TomLancaster-自上次边缘设备安全事件以来已经是零日ZeroDays






© Volexity Inc. | Proprietary & ConfidentialIt Has Been[0]Days Since the Last Edge-Device Security Incident1Tom LancasterCyberThreat | December 2024TLP: WHITE© Volexity Inc. | Proprietary & ConfidentialWhat are we talking about?• Edge-Devices• In the case of this talk – those intended to help protect networks• What do these attacks look like?• What might you do to identify or stop these attacks on your network?2© Volexity Inc. | Proprietary & Confidential3Case 1: Ivanti Connect Secure – Dec 23© Volexity Inc. | Proprietary & ConfidentialHow it started•Signature designed to detect webshells on Exchange4© Volexity Inc. | Proprietary & ConfidentialWebshell Discovery5© Volexity Inc. | Proprietary & ConfidentialThe Investigation Begins6•We acquire memory (RAM) and key files from the webserver•Logons to the Exchange Server came from 192.168.x.x -- ICS VPN device starting on December 6, 2023© Volexity Inc. | Proprietary & ConfidentialAll roads lead to….the ICS VPN Device7© Volexity Inc. | Prop
相关推荐
相关内容
-
腾讯云中国信通院中国通信标准化协会2024年AI大模型应用发展研究报告58页
分类:
时间:2025-05-09
标签:
格式:PDF
-
利用智能视觉组件简化嵌入式视觉开发
分类:
时间:2025-05-09
标签:
格式:PDF
-
俄勒冈州交通规划在快速变化和不确定的时代利用情景规划的案例研究
分类:
时间:2025-05-09
标签:
格式:PDF
-
SiCMOSFET技术进展与发展方向
分类:
时间:2025-05-09
标签:
格式:PDF
-
康嘉种业-每一头猪都代表着康嘉人的尊严
分类:
时间:2025-05-09
标签:
格式:PDF
-
汽车行业周报小米SU7Ultra正式发布Helix带动Figure效率跃升-25030118页
分类:
时间:2025-05-09
标签:
格式:PDF
-
杨昕-AI驱动抖音用户体验中台探索与实践
分类:
时间:2025-05-10
标签:
格式:PDF
-
跨国的AI采用者的肖像公司特征资产的互补性和生产力
分类:
时间:2025-05-10
标签:
格式:PDF
-
OrChechikandDanielFrank-从侦察到毁灭揭露伊朗AgriusAPT最新TTPs
分类:
时间:2025-05-10
标签:
格式:PDF
-
爱立信混合工作模式调查结果
分类:
时间:2025-05-10
标签:
格式:PDF