Black Hat USA
August 2-7, 2014
Mandalay Bay, Las Vegas, NV
Black Hat Europe
October 14-17, 2014
Amsterdam Rai, The Netherlands
7/8/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
Connect Directly
RSS
E-Mail
50%
50%

Black Hat USA 2014: Get Your CSI On

Something happened here, and it wasn't anything good. The damage is as yet unclear, and the perps seemingly vanished. That's where digital forensics step in, helping reconstruct what happened to uncover the answers to the most pressing security questions. And -- did you deduce? -- today's trio of Black Hat USA 2014 Briefing highlights all revolve around being a better digital detective.

Advanced persistent threat (APT) attacks are highly organized and are launched for prolonged periods, but it's possible to turn this persistence against their perpetrators. APT malwares typically contain numerous DNS references to keep their command and control (c2) networks redundant, and in APT Attribution and DNS Profiling, researcher Frankie Li will explain broad patterns he's discovered in these DNS-IP pairs. He'll demonstrate a tool he's created to automate the discovery of information on these pairs and compile it into a database for later visualization and analysis.

What if computers had a simple "find malicious stuff" command? That's (kinda) the concept behind Google's GRR, an open-source live-forensics system. Think something's amiss on your box? A single GRR command can, for example, grab a netstat, a process listing, recent browsing history, and common persistence mechanisms (which it can then send to a malware analysis solution). GRR: Find All the Badness, Collect All the Things will introduce you to GRR's use cases and its powerful new capability to detect "forensic artifacts" and perform large-scale hunts across large groups of computers.

Finally, attackers are increasingly using PowerShell to conduct command-and-control in compromised Windows environments. This creates a whole new playground of attack techniques for intruders who've already popped a few admin accounts. Investigating PowerShell Attacks will focus on common attack patterns performed through PowerShell -- lateral movement, remote command execution, reconnaissance, file transfer, and establishing persistence -- and the sources of evidence they leave behind, which you can collect and interpret both on individual hosts and at scale across the enterprise.

Regular registration ends on July 26. Please visit Black Hat USA 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3345
Published: 2014-08-28
The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503.

CVE-2014-3347
Published: 2014-08-28
Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid s...

CVE-2014-4199
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

CVE-2014-4200
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.

CVE-2014-0761
Published: 2014-08-27
The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infinite loop or process crash) via a crafted TCP packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.