Sophos X-Ops Incident Response: How To Investigate Rclone Data Exfiltration

Поділитися
Вставка
  • Опубліковано 20 вер 2024
  • Robert Weiland of the Sophos X-Ops Incident Response team walks viewers through a data-exfiltration investigation, starting with an idea of which system on the affected estate might have been involved with the incident, and ending with an understanding of the tools used by the attacker - and, crucially, which files were taken. For more information or to comment, please visit the X-Ops blog post based on this video: news.sophos.co...
    00:00 Introduction
    00:17 The Search for Network Traffic Data query
    01:37 Checking the data against Virus Total
    02:37 The File Attributes and Metadata query
    03:50 The All Traffic Sent query
    04:57 The File System Interactions query
    06:04 The Remote Desktop Login Events query
    07:41 Wrapup

КОМЕНТАРІ •