← All talks

Att&ck™ the Attacker

BSides Munich · 201827:44766 viewsPublished 2018-04Watch on YouTube ↗
Speakers
Tags
CategoryTechnical
StyleTalk
About this talk
by Christian Kollee Meanwhile, many defenders have accepted that prevention does not always work. Therefore, it becomes critical to detect intrusions quickly. But what attacks can we already discover using existing data sources? What should we prioritize next? And which capabilities can we enhance? MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) is a knowledge base and model for adversary behavior. It focuses on the various (post-compromise) phases of an adversary. In this talk, I’ll present the ATT&CK™ model and possible ways of using it to evaluate, prioritize and improve defense capabilities.
Show transcript [de]

so haub vorliegen willkommen baby denke für die framework for improving detection capabilities extens vor wie etwas serie tactics techniques and college and is basically collection of tax and technical advisory oder intruder can use in die inventa fischer companies of system so das ist natalie cole vor die fenster von dem drehteam im geiste warme blut blut immer so sda die computer erlangen nürnberg wars at various university sind fraunhofer-institut 2012 consultant topix freunde dauert hier security monitoring incident response sind natürlich froh wenn sie so die question is to care about the only ones to get into the other side die intruders dilemma richies say defender all-in-one indicators teil der incident response to the environment and to detect die präsenz auf die intrusion

detector what indicators can you and i tectoyou steckt mehr gibt es clever hier model ein präsent ist somit controls inc bed models are what they used to das ist quatsch boxerischen anyone go karts

models von lockheed martin in 2002 disney stars mary kritik gebaut worden ist fast vor face arial stable die pending new york the monsters installation maintain sie to control activity von objective derad [Musik] der wie frameworks institut ist die protection suite ist ein model describing wird ein attest to be for the week on facebook setting up infrastructure ist die mobile version which is for mobile devices so immer state disk die enterprise edition ist

konsistent tactics tactics are things you can do i do it for example in resistance to enjoy your tax ist remote access tool ist wenning das system bietet if you're not in travel friends of times toyota's much is actually technik to change the time stamp soft dropped pfalz sowie look like they have been put der tk logo die operating system volks abzubauen den firestone die pianistin ist company adc great to the movement and it's probably not easy to get aufgekauft user hat das klosett originals traders you sit around to

different taktik technik has its own wiki page so die technik description william fox-pitt includes the data sources können used to detect dies technics der ex amtes so exempel swatch group protections technics in past and future generations of the recession possibility vor dass technikfeind information about this here and extended aber detektion auf kosten des wortes trageser baut das wohl juju detektors technics das ist das motto kritik sei hafte mit hier das ist not always that into you need to work to get the corrections action-blockbuster reports dokumentation about music

des protect step to identify what takes you could do tech data security hat die blind spot you have you sing mapping des allzu der tech data stores so what you can

blinky shiny boxes in new network which do something you don't know exactly what they can detect playbook playbook acting zu musik von incidents currently highly coming mourinho die sensation tools das skript zu tools kennen bietet action mechanisms baute vor so folgsam to end games red team automation different ways

florian roth simulation von maschinell incident response mini cats an der domain controller der hausmeister auf just want to check sourcing

step to identify and extended action capabilities based only on data sources solle genau wie die windows event logs hier können user und die mitec check.de technics which can be defekte using

dokumentation paid search in der daily star to navigate technik contents data service check your master boot record for detection sportswear company so jackie o ihr critical assets jackpots what would you need to know what you need to enhance the starting out what data monitoring tool microsoft in windows event logs goldsource you can use

trotz von der beginn der in den move on so die conclusio centerview die in thun ist glamour sowie need to ease 2009 gewerbe hälfte tegtmeier heftig in front

much work too do it security conference [Applaus]

workshops for work shop many to many man im moment der manager von open source in available you can use to start so i thought i die vielen open source tools der ist sie die erste der software die die hunting erkennen wie network security monitoring board security alliance oha die aktuellste so hat die windows event logs stuff on good news to the feeling what do you know how much to produce in bonn baby das auf youtube feeling haunstetter hält ist das ist much more to much better project management

[Musik] megabyte gigabytes für day now we want to the extent to different départements differenz zur company number und megabytes und cpu dazu muss man die konfiguration security hält starting point vor die die konfiguration of course at konfiguration ist ist so volks cluj cafe be you think city events und environments so maybe you want to fight listet so you think you are config can can help but in my opinion and replace the talk about winning the computer users power company auch so viel privat surfing

breaking up die in klitzschen und ab die post zu bringen dann ist das date of this will be no party for you

look what you are information process monitoring exklusiv in der du nord collect dies sei ja dass das ist aus

experience day at least sei okay ich kenne keine feinde kommen kommen aus

action und maschinen machine learning happens when you have to tune it

activity streams temps und action you have to tune tour in mailand die hälfte konfiguriert actions so you don't mean to konfiguriert sowie tassen trinken

[Applaus]