Mind Hunter - Adversary Inception

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

After a successful breach, information security practitioners may be inclined to say “What difference does it make who did it? Let’s remediate and move on.” This perspective is a mistake. General attribution is a worthwhile exercise for defenders because motivation informs methodology. Businesses that pursue adversary profiling will excel at estimating future risk.Today’s most effective adversaries are meticulous about operational security when committing unauthorized access. Therefore, understanding the adversary requires direct engagement. This presentation shares insights gained from conversations with various threat actors over the past two years. The presentation covers OPSEC considerations when engaging with adversaries, the nuisances of motivation, the origination of decisions to engage in criminal behavior, and the takeaways for estimating risk.This presentation is about people, their mindsets, their motivations, and their rationalizations/justifications for committing cyber-crime.Excel beyond the normal conventions of adversary profiling, and enter the criminal mind. Hear firsthand from actors, to understand the nuisances of motivation, the origination of decisions to engage in cyber-criminal behavior, and the takeaways for estimating business risk.Learning Objectives:Identify when to approach threat actors, how to initiate successful actor conversations, and effective strategies for obtaining deeper intelligence about adversary tools and tactics.Consider whether human intelligence (HUMINT) is right for your INFOSEC program, and OPSEC considerations when building a practice.Understand how actors think about their work. Understand how to translate HUMINT into summary business risk.