BH Mobile Security Summit
June 16-18, 2015
ExCeL London | London, UK
Black Hat USA
August 1-6, 2015
Mandalay Bay | Las Vegas, NV
Black Hat Europe
November 10-13, 2015
Amsterdam RAI | The Netherlands
4/22/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Digital Forensics (a.k.a. CSI Online)

As more and more crimes occur online, digital forensics becomes ever more important in identifying hostile entities who would do your company harm. Today's trio of Black Hat 2014 Trainings highlight the skills modern investigators need to pick up on breaches, collect evidence, and see things through to a successful conclusion.

A breach can occur in the blink of an eye and leave few obvious traces, so the ability to recognize and respond rapidly to such attacks is a vital capability for all organizations. Unfortunately, this requires specific training outside the bounds of most IT skillsets. Digital Forensics & Incident Response aims to pick up the slack, briefing you on the nitty-gritty of file system implementations, operating system design, and possible attack vectors. The class accompanies theory with crucial hands-on time, teaching you valuable forensics skills that will be immediately applicable in a variety of investigative scenarios.

Digital attacks tend to be fast and mostly silent, but an attacker's virtual footprints remain throughout the network. The authors of Network Forensics: Tracking Hackers Through Cyberspace will present Network Forensics: Black Hat Release, a fast-paced Training which will give you the tools you need to ferret out key evidence. Topics to be covered include carving out suspicious email attachments from packet captures, dissecting DNS-tunneled traffic, and using flow record analysis tools to pick out brute-force attacks and identify compromised systems, among many others.

Faced with the complex security investigations of the 21st century, many investigators can feel helpless. While deductive talents are certainly relevant, it takes a whole new skillset to harvest (and preserve!) evidence from today's virtual crime scenes successfully. Computer Forensics & Incident Response for Investigators aims to teach investigators to conduct data-breach investigations that adhere to a formal methodology, which will greatly increase the probability of the evidence being admissible in a court of law.

Ready to register? Be sure to lock in those sweet early-bird rates. Please visit the Black Hat USA 2014 registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3653
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

CVE-2014-5406
Published: 2015-07-06
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, ...

CVE-2014-9737
Published: 2015-07-06
Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.

CVE-2014-9738
Published: 2015-07-06
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.

CVE-2014-9739
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report