Get an 11" iPad Pro, Surface Go 2, or $300 Off with OnDemand Training

Webcasts

To attend this webcast, login to your SANS Account or create your Account.

This webcast has been archived. To view the webcast login into your SANS Portal Account or create an account by clicking the "Get Registered" button on the right. Once you register, you can download the presentation slides below.

Bring the Fight to Them: Hunting down adversaries using OSQuery

  • Tuesday, December 05, 2017 at 10:30 AM EST (2017-12-05 15:30:00 UTC)
  • Erik Van Buggenhout, Stephen Sims

You can now attend the webcast using your mobile device!

  

Overview

Defeating Advanced Adversariesa webcast series. In the first webcast of the series, SEC599 Course Authors and Instructors Stephen Sims and Erik Van Buggenhout will walk through how OSQuery can be leveraged to obtain interesting information about your environment. "We will discuss the inner workings of OSQuery and how you can leverage it effectively to obtain critical information." A webcast wouldn't be complete unless we had a live demoview the new lab platform where we will demonstrate how to detect an actual infection using OSQuery.

Watch Part 2 and Part 3 in the Defeating Advanced Adversaries Series

Speaker Bios

Stephen Sims

Stephen Sims is an industry expert with over 15 years of experience in information technology and security. Stephen currently works out of San Francisco as a consultant. He has spent many years performing security architecture, exploit development, reverse engineering, and penetration testing. Stephen has an MS in information assurance from Norwich University and is a course author and senior instructor for the SANS Institute. He is the author of SANS' only 700-level course, SEC760: Advanced Exploit Development for Penetration Testers, which concentrates on complex heap overflows, patch diffing, and client-side exploits. Stephen is also the lead author on SEC660: Advanced Penetration Testing, Exploits, and Ethical Hacking and co-author of SEC599: Defeating Advanced Adversaries Purple Team Tactics & Kill Chain Defenses. He holds the GIAC Security Expert (GSE) certification as well as the CISSP, CISA, Immunity NOP, and many other certifications. In his spare time Stephen enjoys snowboarding and writing music.


Erik Van Buggenhout

Erik Van Buggenhout is the lead author of SEC599 - Defeating Advanced Adversaries and SEC699 - Purple Team Tactics. In addition to SEC599 and SEC699, Erik teaches SEC560 - Network Penetration Testing & Ethical Hacking and SEC542 - Web Application Penetration Testing & Ethical Hacking. In addition to his work with SANS, Erik is the co-founder of Belgian cyber security firm NVISO. Together with his team of 70+ technical experts, Erik delivers a wide array of technical security services, including penetration testing, security monitoring & incident response.

Need Help? Visit our FAQ page or email webcast-support@sans.org.

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.