Operation SemiChimera
Offered By: Hack In The Box Security Conference via YouTube
Course Description
Overview
Syllabus
Intro
C.K Chen @bletchley13
CyCraft in MITRE ATT&CK Evaluation
Outline
Cyberattack to semiconductor vendors
Group Chimera
Investigation Overview
Today's Case Study
Case A: Overview
Used Hosting Server for C2
Root Cause Analysis - PC-SHENNA
Remote Execution Tools
Root Cause Analysis - Server-LAUREN
NTDS.DIT Explanation
Root Cause Analysis - NB-CLAIR
Recon
Data Exfiltration
Powershell
Cyber Situation Graph
Archive Password
Leaked File Name
Actors' Digital Arsenal
Cobalt Strike Beacon
Cobalt Strike Components
Suspicious R-W-X Memory
Hybrid Payload: PE as Shellcode
Transfer Shellcode via Named Pipe
Mutated rar.exe
Forwarded Imports
Dumpert: Implementation
Impact of Skeletonkey Injector
Take Away - 2
Taught by
Hack In The Box Security Conference
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network