Incident Response (region4) - Analizando campañas en México

No ratings

Presented at BSidesCDMX 2019 by

During an incident investigation, our CIR team managed to detect TTP used by the clop ransomware threat actor. This includes anti-forensics, shell-coding, beaconing and lateral movement. In the talk we will show techniques to identify and analyze each artifact involved during the incident. And how the investigation was driven using threat intelligence to accelerate the analysis. Including the process to extract IOCs and how to exploit them. We will also talk about the capabilities needed by an organization that want to face these kind of threats.