YoVDO

Lifting the Fog of War

Offered By: 44CON Information Security Conference via YouTube

Tags

44CON Courses Cybersecurity Courses Threat Detection Courses Windows Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of Microsoft's Remote Procedure Calls (MS-RPC) protocol and its impact on Windows security in this 46-minute conference talk from 44CON 2023. Delve into the protocol's integral role in Windows operations and its connection to various lateral movement techniques and exploits. Discover built-in defensive mechanisms, including the RPC ETW provider and Windows firewall RPC filters, that can be leveraged to mitigate RPC-based threats. Learn about a new tool designed to simplify interaction with the RPC ETW provider, enrich event data, and enhance visualization. Examine the challenges of monitoring RPC traffic and strategies to overcome inherent shortcomings in the ETW provider. Gain insights into utilizing Windows features for tracking and defending against RPC-based attacks, and explore the effectiveness of these methods in analyzing RPC data and detecting malicious traffic. Acquire knowledge about signatures developed to detect common lateral movement techniques and one-day exploits. Presented by Stiv Kupchik, a senior security researcher at Akamai with expertise in OS internals, vulnerability research, and malware analysis.

Syllabus

Stiv Kupchik - Lifting the Fog of War


Taught by

44CON Information Security Conference

Related Courses

Supply Chain Unchained - How To Be A Bad SaaS
44CON Information Security Conference via YouTube
Aviation Security 101
44CON Information Security Conference via YouTube
The Anti-Checklist Manifesto
44CON Information Security Conference via YouTube
Why Are We Still Doing Authentication Wrong?
44CON Information Security Conference via YouTube
What Do Hackers See When They Look at the Clouds
44CON Information Security Conference via YouTube