DIY DNS DFIR: You’re Doing it WRONG: Threat Hunting Summit 2016

Поділитися
Вставка
  • Опубліковано 26 лип 2024
  • DNS is one of those protocols that we, as DFIR practitioners, take for granted. Operationally, if DNS resolution is working properly, we’re happy. Many organizations, however, fail to utilize DNS logs and associated intelligence within their response and investigative activities. This is in part due to the perceived lack of value associated with DNS logs and its associated features, such as name server, WHOIS, and hosting information, and more often due to the unavailability of the logs. This talk will present several tools (both commercial and open source) to help manage the deluge of information on even the smallest of budgets. We will also discuss how to enrich your data with valuable intelligence from freely available sources. Finally, this talk will highlight some real-world investigative techniques where DNS and its associated features were
    used to add clarity to DFIR investigations.
    Andrew Hay, CISO, DataGravity, Inc.
    Andrew Hay
    DataGravity, Inc. @andrewsmhay
    Andrew Hay is the CISO at DataGravity where he is responsible for the development and delivery of the company’s comprehensive information security strategy. Prior to that, Andrew was the Director of Research at OpenDNS (acquired by Cisco) and was the Director of Applied Security Research and Chief Evangelist at CloudPassage.
    ATTEND THE 2017 THREAT HUNTING SUMMIT: dfir.to/ThreatHunting2017
    SANS THREAT HUNTING AND INCIDENT RESPONSE COURSES
    FOR508: Digital Forensics, Incident Response, & Threat Hunting: sans.org/FOR508
    FOR572: Network Forensics: sans.org/FOR572
    FOR578: Cyber Threat Intelligence: sans.org/FOR578
  • Наука та технологія

КОМЕНТАРІ • 2

  • @Ichinin
    @Ichinin 7 років тому +3

    Audience don't know what recursive DNS - or what DNS itself is?
    Who did you invite to the presentation, plumbers and pastry chefs? Can't think that any Infosec people was invited.

    • @x0rZ15t
      @x0rZ15t Рік тому

      This is what happens when you have the execs attending the technical talk/demo/presentation. Those people can barely configure their mail client and/or send meeting invites let alone know what DNS is/for.