The Credentials in the High Castle

No ratings

Presented at grrcon 2017 by

Account takeover (ATO) incidents can be obfuscated from an analyst in a magnitude of ways. Analysts will learn a number of ways to detect and respond to these ATO events. The analysts will be taken through reactive and proactive ATO activity, as well as developing and validating patterns to detect this traffic. Blocking methods are also important considerations we will cover. We will go through three simulated ATO attack scenarios to express this process. It is important to have knowledge of what legitimate traffic should look like, for an analyst to respond appropriately. This will not cover the setup of appropriate logs or focus on a particular tool.