Advanced Internet Dataset Combinations for Threat Hunting and Attack Prediction
Offered By: Security BSides San Francisco via YouTube
Course Description
Overview
Explore advanced Internet dataset combinations for threat hunting and attack prediction in this 31-minute conference talk from BSidesSF 2017. Learn to move beyond simple Whois and PDNS lookups, and noisy threat feeds. Discover how to combine SSL cert facet data with tracking IDs, host-pair relationships, and technology stack fingerprints to detect, verify, and stop adversaries' next attacks. Gain insights into analyzing potentially compromised users and determining if IP addresses, domain names, or URLs pose threats. The presentation covers traditional and modern data sets, operationalizing data, and includes examples and a demo, concluding with a comparison of techniques.
Syllabus
Introduction
Traditional data sets
Modern data sets
Operationalizing data
Examples
Demo
Comparison
Taught by
Security BSides San Francisco
Related Courses
Early Detection through DeceptionYouTube Hack for Show, Report for Dough - Brian King
YouTube Blue Teamin on a Budget of Zero - Kyle Bubp
YouTube Windows Event Logs - Zero to Hero
YouTube Weaponizing Splunk - Using Blue Team Tools for Evil
YouTube