Black Hat Asia
March 24-27, 2015
Marina Bay Sands | Singapore
Black Hat USA
August 1-6, 2015
Mandalay Bay | Las Vegas, NV
Black Hat Europe
November 10-13, 2015
Amsterdam RAI | The Netherlands
4/22/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Digital Forensics (a.k.a. CSI Online)

As more and more crimes occur online, digital forensics becomes ever more important in identifying hostile entities who would do your company harm. Today's trio of Black Hat 2014 Trainings highlight the skills modern investigators need to pick up on breaches, collect evidence, and see things through to a successful conclusion.

A breach can occur in the blink of an eye and leave few obvious traces, so the ability to recognize and respond rapidly to such attacks is a vital capability for all organizations. Unfortunately, this requires specific training outside the bounds of most IT skillsets. Digital Forensics & Incident Response aims to pick up the slack, briefing you on the nitty-gritty of file system implementations, operating system design, and possible attack vectors. The class accompanies theory with crucial hands-on time, teaching you valuable forensics skills that will be immediately applicable in a variety of investigative scenarios.

Digital attacks tend to be fast and mostly silent, but an attacker's virtual footprints remain throughout the network. The authors of Network Forensics: Tracking Hackers Through Cyberspace will present Network Forensics: Black Hat Release, a fast-paced Training which will give you the tools you need to ferret out key evidence. Topics to be covered include carving out suspicious email attachments from packet captures, dissecting DNS-tunneled traffic, and using flow record analysis tools to pick out brute-force attacks and identify compromised systems, among many others.

Faced with the complex security investigations of the 21st century, many investigators can feel helpless. While deductive talents are certainly relevant, it takes a whole new skillset to harvest (and preserve!) evidence from today's virtual crime scenes successfully. Computer Forensics & Incident Response for Investigators aims to teach investigators to conduct data-breach investigations that adhere to a formal methodology, which will greatly increase the probability of the evidence being admissible in a court of law.

Ready to register? Be sure to lock in those sweet early-bird rates. Please visit the Black Hat USA 2014 registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7896
Published: 2015-03-03
Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before ...

CVE-2014-9283
Published: 2015-03-03
The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

CVE-2014-9683
Published: 2015-03-03
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.

CVE-2015-0890
Published: 2015-03-03
The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

CVE-2015-2168
Published: 2015-03-03
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.