Forgotten But Not Gone: Gathering NTFS Artifacts of Deletion - SANS Tactical Detection Summit 2018

Subscribers:
64,000
Published on ● Video Link: https://www.youtube.com/watch?v=3MdDNjtdC8k



Category:
Guide
Duration: 31:46
1,009 views
9


SIEM Summit 2019 Agenda: http://www.sans.org/u/UIC

Presenter: Mari DeGrazia (@MariDeGrazia) and Scott Hanson, Kroll

While endpoint threat monitoring tools are powerful, many lack ways to quickly and efficiently recover evidence of deleted information. This deleted information may include evidence of staging tools, exfiltration files and malware that attackers clean up as they go. How can you track an attacker through your environment if they are cleaning up after themselves? Learn how to pull back and leverage two files on the system, the MFT and the NTFS Index Attribute, to discover evidence of deleted files. Once an attacker’s favorite staging location is known, this technique can be scaled up and automated to sweep an environment to locate and analyze evidence of deleted files.




Other Videos By SANS Institute


2019-03-12Top 10 Writing Mistakes in Cybersecurity and How You Can Avoid Them
2019-03-04The Hitchhiker’s Guide to Evidence Sources - SANS Webcast
2019-02-21Purple Teaming Explained
2019-02-20ICS Security Summit 2019: What to Expect
2019-02-16Network Visualizations: Understand what's happening faster and easier than ever! - SANS Webcast
2019-02-11Unconventional Logging and Detection - SANS Tactical Detection Summit 2018
2019-02-11SANS Blue Team Summit & Training 2019
2019-02-10The Changing Landscape of Offense - SANS Pen Test HackFest 2018
2019-02-07Burning Down the Haystack - SANS Security Operations Summit 2018
2019-02-06Measure Yo Bad Self - SANS Security Operations Summit 2108
2019-02-05Forgotten But Not Gone: Gathering NTFS Artifacts of Deletion - SANS Tactical Detection Summit 2018
2019-02-04Applied Data Science and Machine Learning for Cybersecurity - SANS Tactical Detection Summit 2018
2019-02-01Defeating Attackers with Preventative Security – SANS Institute
2019-01-31Build it Once, Build it Right: Architecting for Detection - SANS Tactical Detection Summit 2018
2019-01-31Ship of Fools: Shoring Up Kubernetes Security - SANS Secure DevOps Summit 2018
2019-01-30Lessons Learned from Illumina's SecDevOps Transition - SANS Secure DevOps Summit 2018
2019-01-30Everything New is Old Again - SANS Secure DevOps Summit 2018
2019-01-30The Top Ten Reasons It’s GREAT to Be a Pen Tester - SANS Pen Test HackFest Summit 2018
2019-01-30A Year Of Gaining Superpowers - SANS Pen Test HackFest Summit 2018
2019-01-29Hatfields and McCoys: The Dev/Sec Relationship - SANS Pen Test HackFest Summit 2018
2019-01-29The Clouds Are Out to Get Me! - SANS Pen Test HackFest Summit 2018



Tags:
sans institute
information security
cyber security
cybersecurity
information security training
cybersecurity training
cyber security training