ARTHIR - ATT&CK Remote Threat Hunting Incident Response Windows Tool
Offered By: BasisTech via YouTube
Course Description
Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the capabilities of ARTHIR, a modular framework for remote threat hunting and incident response, in this conference talk from OSDFCon 2021. Learn how to leverage PowerShell and Windows Remote Management to perform compromise assessments, configuration, containment, and other security activities across multiple target systems. Discover how ARTHIR improves upon the Kansa tool, offering enhanced functionality for remotely executing binaries and retrieving output. Understand the framework's integration with the MITRE ATT&CK Matrix, allowing users to map modules to specific tactics and techniques. Gain insights into the open-source nature of ARTHIR, including its GitHub repository, SLACK community, and opportunities for contribution. Explore the included modules, such as original Kansa and LOG-MD free edition components, and learn how to create custom modules. Presented by Michael Gough, a malware archaeologist and incident responder, this talk provides valuable information for blue team defenders and security professionals seeking to enhance their remote threat hunting capabilities.
Syllabus
ARTHIR: ATT&CK Remote Threat Hunting Incident Response Windows Tool by Michael Gough [OSDFCon 2021]
Taught by
BasisTech
Related Courses
A Golden Ticket to the CloudBasisTech via YouTube Autopsy's Year in Review - OSDFCon
BasisTech via YouTube Autopsy Scoring - Finding the Relevant Data with Analysis Results
BasisTech via YouTube Autopsy Update
BasisTech via YouTube Binee - Complete Emulation of Advanced Malware
BasisTech via YouTube