A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Subscribestar or Patreon

Search Irongeek.com:

Affiliates:
Irongeek Button
Social-engineer-training Button

Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


Advanced threat hunting with open-source tools and no budget - Joseph DePlato SecureWV/Hack3rcon 2018 (Hacking Illustrated Series InfoSec Tutorial Videos)

Advanced threat hunting with open-source tools and no budget
Joseph DePlato
SecureWV/Hack3rcon 2018

This talk is designed to provide you the skills necessary to hunt for malicious actors on the networks you defend​. I will teach you how to do this using primarily Open-Source software and technologies​. You CAN have effective cybersecurity on a limited budget​. Part 1: OSINT Network defenses - talk through creating an open-source network intrusion detection sensor leveraging a Raspberri Pi and Suricata. We have successfully deployed these sensors on network up to 500 endpoints. We will cover the basics of what Suricata is as well as how to use a Pi for better visibility within a network. Part 2: OSINT Threat Intel - talk through using a number of different tools for faster false positive detection. Will also speak about how to automate some of the OSINT feeds for the Suricata sensor - daily OSINT updates protecting the network. Part 3: Now that we have some tooling in place - how do we look for anomalous activity. Will cover how to approach an investigation, define attackers and define a compromise. Part 4: Introduction of our F3EA Framework for threat hunting. Explore all 5 sections and define what each are and how they relate to the overall investigation. The Framework is iterative and feeds itself. Part 5: Threat Hunting models - practical examples of how to hunt and a number of common techniques that we have found highly successful.

Joseph is a professional hacker who has served as a senior cybersecurity consultant to BP, American Express, Home Depot, and Palantir. Joe speaks at a variety of cybersecurity events and leads the Incident Response and technical investigations team at Bluestone Analytics.

Back to SecureWV 2017 video list

Printable version of this article

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast