vpsamz
MyBoerse.bz Pro Member
SANS - SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses
Erik Van Buggenhout, Stephen Sims | Duration: 24h+ | Video: H264 1280x720 | Audio: AAC 32 kHz mono | 2,70 GB | Language: English
Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses will arm you with the knowledge and expertise you need to overcome today's threats. Recognizing that a prevent-only strategy is not sufficient, we will introduce security controls aimed at stopping, detecting, and responding to your adversaries through a purple team strategy.
The topics to be addressed include:
• Leveraging MITRE ATT&CK as a "common language" in the organization
• Building your own Cuckoo sandbox solution to analyze payloads
• Developing effective group policies to improve script execution (including PowerShell, Windows Script Host, VBA, HTA, etc.)
• Highlighting key bypass strategies for script controls (Unmanaged Powershell, AMSI bypasses, etc.)
• Stopping 0-day exploits using ExploitGuard and application whitelisting
• Highlighting key bypass strategies in application whitelisting (focus on AppLocker)
• Detecting and preventing malware persistence
• Leveraging the Elastic stack as a central log analysis solution
• Detecting and preventing lateral movement through Sysmon, Windows event monitoring, and group policies
• Blocking and detecting command and control through network traffic analysis
• Leveraging threat intelligence to improve your security posture
Homepage
Code:



