Incident response findings and conclusions are only as strong as the logs and evidence upon which they are based. Mandiant investigations into application-level compromises have revealed that many organizations either do not centralize application logs into a SIEM or, if they do, there is no formalized process for validation, monitoring, or investigation. Many incident handling teams only realize the significant logging deficiencies and security monitoring gaps for their critical applications after an incident has already occurred. Considering your application logging capability from the perspective of an incident response will ensure the logs you need will be available and actionable when the time comes to respond to an incident.
This talk will challenge information security professionals to proactively evaluate their current application logging capabilities and determine how effectively they can detect and respond to application abuse. Threat modeling and attack simulations from an investigator's perspective will help you develop hunting and detection capabilities. Once you have a possible threat to investigate, you can then craft automated investigation workflows that combine multiple data sets, enrich useful indicators, and provide pivot points to identify related threats.
To elevate your threat hunting, detections, and investigations, we will walk through examples of how you can optimize your log data and significantly cut the amount of time and effort required to detect and investigate abuse of your application platform. This talk will use a hypothetical application with activity types and analysis requirements common to applications across many industries. We will walk through a comprehensive but straightforward hunting, detection, and investigation workflow that you can replicate with your team.
David Pany, Manager, Mandiant
Ryan Tomcik, Senior Consultant, Mandiant
DFIRCON 2020 - Live Online
sans.org/event/dfircon-2020-live-online
Virtual, US Eastern | Mon, Nov 2 - Sat, Nov 7, 2020
Courses Available:
FOR308: Digital Forensics Essentials - NEW
FOR498: Battlefield Forensics & Data Acquisition
FOR500: Windows Forensic Analysis
FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics
FOR518: Mac and iOS Forensic Analysis and Incident Response
FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response
FOR578: Cyber Threat Intelligence
FOR585: Smartphone Forensic Analysis In-Depth
FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques