Finding badness - Using Moloch for DFIR

No ratings

Presented at PacificHackers 2019 by

In this presentation, we will share how the Verizon Media Paranoids use Moloch (molo.ch), our open source full packet capture system, to perform DFIR. Moloch augments your current security infrastructure by storing and indexing network traffic in standard PCAP format, while also providing fast indexed access.We will explore several scenarios:How we use Moloch internally in our day-to-day investigationsHow Moloch allowed us to view the modification to go-pear.phar and build a timeline around its exploitationUsing Moloch for proactive hunting of badnessHow to use Moloch for sustained collection for long-term investigationsCorrelation with other data sources (ie: Suricata, WISE, etc.)Outline:Bad go-pear.phar file discovery and demoWhat is MolochMoloch historyMoloch deploymentsProactive Moloch huntingMoloch enrichment from other data sourcesMoloch opensource communityFuture work