SEC536: Adversarial AI - Penetration Testing AI Systems



Registration:
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
Computer Requirements: Laptop/desktop-based
Extra Requirements: Files downloads are required to participate.
Recommended For: Experienced Digital Forensic Analysts, Forensic Examiners, Media Exploitation Examiners, Malware Analysts, Incident Responders, Threat Hunters, Security Operations Center (SOC) Analysts, Law Enforcement Officers, Federal Agents, Detectives, and Cyber Crime Investigators.
Disciplines: Digital Forensics, Incident Response.
Example Topics:
Interactive Scenario: As a DFIR specialist, you are provided with evidence files from a series of mysterious compromised systems and conventional computing environments. Your mission? Use your DFIR skills to shed light on attack vectors, indicators of compromise, and other evidence needed to resolve the incident.
In-Person & Virtual
Registration:
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
Computer Requirements: Laptop/desktop-based
Extra Requirements: Files downloads are required to participate.
Recommended For: Experienced Digital Forensic Analysts, Forensic Examiners, Media Exploitation Examiners, Malware Analysts, Incident Responders, Threat Hunters, Security Operations Center (SOC) Analysts, Law Enforcement Officers, Federal Agents, Detectives, and Cyber Crime Investigators.
Disciplines: Digital Forensics, Incident Response.
Example Topics:
Interactive Scenario: As a DFIR specialist, you are provided with evidence files from a series of mysterious compromised systems and conventional computing environments. Your mission? Use your DFIR skills to shed light on attack vectors, indicators of compromise, and other evidence needed to resolve the incident.
In-Person & Virtual
Everyday, our mailboxes are flooded with phishing emails that impersonate well-know brands or make the victim uncomfortable (hack, data-leak, risk of data loss, …). Hopefully, most of us just delete them but… what happens with the credentials you left by mistake on a fake login page?
We developed a tool that is an advanced honeypot. First, our bot will visit the fake pages and fill forms with randomly-generated credentials. Then, we will track them expecting them to be used by threat actors against our honeypots (portal, VPN, RDP, VNC, etc). Because credentials are unique, we can link them to threat acts and track them.
The presentation will be contain a presentation of the research, the tool we build and of course some statistics gathered from our huge list of malicious URLs!
In-Person
This talk is about throwing everything but the kitchen sink at the problem of C2 detection and obsessing over the nitty-gritty details of spotting beaconing traffic. We are going to look at various data science approaches like statistical methods, signal processing, probability theory, machine learning, and... what? AI? Sure, maybe that one too! I mean, why not?
However, these solutions are not fast, nor perfect out of the box, so we are going to leave behind all those JupyterLab notebooks to address code optimization, multi-threading, and using accelerated computing as well. We will show you our results when we pit our implementations and novel solutions against other tools and projects, such as Flare or RITA, to compare and further improve the current state of the art.
Sounds awesome, right? Yeah... if you have the data to begin with! But where can we find it? And how can we massage it into a format that is useful for us? We will also consider the often-overlooked issue of finding data for testing and training models, and then generating and collecting the data for detection.
In-Person