Optimizing Security Incident Response
Facebook Twitter LinkedIn

Optimizing Security Incident Response

Combined Session
Wednesday, September 15, 2021 12:00—13:00
Location: AMMERSEE II

From Zero to Full Domain Admin: The Real-World Story of a Ransomware Attack

Following in the footsteps of a cyber-criminal and uncovering their digital footprint. This is a journey inside the mind of an ethical hacker's response to a ransomware incident that brought a business to a full stop, and discovering the evidence left behind to uncover their attack path and the techniques used. Malicious attackers look for the cheapest, fastest, stealthiest way to achieve their goals. Windows endpoints provide many opportunities to gain entry to IT environments and access sensitive information. This session will show you the attacker's techniques used and how they went from zero to full domain admin compromise that resulted in a nasty CryLock ransomware incident.

In this session I will cover a real-world incident response to the CryLock ransomware showing the techniques used by the attackers.  The footprints left behind and uncovering the techniques used. 

•              How attackers gained access to system

•              Established staging

•              What tools were used

•              What commands were executed

•              How the ransomware was delivered

•              How AD elevation was achieved

Joseph Carson
Joseph Carson
Thycotic
Joseph Carson is an award-winning cyber security professional and ethical hacker with more than 25 years’ experience in enterprise security specialising in blockchain, endpoint security,...

Panel: Best Practices to Implement Security Automation

Alexei Balaganski
Alexei Balaganski
KuppingerCole
Alexei is an analyst with specific focus on cybersecurity and Artificial Intelligence. At KuppingerCole, he covers a broad range of security-related topics: from database, application and API...
Joseph Carson
Joseph Carson
Thycotic
Joseph Carson is an award-winning cyber security professional and ethical hacker with more than 25 years’ experience in enterprise security specialising in blockchain, endpoint security,...
Christopher Schütze
Christopher Schütze
KuppingerCole
Christopher Schütze has been working as Director Practice Cybersecurity and Lead Analyst for KuppingerCole Analysts AG since 2019. Prior to that, he was Head of Cloud Security at an auditing...

Tickets

On-Demand Access
Re-live EIC 2021
€100
 
Watch more than 250 sessions on-demand
Download all available presentations
Subscribe for updates
Please provide your email address