Threat Hunting Through the Kill Chain

No ratings

Presented at BSidesRaleigh 2016 by

Hunting is proactive searching for threats that may go unidentified by intrusion detection, log alerting, or antivirus software. Hunting allows organizations to find unknown threats while gaining a deeper understanding of their networks. This presentation will show how to hunt through network data at each stage of the kill chain. Three kinds of hunts will be presented: stacking, tracking, visualization. Working implementations used by Cisco Active Threat Analytics team will be presented for finding attacks pre-exploitation, exploitation attempts, and post-exploitation.