Hunting Threats in Your Enterprise
Hunting Threats in Your Enterprise
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
ü Who am I ?
ü Abdulrahman Al-Nimari
ü 25 Years IT & Infosec Experience
ü Lead Enterprise Security Architect
ü Mantech International Corporation, Riyadh, KSA
ü CISSP, CISM, CCISO, PMP, GCIH, GCIA, GCUX, GREM, GSEC
ü @nimari
ü https://www.linkedin.com/in/alnimari/
ü alnimari@gmail.com
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
ü Agenda
ü What is Threat Hunting ?
ü Threat Hunting Plan
ü Hunt Cycle
ü Hunting in Action
ü Hunt Maturity Level
ü Measuring Success ( Metrics )
ü Resources
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
https://www.verizonenterprise.com/resources/reports/rp_DBIR_2018_Report_execsummary_en_xg.pdf
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/ 7
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/ 8
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Know Your Adversary - Cyber Kill Chain
A cyber kill chain is a ‘Lockheed Martin’ model that reveals the stages of a cyber
attack from early reconnaissance to the goal of data exfiltration :
https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Intel-Driven-Defense.pdf
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Know Your Adversary – Mitre ATT&CK
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Collect Hunt Data
Data Domains :
Network Host Application
- Flow Data - NetFlow - AV/EDR/FW - Authentication
- PCAP - Windows/Sysmon Events - Transaction Logs
- DNS - File System - DB Logs
- Proxy Logs - Autoruns - Security Alerts
- FW/SW/Routers
ü Log Data
ü PCAP Data
ü Netflow
ü Threat Intelligence Data
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Creating Hypothesis
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Hunting Cycle
Iterate aggressively
through this cycle
https://sqrrl.com/the-threat-hunting-reference-model-part-2-the-hunting-loop/
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
https://sqrrl.com/the-threat-hunting-reference-model-part-1-measuring-hunting-maturity/
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Pyramid of Pain
HMM2,3,4
HMM1
HMM0
http://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Hunting in Action #1
Malicious IP
Network Flow Internal IP
Address(es)
Network
Anomaly Time Stamp
Flow
Investigate
PCAP/Logs
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Hunting in Action #2
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Hunting in Action #2
Deploy Compare to
Collect Results
autorunsc.exe to Baseline/VT
in SIEM
EP Hash DB
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
https://sqrrl.com/media/Your-Practical-Guide-to-Threat-Hunting.pdf
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
ü Resources
ü https://www.threathunting.net/
ü https://threathunting.org/
ü https://intel.criticalstack.com/
ü https://www.mitre.org/
ü https://www.elastic.co/
ü https://github.com/Cyb3rWard0g/ThreatHunter-Playbook
ü https://nxlog.co/
ü https://docs.microsoft.com/en-us/sysinternals/
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Q&A
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/
Hunting Threats in Your Enterprise
Thank You
Abdulrahman Al-Nimari | BSides Conference , Dubai 27-28, November, 2018 | @nimari | https://www.linkedin.com/in/alnimari/