Emulating, Detecting, and Responding to LOLBAS Attacks – A SEC699 Update Preview

Join SANS Certified Instructor Jean-François Maes as he previews new material directly from the updated SANS SEC699: Purple Team Tactics - Adversary Emulation for Breach Prevention & Detection. Once attackers have gained initial access, they do not want to get caught by the suite of security tools on modern Windows systems. To stay under the radar, attackers leverage Living Off the Land Binaries and Scripts (LOLBAS). These are signed, allowed, and often built-in binaries, scripts, and libraries that have additional functionality attackers can abuse. In this webcast, Jean will introduce various LOLBAS, how to emulate them, detect, and respond to them in a true purple team fashion. As usual, expect demos and dad jokes.

PurpleTeam_Webcast_Emulating_DetectingandRespondingtoLOLBAS_5.jpg