SEC504: Hacker Tools, Techniques, and Incident Handling

Unlock industry insights and hands-on learning with upcoming SANS webcasts and workshops. View archived webcasts here.
In the world of application security, the influx of alerts has reached overwhelming levels, making it increasingly challenging to effectively monitor and respond. This surge in alerts often leads to unresolved issues and persistent vulnerabilities. Are we sounding the alert too frequently? Is there a way to strike a balance between reducing the noise and maintaining robust security?
Everyone has alerts and everyone has different forms of intelligence they use to try and detect, research, and respond to a threat within their environment. As a security practitioner, you know the process and time involved to “connect the dots” between the intelligence available and what is in your environment is often time consuming and requires a good deal of knowledge to correlate. These are all the realities of the world we currently live in as cybersecurity professionals…. but what if we could leverage a new approach to automate these efforts and also better protect your organization in ways that weren’t possible before?
This program, from SANS and Sinclair Community College, in collaboration with the National Science Foundation (NSF), is designed to engage and empower underrepresented student groups, including women, Black, African American, Latino(a), Hispanic and Indigenous students, providing them with an opportunity to excel in cybersecurity education this summer and prepare them for future jobs.
AI seems to have taken the world by storm lately. From ChatGPT to automated spear phishing techniques, the security world has already seen changes in processes, automation, and threat detection - not to mention attack techniques! The recent surge of AI opens up opportunities for both defenders and adversaries alike. What can we build? What can we automate? How can we use AI to augment security to buy time and add another layer of defense to our enterprise?In this AI-focused solutions forum, we’ll examine how AI will continue to change the security landscape. After all - tools for one are tools for many. Just as defenders benefit from AI capabilities, adversaries have found their own uses. From writing malware to discovering vulnerable systems, threat actors have found efficiencies using AI capabilities. Defenders must be prepared for how AI will help bolster defenses, while adversaries use it to ramp up their attacks.Join us for our first-ever SANS AI & ChatGPT Solutions Forum, where we will discuss the risks, vulnerabilities, and benefits linked with the rapid introduction of machine learning and artificial intelligence in the world. Information security experts will bring their ideas, theories, and case studies of how AI will impact security for years to come.Join in on the action! Connect with fellow attendees and our event chairs in the SANS Solutions Forum Interactive Slack Workspace. Sign in once and you'll be all set for the rest of our 2023 Solutions Forums. We'll see you there!
It appears that every few months, there's news of yet another cloud breach stemming from a carelessly configured cloud storage solution. While this isn't the default for most cloud vendors, some users still manage to make their cloud data publicly accessible by going out of their way - sometimes to a significant extent. Whether it's out of ignorance or convenience, it doesn't matter - this practice must come to an end.
The increased size and complexity of enterprise networks, combined with the increasing scale of attacks means that we need to develop new ways to respond to our adversaries. In this talk we will look at the challenges faced during enterprise IR and how we can use triage & automation to help speed up our response.
中小企業や非営利団体など、リソースに制約のある環境で事業を展開する組織にとって、サイバー空間における脅威の広がりと巧妙さはますます増しており、大きな課題となっています。機密データやミッションクリティカルなインフラをサイバー攻撃から守るためには、強固なサイバーセキュリティ対策が必要ですが、それには多額な費用が必要になることが多いです。
経済安全保障は、アジア太平洋地域の経営層にとって益々重要な課題となりつつある中、サイバー防衛担当者たちがサプライチェーンリスク管理や業務継続性上で果たす役割も高まっている。本セッションでは、ランサムウェア攻撃やウクライナで続く戦争のアジア太平洋地域への影響の可能性について分析し、サイバー防衛担当者たちが如何に経営層を支え、経済安全保障に寄与できるかを分析する。
DFIR の分野での15年以上の経験から、自分のキャリアパスを振り返り、どのような学びが自分のスキルや能力を最もレベルアップさせたかについて考えをまとめてみました。このキャリアパスには、軍事、政府、コンサルティング、産業などの様々な環境における個人貢献(IC)とマネジメント(M)両方の業務内容が含まれています。このプレゼンテーションでは、あなたのキャリアを明日にでも向上させるかもしれない技術的スキルとソフトスキルの両方の視点で紹介します。
ランサムウェアは、かつては熟練したサイバー攻撃者に限定された脅威でしたが、Ransomware as a Service(RaaS)ビジネスモデルの登場によって広く悪用されるようになり、その脅威は限定的なものではなくなってきています。
ホストベースのフォレンジックの経験は豊富であっても、クラウドベースのインフラについて扱った経験が少ない担当者が、クラウドにおけるインシデントレスポンスにおいて陥りがちな落とし穴についてご紹介します。また、DFIRチームメンバーがクラウドベースのフォレンジック調査に対応できるよう、管理職がトレーニングや演習に投資すべき理由についても説明します.
近年のサイバー犯罪の増加に伴い、組織が組織的な犯罪者集団に狙われる可能性が高まっています。この講演では、DFIRに対するランドスケープの進化に焦点を当てて技術的な観点から情報を共有します。