Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Beyond ‘Check The Box’ - Powering Intrusion Investigations

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore a comprehensive conference talk that delves into advanced techniques for conducting intrusion investigations. Learn how to move beyond basic "check the box" approaches and leverage powerful capabilities to uncover critical insights. Discover various use cases, understand the context of investigations, and explore high-level questions that drive effective inquiries. Examine essential data points, including DHCP logging, Kerberos service tickets, and authentication events. Gain insights into the intrusion life cycle, possible explanations for suspicious activities, and the differences between Windows 2003 and 2008 logging. Master the art of tracking DNS resolutions, identifying indicators of compromise, and recognizing network-based signs of intrusion. Enhance your cybersecurity skills with practical examples, commercial simulation insights, and expert guidance on logging best practices.

Syllabus

Introduction
Capabilities
Use Cases
Who I am
Context on investigations
Selfidentified
Questions
Example
High Level Questions
Data Points
DHCP Logging
Systems
Bottom Line
Life Cycle
Possible explanations
Kerberos service tickets
Commercial Sim example
Windows 2003 vs Windows 2008
Logging Authentication Events
Events to Log
Net Float
Tracking DNS Resolutions
The Simple Case
Logging DNS
Identifying indicators of compromise
Network indicators of compromise
Summary
QA

Taught by

Black Hat

Reviews

Start your review of Beyond ‘Check The Box’ - Powering Intrusion Investigations

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.