Тёмный
SANS Digital Forensics and Incident Response
SANS Digital Forensics and Incident Response
SANS Digital Forensics and Incident Response
Подписаться
Over 80% of all breach victims learn of a compromise from third-party notifications, not from internal security teams. In most cases, adversaries have been rummaging through your network undetected for months or even years.

Incident response tactics and procedures have evolved rapidly over the past several years. Data breaches and intrusions are growing more complex. Adversaries are no longer compromising one or two systems in your enterprise; they are compromising hundreds. Your team can no longer afford antiquated incident response techniques that fail to properly identify compromised systems, provide ineffective containment of the breach, and ultimately fail to rapidly remediate the incident.

A thorough understanding of many detailed areas is required for success, including a mastery of the following fundamental skills covered by the SANS Digital Forensics and Incident Response (DFIR) RU-vid Channel.
Getting down and dirty with Mac imaging
31:12
16 часов назад
The SaaS-y Side of Incident Response
28:13
16 часов назад
Ghost in Your Supply Chain
44:32
16 часов назад
Atomic Ransomware Emulation
33:53
3 месяца назад
Ransomware Running Wild in the Cloud
33:30
3 месяца назад
Комментарии
@somiltyagi7127
@somiltyagi7127 2 дня назад
2024, still its good topic to refresh the knowledge. Good Job 🙂
@gallaouedermaez8336
@gallaouedermaez8336 2 дня назад
Nothing new
@gristlevonraben
@gristlevonraben 2 дня назад
great video
@dlcrdz00
@dlcrdz00 3 дня назад
IBM in the House!!!
@danielrodriguezrodriguez415
@danielrodriguezrodriguez415 6 дней назад
Great talk, thanks for sharing
@joebrown-w6q
@joebrown-w6q 7 дней назад
Is there a way you can see when logs were deleted? I noticed about a week or two ago. When I went to event viewer in security logs I saw my laptop turn on when I was not even using it! Tonight, I went on to check logs and it didn't even go past the previous day. I turned it off and back on, now I can see past today. Whats going on, can anyone help?
@techcafe0
@techcafe0 8 дней назад
oh ffs it's practically impossible to hear what the speaker is saying. please fix the audio and re-upload.
@BackMarcus-n5k
@BackMarcus-n5k 10 дней назад
Thomas Deborah Davis David Garcia John
@razmus9708
@razmus9708 13 дней назад
Chad singlehandedly just made me want to sign up and take any of his classes. What a great speaker.
@somebodyThen
@somebodyThen 16 дней назад
came from my FOR508 which references this talk. excellent lesson.
@deanhaycox
@deanhaycox 18 дней назад
I looked at the ver success academy its only open to US citizens Will you be opening to UK?
@NoddinSummi-d3n
@NoddinSummi-d3n 20 дней назад
Wilson Susan Robinson Kenneth Taylor Timothy
@JoeyojHolmsop
@JoeyojHolmsop 20 дней назад
Harris Betty Thomas Larry Thomas Joseph
@JoeyojHolmsop
@JoeyojHolmsop 20 дней назад
Thompson Joseph Gonzalez Ronald Taylor Matthew
@LambDavid-o4y
@LambDavid-o4y 22 дня назад
3802 Waters Path
@MayPhil-u5x
@MayPhil-u5x 23 дня назад
15330 Denesik Corner
@NelmuArina
@NelmuArina 24 дня назад
566 Bahringer Loaf
@PoundJoanna
@PoundJoanna 25 дней назад
0940 Peggie Ports
@HuttFrances
@HuttFrances 25 дней назад
68236 Fredy Drives
@CityThatCannotBeCaptured
@CityThatCannotBeCaptured 25 дней назад
Brilliantly useful. Thank you.
@JossOrtan
@JossOrtan 26 дней назад
Interesting perspective on threat intelligence! Could you elaborate on why you believe it might be a fallacy? What alternative approaches do you suggest?
@PearsonGodfery
@PearsonGodfery 27 дней назад
8117 Doyle Stravenue
@B_knows_A_R_D-xh5lo
@B_knows_A_R_D-xh5lo 27 дней назад
awesome
@YuleEmily
@YuleEmily 28 дней назад
0350 Schneider Row
@ernhar
@ernhar Месяц назад
Great brief Katie, very relevant threats for us to consider
@dominiclaplante4563
@dominiclaplante4563 Месяц назад
Nice MITRE ATT&CK poster 👌
@Nathiest2
@Nathiest2 Месяц назад
moloch is a satanic deity that requires child sacrifice to summon him. Wtf Verizon?!
