Detection and Response Triage and Analysis

No ratings

Presented at Texas Cyber Summit 2023 by

NEEDED: VMWare workstation or VMWare player installed on your own Laptop, basic familiarity of the Windows internals. Detection and Response Triage & Analysis AbstractResponding to threat actor activity requires that detection and response personnelare able to quickly pivot from a detection and acquire actionable evidence to drive decisions. In this workshop, Principal Readiness Engineer Gerard Johansenwill walk attendees through realistic detection and utilize tools to conduct localand remote artifact collection. From here, attendees will be then shown how toquickly analyze artifacts in support of incident response decisions. Some of the key learning points:- The role that incident triage has in responding to detections- Using Kroll Artifact Parser and Extractor for local triage- Velociraptor for remote triage- Extracting key artifacts to determine initial access, execution, lateral movement and command and control- Analyzing artifacts to extract key IOCs- Building workflows and playbooks to quickly pivotfrom a detection to responseAttendees will be presented with realistic scenarios and artifacts to workfrom.