This video looks at fileless malware, an attack vector that makes up over half of today’s malicious software attacks. After a walkthrough of an attack, we’ll step through three phases of defense implementation an organization can implement over time, depending on budget and other resources.
I divide the needed safeguards into three implementation phases, beginning with the FIPS 200 minimum controls, moving to better network and endpoint defenses, and ending with a discussion of how zero-trust helps prevent today's advanced threats.
You can download the script for this video, formatted as a study guide, from a link in the video description. The script includes a selected bibliography.
~ Tom Olzak
Table of Contents:
00:00 - Introduction
00:43 - Fileless Malware
03:40 - Phase I controls
10:07 - Phase II Controls
16:03 - Phase III Controls
==========
Video Script
https://adventuresinsecurity.com/CISS...
==========
FIPS 200
https://csrc.nist.gov/publications/de...
==========
Threat Hunting: What It Is and Why It's Necessary
https://www.spiceworks.com/it-securit...
==========