BH Mobile Security Summit
June 16-18, 2015
ExCeL London | London, UK
Black Hat USA
August 1-6, 2015
Mandalay Bay | Las Vegas, NV
Black Hat Europe
November 10-13, 2015
Amsterdam RAI | The Netherlands
4/22/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Digital Forensics (a.k.a. CSI Online)

As more and more crimes occur online, digital forensics becomes ever more important in identifying hostile entities who would do your company harm. Today's trio of Black Hat 2014 Trainings highlight the skills modern investigators need to pick up on breaches, collect evidence, and see things through to a successful conclusion.

A breach can occur in the blink of an eye and leave few obvious traces, so the ability to recognize and respond rapidly to such attacks is a vital capability for all organizations. Unfortunately, this requires specific training outside the bounds of most IT skillsets. Digital Forensics & Incident Response aims to pick up the slack, briefing you on the nitty-gritty of file system implementations, operating system design, and possible attack vectors. The class accompanies theory with crucial hands-on time, teaching you valuable forensics skills that will be immediately applicable in a variety of investigative scenarios.

Digital attacks tend to be fast and mostly silent, but an attacker's virtual footprints remain throughout the network. The authors of Network Forensics: Tracking Hackers Through Cyberspace will present Network Forensics: Black Hat Release, a fast-paced Training which will give you the tools you need to ferret out key evidence. Topics to be covered include carving out suspicious email attachments from packet captures, dissecting DNS-tunneled traffic, and using flow record analysis tools to pick out brute-force attacks and identify compromised systems, among many others.

Faced with the complex security investigations of the 21st century, many investigators can feel helpless. While deductive talents are certainly relevant, it takes a whole new skillset to harvest (and preserve!) evidence from today's virtual crime scenes successfully. Computer Forensics & Incident Response for Investigators aims to teach investigators to conduct data-breach investigations that adhere to a formal methodology, which will greatly increase the probability of the evidence being admissible in a court of law.

Ready to register? Be sure to lock in those sweet early-bird rates. Please visit the Black Hat USA 2014 registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: nice one
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1235
Published: 2015-04-19
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME element.

CVE-2015-1236
Published: 2015-04-19
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a cr...

CVE-2015-1237
Published: 2015-04-19
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages ...

CVE-2015-1238
Published: 2015-04-19
Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.

CVE-2015-1240
Published: 2015-04-19
gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.