YoVDO

Don't Repeat Yourself - Automating Malware Incident Response for Fun and Profit

Offered By: BSidesLV via YouTube

Tags

Security BSides Courses Cybersecurity Courses Digital Forensics Courses

Course Description

Overview

Explore automation techniques for malware incident response in this 30-minute conference talk from BSidesLV 2016. Gain insights into the roles of malware analysts and digital forensics tools, with a focus on OSX Collector and ISAC Selector. Learn about JSON entry examples, visualization techniques, and output filters. Discover how to leverage S3 event notifications, execute analysis filters, and interpret results. Understand the benefits of automating forensics collections, including time savings and improved interaction between analysts and help desk. Examine a script example and consider the advantages of remote collection methods. Conclude with a discussion on sandboxing and potential pitfalls in malware incident response automation.

Syllabus

Introduction
About me
What is malware incident response
People involved in malware incident response
Job of malware analysts
Digital forensics tools
OSX Collector
ISAC Selector
Example JSON Entry
Example JSON Visualization
OSEx Selector Output Filters
S3 Event Notifications
Osx Collector Output
Extract JSON File
Execute Analysis Filters
Analysis Results
Load Results
Automate forensics collections
Script example
Time savings
Interaction between analysts and help desk
No need for physical collection
Conclusion
What kind of falls
Sandboxing


Taught by

BSidesLV

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network