Black Hat USA
August 2-7, 2014
Mandalay Bay, Las Vegas, NV
Black Hat Europe
October 14-17, 2014
Amsterdam Rai, The Netherlands
4/22/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
Connect Directly
RSS
E-Mail
50%
50%

Black Hat USA 2014: Digital Forensics (a.k.a. CSI Online)

As more and more crimes occur online, digital forensics becomes ever more important in identifying hostile entities who would do your company harm. Today's trio of Black Hat 2014 Trainings highlight the skills modern investigators need to pick up on breaches, collect evidence, and see things through to a successful conclusion.

A breach can occur in the blink of an eye and leave few obvious traces, so the ability to recognize and respond rapidly to such attacks is a vital capability for all organizations. Unfortunately, this requires specific training outside the bounds of most IT skillsets. Digital Forensics & Incident Response aims to pick up the slack, briefing you on the nitty-gritty of file system implementations, operating system design, and possible attack vectors. The class accompanies theory with crucial hands-on time, teaching you valuable forensics skills that will be immediately applicable in a variety of investigative scenarios.

Digital attacks tend to be fast and mostly silent, but an attacker's virtual footprints remain throughout the network. The authors of Network Forensics: Tracking Hackers Through Cyberspace will present Network Forensics: Black Hat Release, a fast-paced Training which will give you the tools you need to ferret out key evidence. Topics to be covered include carving out suspicious email attachments from packet captures, dissecting DNS-tunneled traffic, and using flow record analysis tools to pick out brute-force attacks and identify compromised systems, among many others.

Faced with the complex security investigations of the 21st century, many investigators can feel helpless. While deductive talents are certainly relevant, it takes a whole new skillset to harvest (and preserve!) evidence from today's virtual crime scenes successfully. Computer Forensics & Incident Response for Investigators aims to teach investigators to conduct data-breach investigations that adhere to a formal methodology, which will greatly increase the probability of the evidence being admissible in a court of law.

Ready to register? Be sure to lock in those sweet early-bird rates. Please visit the Black Hat USA 2014 registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0993
Published: 2014-09-15
Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.

CVE-2014-2375
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

CVE-2014-2376
Published: 2014-09-15
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2377
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

CVE-2014-3077
Published: 2014-09-15
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
CISO Insider: An Interview with James Christiansen, Vice President, Information Risk Management, Office of the CISO, Accuvant