APT Presentation from July 2008

February 6th, 2010 admin

Some of you may remember me mentioning the 2008 SANS WhatWorks in Incident Response and Forensic Solutions Summit organized by Rob Lee. I provided the keynote and really enjoyed listening to the presentations, which Rob has graciously made available at http://files.sans.org/summit/forensics08/ . One of the presentations, by Mandiant consultant Wendi Rafferty and then-Mandiant consultant (now GE-CIRT incident handler) Ken Bradley, was titled Slaying the Red Dragon . As you can see from the …


Originally posted on TAOSecurity

 
  Related Posts
SANS WhatWorks Summit in Forensics and Incident Response
SANS WhatWorks Summit in Forensics and Incident Response
I wanted to remind everyone about the SANS WhatWorks Summit in Forensics and Incident Response in DC, 8-9 July 2010. The Agenda looks great. I will offer the “Expert Briefing: CIRT-level Response to Advanced Persistent Threat” and participate on the “APT Panel Discussion.” This IR event is a great precursor to my next SANS... 
Audio of Bejtlich Presentation on Network Security Monitoring
Audio of Bejtlich Presentation on Network Security Monitoring
One of the presentations I delivered at the Information Security Summit last month discussed Network Security Monitoring. The Security Justice guys recorded audio of the presentation and posted it here as Network Security Monitoring and Incident Response. The audio file is InfoSec2009_RichardBejtlich.mp3. Copyright 2003-2009 Richard Bejtlich and... 
Google and NSA Fulfilling 2008 Predictions
Google and NSA Fulfilling 2008 Predictions
In December 2007 I wrote Predictions for 2008 . They included 2) Expect greater military involvement in defending private sector networks; 3) Expect increased awareness of external threats and less emphasis on insider threats; and 4) Expect greater attention paid to incident response and network forensics, and less on prevention. All three of... 
Offshoring Incident Response
Offshoring Incident Response
A blog reader emailed the following question. We recently had a CISO change, and in the process of doing an initial ops review and looking at organizational structure, one of the questions the new CISO has is about the viability of offshoring incident response… I would be very interested in your views on this matter, and would appreciate... 
Tentative Speaker List for SANS Incident Detection Summit
Tentative Speaker List for SANS Incident Detection Summit
Thanks to everyone who attended the Bejtlich and Bradley Webcast for SANS yesterday. We recorded that Webcast (audio is now available ) to start a discussion concerning professional incident detection. I’m pleased to publish the following tentative speaker list for the SANS WhatWorks in Incident Detection Summit 2009 on 9-10 Dec in Washington,... 
Every Software Vendor Must Read and Heed
Every Software Vendor Must Read and Heed
Matt Olney and I spoke about the role of a Product Security Incident Response Team ( PSIRT ) at my SANS Incident Detection Summit this month. I asked if he would share his thoughts on how software vendors should handle vulnerability discovery in their software products. I am really pleased to report that Matt wrote a thorough, public blog post... 
Brief Thoughts on SANS WhatWorks Summit in Forensics and Incident Response 2010
Brief Thoughts on SANS WhatWorks Summit in Forensics and Incident Response 2010
Last week I spoke at the third SANS WhatWorks Summit in Forensics and Incident Response in DC, organized and led by Rob Lee. As usual, Rob did a wonderful job bringing together interesting speakers and timely topics. I thought my presentation on “CIRT-level Response to Advanced Persistent Threat” went well and I enjoyed participating... 
Comments on Sharkfest Presentation Materials
Comments on Sharkfest Presentation Materials
I saw that presentations from Sharkfest 2010 are now posted. This is the third year that CACE Technologies has organized this conference. I’ve had conflicts each of the last three years, but I think I need to reserve the dates for 2011 when they are available. In this post I wanted to mention a few slides that looked interesting. Jasper... 
Wednesday is Last Day for Discounted SANS Registration
Wednesday is Last Day for Discounted SANS Registration
In my off time I’m still busy organizing the SANS WhatWorks in Incident Detection Summit 2009 , taking place in Washington, DC on 9-10 Dec 09. The agenda page should be updated soon to feature all of the speakers and panel participants. Wednesday is the last day to register at the discounted rate . I wrote the following to provide more information... 
Thanks for a Great Incident Detection Summit
Thanks for a Great Incident Detection Summit
We had a great SANS WhatWorks in Incident Detection Summit 2009 this week! About 100 people attended. I’d like to thank those who joined the event as attendees; those who participated as keynotes (great work Ron Gula and Tony Sager), guest moderators (Rocky DeStefano, Mike Cloppert, and Stephen Windsor), speakers, and panelists; Debbie Grewe... 
  Related Tweets from Twitter

There was an error processing the Feed, if this is your page, please check the information provided in your profile.

  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP