TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays

3.0 2025-05-10 51 0 2340 KB 37 页 PDF
侵权投诉
TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays
TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays
TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays
TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays
TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays
摘要:

© Volexity Inc. | Proprietary & ConfidentialIt Has Been[0]Days Since the Last Edge-Device Security Incident1Tom LancasterCyberThreat | December 2024TLP: WHITE© Volexity Inc. | Proprietary & ConfidentialWhat are we talking about?• Edge-Devices• In the case of this talk – those intended to help protect networks• What do these attacks look like?• What might you do to identify or stop these attacks on your network?2© Volexity Inc. | Proprietary & Confidential3Case 1: Ivanti Connect Secure – Dec 23© Volexity Inc. | Proprietary & ConfidentialHow it started•Signature designed to detect webshells on Exchange4© Volexity Inc. | Proprietary & ConfidentialWebshell Discovery5© Volexity Inc. | Proprietary & ConfidentialThe Investigation Begins6•We acquire memory (RAM) and key files from the webserver•Logons to the Exchange Server came from 192.168.x.x -- ICS VPN device starting on December 6, 2023© Volexity Inc. | Proprietary & ConfidentialAll roads lead to….the ICS VPN Device7© Volexity Inc. | Prop

展开>> 收起<<
TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays

共 37 页,预览3页

还剩34页未读, 继续阅读

声明:企商查报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
作者: 分类: 属性:37 页 大小:2340 KB 格式:PDF 时间:2025-05-10

开通VIP享超值会员特权

  • 多端同步记录
  • 高速下载文档
  • 免费文档工具
  • 分享文档赚钱
  • 每日登录抽奖
  • 优质衍生服务
/ 3
客服
关注