Register now for SANS Cyber Defense Initiative 2016 and save $400.

Baltimore 2015

Baltimore, MD | Mon, Sep 21 - Sat, Sep 26, 2015

The Plinko Board of Modern Persistence Techniques

  • Alissa Torres
  • Thursday, September 24th, 7:15pm - 8:15pm

No matter what techniques an attacker employs to hide and persist on compromised remote systems, we must be up for the challenge, to detect, analyze and remediate. This session focuses on the latest techniques modern malware is using to ensure continued presence in your network. As detailed in recently released industry threat intelligence reports, these methods are increasing in sophistication and are often times missed by forensics tools developed to only enumerate common autorun and service persistence methods. In this presentation, we will cover advanced detection techniques, pivoting from physical memory analysis to the examination of remnants found on the file system.

Bonus Sessions

The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:

  • SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
  • Special Events: SANS-hosted events and other non-technical recreational offerings. This category includes, but is not limited to, Receptions and Information Tables.
  • Lunch & Learn: Short presentations given during the lunch break.
  • Master's Degree Presentation: Presentations given by SANS Technology Institute's Master's Degree candidates.
Monday, September 21
Session Speaker Time Type
General Session - Welcome to SANS Paul Henry Monday, September 21st, 8:15am - 8:45am Special Events
Evolving Threats & Defences Paul Henry Monday, September 21st, 7:15pm - 9:15pm Keynote
Tuesday, September 22
Session Speaker Time Type
How to bring some Advanced Persistent Trickery to your fight against Advanced Persistent Threats.. Bryce Galbraith Tuesday, September 22nd, 7:15pm - 8:15pm SANS@Night
Wednesday, September 23
Session Speaker Time Type
Adopting an Attacker Mindset with Core Impact Pro Bobby Kuzma, Systems Engineer, Core Security Wednesday, September 23rd, 12:30pm - 1:15pm Lunch and Learn
Applying Lessons Learned for the US DoD Next Generation Vulnerability Management System (VMS) John Dittmer - Master's Degree Candidate Wednesday, September 23rd, 7:15pm - 7:55pm Master's Degree Presentation
Thursday, September 24
Session Speaker Time Type
The Plinko Board of Modern Persistence Techniques Alissa Torres Thursday, September 24th, 7:15pm - 8:15pm SANS@Night