Reverse Analyzing Attacks for Detection, Justin Henderson Paul's Security Weekly #519
974 views · Published 23 June 2017 · 36:24 · Indexed 21 September 2026
Channel: Security Weekly - A CRA Resource · 2017 · Science & Technology
Learn how to use Windows Event Logs to catch attackers in your network, including domain admin group enumeration and mimikatz attacks! Justin Henderson (@SecurityMapper) categorizes these techniques as "reverse attack analysis for detection" and shows us how to do it in this technical segment! References to Mark Baggett's work on freq.py are made as well (https://isc.sans.edu/forums/diary/Detecting+Random+Finding+Algorithmically+chosen+DNS+names+DGA/19893/) Full Show Notes: https://wiki.securityweekly.com/Episode519 Security Weekly Web Site: http://securityweekly.com Follow us on Twitter: @securityweekly
More from this channel
-
51:27
Security Weekly #399 - Security News (The f**k you Kris Episode)
-
39:57
Security Weekly #410 - Interview with Pablos Holman
-
58:33
Security Weekly #415 - Interview with Apollo Clark
-
47:08
Security Weekly #462: Stories of the Week
-
8:10
Hack Naked TV - May 3, 2016
-
1:05:06
Paul's Security Weekly #485 - Scott Lyons and Joshua Marpet, Guarded Risk
-
29:35
THROWBACK - Interview with Adrian "Irongeek" Crenshaw (EP321)
-
13:05
Enterprise Security Weekly #27 - Win10 Ubuntu with John Strand