Course Hive
Search

Welcome

Sign in or create your account

Continue with Google
or
Incident Response Training Course, Malware Alert Investigation, Day 14
Play lesson

BlackPerl DFIR || INCIDENT RESPONSE TRAINING || Full Course - Incident Response Training Course, Malware Alert Investigation, Day 14

5.0 (0)
14 learners

What you'll learn

This course includes

  • 13.5 hours of video
  • Certificate of completion
  • Access on mobile and TV

Summary

Keywords

Full Transcript

In this full series we will talk about Incident Response and it will be a Free Training Course for everyone. Today is Day-14 and I will show you a real SOC Incident that came from SIEM tool where Antivirus fired an alert of one machine being infected by Emotet Malware. There was another PC on the same network which started suspicious outbound connection just after the first machine got infected with Emotet. In this episode, I will show you how can you efficiently and quickly perform analysis on the memory of the second PC and identify what's wrong in it and what is the relation between PC1 Infection and PC2 outbound communication. This is an example of triaging real SOC Detection Alert which might arise anytime in your SOC. So we will be covering and trying to answer below questions- 1. Why PC2 is communicating to a malicious IP? 2. Is PC2 also infected with Emotet? 3. If 2 is True, how can you prove that? 4. Any process injection took place on it? 5. What are the IOCs present on the PC2 apart from the IP address? 6. What steps need to be done to contain this incident? 7. If this type of case arises to your SOC, what you MUST do at first. So if you want to become a SOC BOSS, watch the full episode. All feedbacks are appreciated!! Comment and let me know if you have ever come across any such scenarios or learned something new! Tools I have used in this Episode- 👉 Volatility 👉 Floss 👉 Capa 🔮DISCLIAMER ------------------------------------------------------------------------------------------------------------------------- The story has been developed with inspiration of a real case study and from the help of https://cyberdefenders.org/labs/78. Of note, the memory from this repository contains actual Windows-based malware. That poses a risk of infection when reviewing the pcap on a Windows-based host. I recommend people review the memory in a non-Windows environment. WATCH BELOW Playlists as well, if you want to make your career in DFIR and Security Operations!! ------------------------------------------------------------------------------------------------------------------------- INCIDENT RESPONSE TRAINING Full Course 👉https://youtube.com/playlist?list=PLjWEV7pmvSa4yvhzNsCjOJovOn1LLyBXB DFIR Free Tools and Techniques 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa6f-NTpXsaUYWZLjLAB_0TS Windows and Memory Forensics 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa50erciZUSnzvE7nK0FyvsH Malware Analysis 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa6u32RongesgDtkfKBfrFWW SIEM Tutorial 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa7cXTkCppnYHERUdy8Dd71x Threat Hunt & Threat Intelligence 👉 https://youtube.com/playlist?list=PLjWEV7pmvSa5UTZlsWp5wRnURNbeMS-fu ⌚ Timelines ------------------------------------------------------------------------------------------------------------------------- 0:00 ⏩ Introduction 1:05 ⏩ Background of Alert 2:44 ⏩ Memory Analysis of PC2 6:13 ⏩ Identify Hidden Process 11:12 ⏩ Dump Malicious Process 15:11 ⏩ Identify Process Injection 21:00 ⏩ Identify Actual Process 27:58 ⏩ Containment/remediation Steps 30:08 ⏩ Summarize 📞đŸ“Č FOLLOW ME EVERYWHERE- ------------------------------------------------------------------------------------------------------------------------- ✔ LinkedIn: https://www.linkedin.com/company/blackperl ✔ You can reach out to me personally in LinkedIn as well- https://bit.ly/38ze4L5 ✔ Twitter: @blackperl_dfir ✔ Git: https://github.com/archanchoudhury ✔ Insta: (blackperl_dfir)https://www.instagram.com/blackperl_dfir/ ✔ Can be reached via [email protected] CREDIT ------------------------------------------------------------------------------------------------------------------------- Thank you, Alex Siviero for creating and sharing the memory dump! Thank you, https://cyberdefenders.org/ for making such awesome CTFs! SUPPORT BLACKPERL ------------------------------------------------------------------------------------------------------------------------- ╔═╩╗╔╩╗╔═╩═╩╩╩╩╗╔═╗ ║╚╣║║║╚╣╚╣╔╣╔╣║╚╣═╣ ╠╗║╚╝║║╠╗║╚╣║║║║║═╣ ╚═╩══╩═╩═╩═╩╝╚╩═╩═╝ âžĄïž SUBSCRIBE, Share, Like, Comment ☕ Buy me a Coffee 👉 https://www.buymeacoffee.com/BlackPerl 📧 Sponsorship Inquiries: [email protected] ------------------------------------------------------------------------------------------------------------------------- 🙏 Thanks for watching!! Be CyberAware!! đŸ€ž

Course Hive

Continue this lesson in the app

Install CourseHive on Android or iOS to keep learning while you move.

Related Courses

FAQs

Course Hive
Download CourseHive
Keep learning anywhere