SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Extended File Attributes are the Linux version of the NTFS ADS (Alternate Data Stream). They are use for the same kind of purposes but may sometimes contain very interesting data like payloads or encrypted data. This presentation will be split in two parts: First, I'll show you how to hide a simple payload in Extended File Attributes (the bad guy), then I'll show you how to can hunt for such attributes (the good guy).
This presentation sets the stage for a critical discussion on third-party risk management in cybersecurity. The agenda outlines a journey from awareness to action, covering why vendor risk matters, current practices, real-world breaches, limitations of questionnaires, recommended improvements, and key takeaways. It emphasizes the importance of rethinking how organizations assess and manage vendor relationships in an increasingly interconnected digital landscape.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.