Temet Nosce: Know Thy Endpoint Through and Through
Thomas V. Fischer
Temet Nosce: Know Thy Endpoint Through and Through Thomas V. - - PowerPoint PPT Presentation
Temet Nosce: Know Thy Endpoint Through and Through Thomas V. Fischer I am Threat Researcher 25+ years experience in InfoSec Spent number years in IR team positions Director @BSidesLondon Contact
Thomas V. Fischer
§ Threat Researcher § 25+ years experience in InfoSec § Spent number years in IR team positions § Director @BSidesLondon § Contact
Public 3
Public 4
Public 5
Public 6
Public 7
Public 8
Public 9
Public 10
Public 11
Public 12
L i k e l y b e n i g n A l m
t c e r t a i n l y m a l i c i
s D e f i n i t e l y m a l i c i
s R i s k
d a t a e x f i l t r a t i
Public 13
Public 14 Outlook creates temp file File write new location Other process file open Load of macro subsystem
Tag file
Open of tagged file Write file Network connection Execute command shell Execute binary Move file to user directory
Attachment Opened Active Attachment Suspicious activity Risk - unknown Risk - elevated
Public 15
Public 16