Profiling the attacker - using offender profiling in SOC environments

No ratings

Presented at BSidesLondon 2018 by

It’s been said ‘‘Intrusion analysis is as much about tcpdump as astronomy is about telescopes". Understanding who is attacking your or a customer's network and why is just as important as analysing the packets on it.This slot will focus on a technical offender profiling framework that can be used to build a knowledge base on malicious actors. This talk will delve into the following areas:Building an information classification for your assetsAttack significance plottingAttack factor comparison analysisDiscerning motiveAttacker kill chain analysisMalicious actor profile checklist