
Are you following and utilizing projects such as Living Off Trusted Sites (LOTS) and Bring Your Own Vulnerable Driver (BYOVD)?
Are you looking for Bloodhound/SharpHound?
Do you know how PsExec-like tools work at a forensic level (e.g., smbexec)? Are you hunting for rogue installations of Remote Monitoring & Maintenance (RMM) tools?
Did you know that data exfiltration tools like Winzip, 7Zip, WinSCP, FileZilla, Rclone, and MEGAsync often leave forensic artifacts that are absolute snitches that are just phenomenal for us cyber defenders?
In this session he will discuss these tools, and show you how they work, and share tips & tricks related to preventing, detecting, and hunting them!

For presentation slides visit here: https://www.sans.org/webcasts/communi...

About FOR528: Ransomware for Incident Responders course

FOR528: Ransomware for Incident Responders (www.sans.org/FOR528) covers the entire life cycle of an incident, from initial detection to incident response and postmortem analysis. While there is no way to prepare for every scenario possible, our course uses deftly devised, real-world attacks and their subsequent forensic artifacts to provide you, the analyst, with all that you need to respond when the threat become a reality.

About Ryan Chapman

Ryan is a Principal Incident Response Consultant with Palo Alto Networks. He has worked in the Digital Forensics & Incident Response (DFIR) realm for over 10 years. He is the author of the new SANS course on ransomware FOR528: Ransomware for Incident Responders and he has also taught the SANS FOR610: Reverse Engineering Malware. During his career, Ryan has worked in Security Operations Center and Cyber Incident Response Team roles that handled incidents from inception through remediation. With Ryan, it's all about the blue team, including sifting through Packet Captures, researching domains and IPs, hunting through log aggregation utilities, analyzing malware, and performing host and network forensics.

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
Detecting & Hunting Ransomware Operator Tools: It Is Easier Than You Think!

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

Investigating WMI Attacks

Investigating WMI Attacks

Handling Ransomware Incidents: What YOU Need to Know!

Handling Ransomware Incidents: What YOU Need to Know!

License to Kill: Malware Hunting with the Sysinternals Tools

License to Kill: Malware Hunting with the Sysinternals Tools

The Truth about Ransomware: Its not Complicated!

The Truth about Ransomware: Its not Complicated!

John Hammond: Is cyber security hustle culture killing us?

John Hammond: Is cyber security hustle culture killing us?

OSINT для начинающих: узнайте всё о ком угодно!

OSINT для начинающих: узнайте всё о ком угодно!

Хакер демонстрирует самые безумные гаджеты в своем EDC

Хакер демонстрирует самые безумные гаджеты в своем EDC

Как плохая операция OPSEC привела к 4 арестам

Как плохая операция OPSEC привела к 4 арестам

My “Aha!” Moment - Methods, Tips, & Lessons Learned in Threat Hunting - SANS THIR Summit 2019

My “Aha!” Moment - Methods, Tips, & Lessons Learned in Threat Hunting - SANS THIR Summit 2019

вам НУЖНА эта сертификация аналитика SOC

вам НУЖНА эта сертификация аналитика SOC

REAL Ransomware Chat Logs

REAL Ransomware Chat Logs

Learning to Combat Ransomware

Learning to Combat Ransomware

Чем ОПАСЕН МАХ? Разбор приложения специалистом по кибер безопасности

Чем ОПАСЕН МАХ? Разбор приложения специалистом по кибер безопасности

SANS Threat Analysis Rundown - Ransomware with guest speaker Ryan Chapman

SANS Threat Analysis Rundown - Ransomware with guest speaker Ryan Chapman

Keynote: Cobalt Strike Threat Hunting | Chad Tilbury

Keynote: Cobalt Strike Threat Hunting | Chad Tilbury

OSINT: как найти ВСЮ информацию о ЛЮБОМ ЧЕЛОВЕКЕ!!

OSINT: как найти ВСЮ информацию о ЛЮБОМ ЧЕЛОВЕКЕ!!

LOCKED OUT! Detecting, Preventing, & Reacting to Human Operated Ransomware

LOCKED OUT! Detecting, Preventing, & Reacting to Human Operated Ransomware

The Detection Engineering Process w/ Hayden Covington #livestream

The Detection Engineering Process w/ Hayden Covington #livestream

Hunting and Scoping A Ransomware Attack

Hunting and Scoping A Ransomware Attack

Malware Hunting with Mark Russinovich and the Sysinternals Tools

Malware Hunting with Mark Russinovich and the Sysinternals Tools

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]