Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
The Most Dangerous Game
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Scott J. Roberts
February 03, 2015
Technology
5.4k
5
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
The Most Dangerous Game
A presentation about merging Threat Intelligence and DFIR by the team behind YoloThre.at.
Scott J. Roberts
February 03, 2015
More Decks by Scott J. Roberts
See All by Scott J. Roberts
LLM SATs FTW
sroberts
0
1.5k
STRAT - A System-Centric Approach to Cyber Resilience
sroberts
0
91
Tortured Responders Dept - Scott & Rebekah's Edition
sroberts
0
180
Skynet the CTI Intern: Building Effective Machine Augmented Intelligence
sroberts
0
200
DRIVING INTELLIGENCE WITH MITRE ATT&CK: LEVERAGING LIMITED RESOURCES TO BUILD AN EVOLVING THREAT REPOSITORY
sroberts
0
140
Exploring Threat Intelligence: Insights and Tools from Vertex Synapse
sroberts
0
130
Homemade Ramen & Threat Intelligence
sroberts
2
630
Introduction to Open Source Security Tools
sroberts
3
5.1k
Building Effective Threat Intelligence Sharing
sroberts
1
150
Other Decks in Technology
See All in Technology
ファミコンでPHPを動かす / PHP on the Famicom
tomzoh
2
150
ZOZOTOWNの進化と信頼性を両立する負荷試験
zozotech
PRO
2
170
SRE依存からの脱却 運用を開 発チームへ移す、 フルサイ クル開 発体制の実践
joooee0000
0
2.8k
AI時代のYAGNI:「爆速で無駄になった機能」からの学び / 20260720 Naoki Takahashi
shift_evolve
PRO
2
130
環境凍結という Toil を倒す -セルフサービス型 Ephemeral テスト環境の 設計と実践
shirouz
1
2.4k
誤解だらけの開発生産性 / Myths and Misconceptions about Developer Productivity
i35_267
2
710
「ちゃんとやっている」は独りよがりだった ― 不安に寄り添うインシデント対応へ / Towards incident response that addresses anxieties
chmikata
1
5.6k
公式ドキュメントの歩き方etc
coco_se
0
110
壊して学ぶAWS CDK: そのcdk deployで消えるもの、残るもの
k_adachi_01
1
270
Empower GenAI with Agile - あなたのアジャイルが生成AIのバフになる仕組み
hageyahhoo
1
210
LLM/Agent評価:トップ営業の発言を「正解」にする 〜暗黙的正解による評価を営業資産に変える〜
takkuhiro
1
230
AIと共生する開発者プラットフォーム:バクラクのモノレポ×マイクロサービス基盤
sakajunquality
2
3.6k
Featured
See All Featured
SEO for Brand Visibility & Recognition
aleyda
0
4.6k
Design in an AI World
tapps
1
260
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
46
2.9k
Principles of Awesome APIs and How to Build Them.
keavy
128
18k
Public Speaking Without Barfing On Your Shoes - THAT 2023
reverentgeek
1
460
Lessons Learnt from Crawling 1000+ Websites
charlesmeaden
PRO
1
1.4k
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
47
8.2k
ピンチをチャンスに:未来をつくるプロダクトロードマップ #pmconf2020
aki_iinuma
128
56k
Site-Speed That Sticks
csswizardry
13
1.3k
個人開発の失敗を避けるイケてる考え方 / tips for indie hackers
panda_program
123
22k
Navigating the Design Leadership Dip - Product Design Week Design Leaders+ Conference 2024
apolaine
1
370
職位にかかわらず全員がリーダーシップを発揮するチーム作り / Building a team where everyone can demonstrate leadership regardless of position
madoxten
63
55k
Transcript
The Most Dangerous Game Hunting Adversaries Across the Internet
Kyle Maxwell Super Special Security Researcher @ iDefense
Scott J Roberts Advanced Persistent Incident Responder @ GitHub
How Kyle met Scott or How Scott met Kyle
If you are on the Twitter we’re @kylemaxwell & @sroberts
#YOLOTHREAT
Intelligence Concepts That everyone knows and already agrees on right…?
Data vs Intelligence Intelligence has gone through the intelligence process
Data is a raw piece of information without context
Feedback Analysis Processing Dissemination Collection Requirements Intelligence Cycle
F3EAD While… Find Exploit Finish Disseminate Fix Analyze
The Target
What is Targeting? Making a plan for focusing threat research
& investigation
Targeting Methodologies Actor Centric ~ Target Centric ~ Technology centric
Feeds Needles in Haystacks
“My 5.4 gazillion indicators can beat up your threat indicators.
