Packets or It Didn't Happen: Network-Driven Incident Investigations

  • Thursday, 20 May 2021 2:00PM EDT (20 May 2021 18:00 UTC)
  • Speakers: Alan Hall, Jake Williams

The way we handle incident response has changed in recent years. With it, so has the role of network data in incident response investigations. In this webcast, SANS Senior Instructor Jake Williams and Symantec's Broadcom's Alan Hall examine the use of network traffic capture in today's incident response environment. They will explore questions such as:

  • Is there any replacement for a full PCAP?
  • Can endpoint antiforensics activities be confirmed with packet capture?
  • What can network traffic tell us if an attackers can perform anti-forensics on the endpoint?
  • Even without TLS break/inspect, is there any value in analyzing encrypted communications?

Be among the first to receive the associated whitepaper written by Jake Williams.


Symantec by Broadcom logo