SOC them in the face: Building and Attacking SOCs

No ratings

Presented at BSidesPittsburgh 2018 by

The goal of any attacker or red teamer is generally to avoid the employees of the Security Operations Center (SOC), as they are primarily responsible for detecting and remediating threats to thenetwork. However, what happens when the attackers start targeting the employees of the SOC itself? In this presentation, we combine our experiences in building and attacking SOCs to demonstrate howattackers can target the employees and structure of the SOC to evade detection. We finish the presentation by providing some best practices on building, training, and utilizing a SOC to ensure it remains effective against today’s advanced attacks.