From The Trenches: Observations of and Tracking Actor Activity
From The Trenches: Observations of and Tracking Actor Activity
OBSERVATIONS OF AND
TRACKING ACTOR ACTIVITY
H. CARVEY, SR RESEARCHER, OWSR-OUTREACH
Event Enrichment
MITRE ATT&CK
Things we see
Nuggets
https://www.crowdstrike.com/resources/
reports/2019-crowdstrike-global-threat-
report/
Modify system binaries – compile new functions into ssh/sshd to record credentials,
permit access via “magic key”
Linux
Use of netcat (data exfil); i.e., “nc –nv < some_file.zip”