Distributed Sensor Data Contextualization at Scale for Threat Intelligence Analysis
Jason Trost January 12, 2016
Distributed Sensor Data Contextualization at Scale for Threat - - PowerPoint PPT Presentation
Distributed Sensor Data Contextualization at Scale for Threat Intelligence Analysis Jason Trost January 12, 2016 whoami Jason Trost VP of Threat Research @ ThreatStream Previously at Sandia, DoD, Booz Allen, Endgame Inc. Background
Jason Trost January 12, 2016
Mnemosyne Webapp REST API honeymap
MHN Server
wordpot shockpot p0f snort conpot dionaea
Sensors
hpfeeds
suricata Kippo Amun Glastopf
hpfeeds-logger
Integrations Users 3rd party apps
elastichoney
Malware Sandboxes
MHN Servers Honeypots/Sensors MHN Project Stats and Indicators on Attackers Events
Infected Windows Workstation?
Compromised Webserver?
Ephemeral Exploitation/Scanning server?
Event, DNS Sinkhole hit, Indicator Match in SIEM, etc.
image”
Repositories