@VJovenSuenosenConstruccion
@VJovenSuenosenConstruccion Месяц назад
Where's the course?
@JossOrtan
@JossOrtan Месяц назад
This was such an insightful video on starting with CTI! What’s the biggest challenge you faced when first diving into threat intelligence?
@ram_bam
@ram_bam Месяц назад
This course was not included in the SANS 2024 Career Guide. I hope it's not being discontinued because I'm looking forward to taking it in Q2 2025.
@TomDavidMcCauley
@TomDavidMcCauley Месяц назад
Still trying to figure out how the streetlight effect joke was politically incorrect at all. Seems like people just say that without thinking about it. Like I once had a girlfriend claim it was “so P.C.” that a coffee shop put “Caution: Hot” on their coffee cups 😂 wtf Great talk otherwise though 10/10
@swede7581
@swede7581 Месяц назад
14,4KB IS 16KB OK I GOT IT FINALY...Im just in the middle of moving 3 games that is 62gb but also the size on disc size 93gb so a huge difference on the size(oooh yes a big difference ( But i now understand this finaly after about 2 years w thoughts about this SIZE thing n why there is 2 kinds of NR..... But 60 vs 90gb is alot of difference in size(so alot of unused space "Kind of"!) Thanks 4 this great video-finaly explained this for me so i understand why the difference can be so huge!!
@ma34529
@ma34529 Месяц назад
GIME all day
@PtolemyPetrie
@PtolemyPetrie 2 месяца назад
It's actually very simple. Pull the drive of the affected machine, and plug into known good machine as a non booting drive, point your scanners at the affected drive, probably labeled e: or f: remove the ransomware once detected by your scanner. Alternatively you can boot a malware removal disc like Dr web, and point it at scanning the drive.
@TheRaghav12345678910
@TheRaghav12345678910 Месяц назад
??? You do know that ransomware encrypts the files right? Do you want to remove all the encrypted files? That defeats the whole purpose
@PtolemyPetrie
@PtolemyPetrie Месяц назад
doesn't matter, you're not booting the drive. there are tools you can run to remove the infection, i have removed ransomware and free av and many scareware this way. The encrypted files are not removed.
@Oneform-v3p
@Oneform-v3p 2 месяца назад
Sans is a funni skeleton not this
@MermaidDreamsAstrology
@MermaidDreamsAstrology 2 месяца назад
Thank you for sharing your passion. I'm in my late 40s and I'm just starting the climb to DF. Feels overwhelming but you and others, who genuinely are passionate about this field keep me in the fight.
@hanknorris5642
@hanknorris5642 2 месяца назад
Very good course, highly recommended.
@DineshPandiyan-jf2jj
@DineshPandiyan-jf2jj 2 месяца назад
It was very useful! Learned a lot about threat hunting
@StarOfDavidKush
@StarOfDavidKush 2 месяца назад
Awesome channel. Thanks!
@bradpryer
@bradpryer 2 месяца назад
Thanks! So well explained.
@user-yq7oo1uj3f
@user-yq7oo1uj3f 2 месяца назад
Love Joe, met him earlier this year - a good guy!
@matthewaufdemberg9823
@matthewaufdemberg9823 2 месяца назад
This was an amazing and thorough presentation 👏 thank you very much for presenting this!
@chrisbrenton3834
@chrisbrenton3834 2 месяца назад
Wow the presented data is quite a few years out of date. All major CDNs block host and SNI mismatches. So while you can still theoretically put a C2 server behind a CDN, you can no longer use domain fronting to obfuscate it. Also, RITA has supported bimodal analysis for a number of years now. Its specifically designed to detect the use case described (beacon timing at idle is different than timing when active).
@ByteBudsBites
@ByteBudsBites 2 месяца назад
👍 thank you
@ByteBudsBites
@ByteBudsBites 2 месяца назад
❤thank you
@gitgudsec
@gitgudsec 3 месяца назад
thanks mehmet, great info that's hard to find!
@laptoplifestylegeez
@laptoplifestylegeez 3 месяца назад
where can i find this write block file
@DIGGERfromAR
@DIGGERfromAR 3 месяца назад
While there are some good nuggets. She generally starts a point then allows to hang unfinished. She says to ignore trends yet relies on causality. The nuance of these ideas is lost. Great topic, poor presentation.
@akpologun6654
@akpologun6654 3 месяца назад
Awesome
@akpologun6654
@akpologun6654 3 месяца назад
Awesome