DFSP # 284 - Fast Triage case study: non-Windows core processes

DFSP # 284 - Fast Triage case study: non-Windows core processes

This week we're going to take a look at how standard triage methodology can detect advanced attack techniques. Even as a newer examiners, if you learn the standard triage methods that I have covered in the fast triage series, you will find the skills provide ample opportunity to detect all sorts attack activity-even very advanced attack activity. This is because there are natural chokepoints in the attack chain that can be used to your advantage. This week we are going to see the non-Windows core process triage in action through the lens of a very advanced attack dubbed "operation ghost."

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(498)

Populärt inom Vetenskap

p3-dystopia
dumma-manniskor
allt-du-velat-veta
rss-mottagningen
rss-ronden
kapitalet-en-podd-om-ekonomi
medicinvetarna
rss-ufobortom-rimligt-tvivel
det-morka-psyket
rss-vetenskapsradion
bildningspodden
halsorevolutionen
ufo-sverige
sexet
paranormalt-med-caroline-giertz
rss-geopodden-2
rss-arkeologi-historia-podden-som-graver-i-vart-kulturlandskap
rss-koll-pa-socialt-arbete
dumforklarat
rss-vetenskapsradion-2