ShimCache and AmCache enterprise-wide hunting - SANS Threat Hunting Summit 2017

Описание к видео ShimCache and AmCache enterprise-wide hunting - SANS Threat Hunting Summit 2017

The presentation will focus around the open source release of a tool designed to efficiently process and analyse ShimCache and AmCache data at scale for enterprise-wide hunting purposes. The tool is designed as a framework with which to explore new analytics but will be released with some of our own custom-built analytics in it like: time execution correlation, Levenshtein distance analysis and time stacking to name a few.

Matias Bevilacqua, Senior Incident Response Consultant, Mandiant

Комментарии

Информация по комментариям в разработке