Book Image

Cyber Threat Hunting [Video]

By : Sunil Gupta
2 (1)
Book Image

Cyber Threat Hunting [Video]

2 (1)
By: Sunil Gupta

Overview of this book

<p>Threat hunting is the proactive technique that focuses on the pursuit of attacks and the evidence that attackers leave behind when they conduct reconnaissance, attack with malware, or exfiltrate sensitive data. This process allows attacks to be discovered earlier with the goal of stopping them before intruders are able to carry out their attacks and take illegal advantage of them.</p> <p>In this course, you will get to know about the tools, techniques, and procedures necessary to effectively hunt, detect, and contain a variety of adversaries and to minimize incidents. You'll perform incident response and hunt across hundreds of unique systems using PowerShell and identify and track malware beaconing outbound to its command and control (C2) channel via memory forensics, registry analysis, and network connection residues.<br />You will determine how the breach occurred by identifying the beachhead and spear phishing attack mechanisms. You will be able to use memory analysis, incident response, and threat hunting tools to detect malware, attacker command lines, network connections, and more.</p> <h1>Style and Approach</h1> <p>With extensive theoretical exploration on the subject in the initial half of the course, the concepts are demonstrated effectively with the help of detailed practical sessions in the second half of the course.</p>
Table of Contents (7 chapters)
Chapter 7
Hunting Malware
Content Locked
Section 4
Memory Analysis
Advance technique to analyse malware in systems - Learn about memory analysis - Get memory file of victim machine - Analyse victim machine memory file using volatility tool