BSides Iowa 2017 - Track 1
Title: "Exploit Kits and Indicators of Compromise"
Speaker: Brad Duncan
Exploit kits are a well known method used by criminals to distribute malware. Many security professionals know about exploit kits, but the full sequence of events is often misunderstood. In this presentation, Brad explains the concept behind a successful malware infection by criminals using exploit kits. This talk traces the sequence of events, starting with a compromised website and ending with the exploit kit delivering its malware payload.
Different steps of an exploit kit’s kill chain are sometimes identified through an organization’s intrusion detection system (IDS). These IDS alerts provide indicators of compromise (IOC). However, in many cases the kill chain is incomplete, and no infection has occurred. Brad discusses examples of exploit kits detected in a security operations center (SOC) environment, how analysts investigate this activity, and the overall impact to an organization.