Reverse Analyzing Attacks for Detection, Justin Henderson Paul's Security Weekly #519 episode artwork

EPISODE · Jun 25, 2017 · 36 MIN

Reverse Analyzing Attacks for Detection, Justin Henderson Paul's Security Weekly #519

from Paul's Security Weekly (Video)

Learn how to use Windows Event Logs to catch attackers in your network, including domain admin group enumeration and mimikatz attacks! Justin Henderson (@SecurityMapper) categorizes these techniques as "reverse attack analysis for detection" and shows us how to do it in this technical segment! References to Mark Baggett's work on freq.py are made as well (https://isc.sans.edu/forums/diary/Detecting+Random+Finding+Algorithmically+chosen+DNS+names+DGA/19893/) Full Show Notes: https://wiki.securityweekly.com/Episode519 Security Weekly Web Site: http://securityweekly.com Follow us on Twitter: @securityweekly

NOW PLAYING

Reverse Analyzing Attacks for Detection, Justin Henderson Paul's Security Weekly #519

0:00 36:24

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Paul's Security Weekly (Video)?

This episode is 36 minutes long.

When was this Paul's Security Weekly (Video) episode published?

This episode was published on June 25, 2017.

What is this episode about?

Learn how to use Windows Event Logs to catch attackers in your network, including domain admin group enumeration and mimikatz attacks! Justin Henderson (@SecurityMapper) categorizes these techniques as "reverse attack analysis for detection" and...

Can I download this Paul's Security Weekly (Video) episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!