Asia-24-Bohannon-CloudConsoleCartographer

3.0 2025-05-10 23 0 31407 KB 108 页 PDF
侵权投诉
Asia-24-Bohannon-CloudConsoleCartographer
Asia-24-Bohannon-CloudConsoleCartographer
Asia-24-Bohannon-CloudConsoleCartographer
Asia-24-Bohannon-CloudConsoleCartographer
Asia-24-Bohannon-CloudConsoleCartographer
摘要:

ASIA 2024Cloud Console CartographerTapping Into Mapping > Slogging Thru Logging•Introduction•Cloud Logs for Defenders•PROBLEM: Noisy Console Logs•SOLUTION: Mapping for Clarity•Tool Demo + ReleaseANDI AHMETIASSOCIATE THREAT RESEARCHER@SecEagleAnd1andi-ahmetiKosovoPermiso-io-tools/CloudGrapplerDANIEL BOHANNONPRINCIPAL THREAT RESEARCHER@danielhbohannondanielhbohannondanielbohannon/Invoke-Obfuscation/Invoke-CradleCrafter/Invoke-DOSfuscation/Revoke-ObfuscationUSA(5 yrs)(2 yrs)Role of Logs in Threat Hunting & IR•Logs == Visibility•Enable (if not by default)•Forward to secondary location•Process further:•Aggregate•Correlate•Search for malicious activityOn-Premvs Cloud Logs (Data source, not storage location)•Host & network logs•Native logging vs aftermarket products•Extremely granular:•E.g.process arguments, image loads, process memory, registry modifications, DNS lookups, network connections, logon types, file writes, file content•Numerous “fingerprints” in user/attacker activity•Intro

展开>> 收起<<
Asia-24-Bohannon-CloudConsoleCartographer

共 108 页,预览3页

还剩105页未读, 继续阅读

声明:企商查报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
作者: 分类: 属性:108 页 大小:31407 KB 格式:PDF 时间:2025-05-10

开通VIP享超值会员特权

  • 多端同步记录
  • 高速下载文档
  • 免费文档工具
  • 分享文档赚钱
  • 每日登录抽奖
  • 优质衍生服务
/ 3
客服
关注