Garbage in garbage out #ThreatIntel ~ Rick Holland
Honeypots Bringing the Bad Guys to You
Low vs High Interaction High interaction honeypots are a risky
& complicated way to generate high quality intelligence Low interaction honeypots are an easy way to get low value intel on commodity threats
Software Old School: HoneyNet Project New Hotness: Modern Honey Network
by Threat Stream
Vulnerability Information Taking care of your Toys
“Structured vulnerability analysis is not threat intelligence it is requirements
gathering for threat intelligence. ~ @selil
Vendor Information Blogs ~ Reports ~ Services & APIs
Personal Aside to Vendors If you’re going to release a
report, blog post, etc: do not break the Cut and Copy Actions
None
Review Your Own Incidents Mine that fancy Incident Management System…
Review Your Others Incidents By sharing or News mining
The Hunt
What to Analyze Technical Sources
What to Analyze: Hashes Reversing: • C2 info • Developer
artifacts Sources: • VxShare • VirusTotal • malwr.com
What to Analyze: Passive DNS • Single most useful tool
for infrastructure research • What resolved to what, and when? • DNSDB (Farsight), PassiveTotal, VirusTotal
What to Analyze: Whois • Tougher to Acquire • WhoDat
etc for ongoing Tracking
What to Analyze Actors
What to Analyze: Criminal • Primary Weapon: Google • Social
Media (Twitter, Facebook) • Underground forums?
What to Analyze: Espionage • This is hard • Malware
& System artifacts • whois/registrar data • actions over target
How to Keep Tracking
Threat Library • CRITs is popular, MISP also • Lighter
solutions often work • Market hasn't fully addressed this
Web Monitoring Systems • Netflix Scumblr Meta SearcH (Works alongside
Sketchy) • Recorded Future • Lots of custom development
Malware Monitoring • VirusTotal is • Malware feeds with Lots
of custom internal solutions • Maltrieve, Viper, & Cuckoo
Internal Logging • Firewall, IDS, & Proxy • Web, mail,
& DNS • Authentication & Audit
The “Kill”
Incident Response The Entire Goal… Right?
The Imitation Game Don’t let them know that you know
that they know…
Attribution Probably doesn’t matter unless you can do this
Hand Cuffs or Cruise Missiles
KICK ‘EM OUT NOW! Sometimes it’s better to watch for
a while
Intel Driven Responses deny Deceive ⁉️ degrade ⁉️ disrupt ⁉️
Destroy ‼️
Communication Who can make use of this information? ~ Who
might be able to provide additional intel?
The Hunting Stories
Products IOCs & RFIs ~ Short Form Products ~ Long
Form Products
Audience Internal - Team Internal - Organization External - Peers
External - Wide
IOCs - Generalized Stix & OpenIOC
“you pretty much need a PHD in XML to understand
either STIX or TAXII ~ Jeff Bryner
XKCD.com/927
IOCs - Specialized Yara: Malware centric av signature style IOCs,
getting more advanced Snort: Go to for network activity, Comprehensive and well supported
“OH: "Yara is an antivirus that you update using git
pull" ~ @tomchop_
Requests For Intelligence A Q/A requesting very specific Intelligence ~
Shortest form Possible ~ Fastest turn around
Short Form Products Intermediate products to support incident response ~
Focus on actionable Information
Long Form Products Comprehensive “All Source” intelligence products ~ Requires
considerable Time & a well rounded team
The Surprise…
You Can’t Download a Threat Intelligence Until now….
The Surprise Coming out of Stealth Today, our new Startup…
YOLOTHRE.At
Announcement yolothre.at has run out of runway (We used up
our whole Starbucks Gift Card) SO we’re open sourcing everything and going back to our old jobs...
YoloThre.at A collection of open source docker containers for Threat
Intel
Including Maltrieve Malware Collection Combine Threat Feed Aggregator Scumblr Social
Network Collection CRITs Intel Collection System MISP Malware Analysis Hub ELK Log Analysis Viper Malware Zoo System Thug Website Collection Tool Yara Malware Identification
Review
Review The Target The Hunt The “Kill” The Hunting Stories
Questions?
Thanks
None