How to Identify and Prevent Evasive Threats Using your Organisation’s Data

No ratings

Presented at InfoSecurityEurope 2019 by

Stealth operations that were once only possible for the most sophisticated state-actors, are now much more common. These new and sophisticated techniques bring new security challenges. Focusing on a real-world case study, we will disclose advanced evasive operations detected by our IR team and the ways organisations can use their VPN, DNS and proxy data to enrich their internal data sources like Directory Services and Mail-servers to unmask those attacks. We’ll also show how advanced perimeter correlations can help uncover other common threats, such as account hijacking, lateral movement, persistency and data exfiltration.Learning Outcomes:Learn the new risk landscape utilising VPN access, DNS and ProxyDetermine which data feeds and enrichments are best for your organisation.Know which internal data sources can provide strong correlation to which perimeter.Determine which fields and values are a must to build strong security visibility. Learn about additional controls that complement the perimeter sources.