Chris Sanders 🔎 🧠
Security Analyst, Author, and Instructor, Ed.D.
Studying the intersection of security investigation doctrine, cognitive psychology, and education.
Founder of Applied Network Defense and Rural Tech Fund
Books:
🍯 Intrusion Detection Honeypots
🦈 Practical Packet Analysis
🌐 Applied Network Security Monitoring
Former: Mandiant, InGuardians, Dept of Defense, Roadside Fruit Vendor.
A question well stated is a problem half-solved. #InvestigationTheory
I ask everyone who starts my Investigation Theory class, "What's a valuable trait or skill for an analyst to have?"
Many say "thinking outside the box"
And sometimes, unconventional solutions are exactly what’s needed.
But the pursuit of novelty can't be an excuse for ignorance of proven doctrine, either.
Sometimes we need folks thinking outside the box, but more often, we just need to understand the box better.
A whole bunch of people DM'd me about meeting Cliff Stoll in Vegas and I love that I've done things in my life that have folks wanting to share that specific joy with me. 💙😂 #cuckoosegg
Investigation Scenario 🔎
A user’s RecentDocs LNK file points to C:\Users\Public\Libraries\update.iso, mounted shortly before rundll32.exe launched update.dll from the new drive letter. The ISO is now gone.
What do you look for to investigate whether an incident occurred?
Investigation Scenario 🔎
You received an alert that one of your honeydocs was opened on a network other than your own.
What do you look for to investigate whether an attacker exfiltrated this file from your network?
Investigation Scenario 🔎
While reviewing Amcache.hve, you notice C:\Users\Public\Libraries\SyncHost.exe executed once, but no corresponding Prefetch file exists despite Prefetch being enabled. The file is not present at that location.
What do you look for to investigate whether an incident occurred?
Bonus Exercise: List several of the potential explanations for this behavior
RE: @dougburks@infosec.exchange
Doug built ANOTHER useful thing! I had a chance to play around with OhMyPCAP pre-release... super handy and worth having in your toolbox!
You always want to take the smallest slice of data necessary to answer an investigative question you're asking. It forces you to be focused and specific, while also limiting data processing time and resource utilization on your tools. I preach this frequently to my Investigation Theory students.
When you hear the word "identity" in cybersecurity, what does that mean to you? How do you define it?
Investigation Scenario 🔎
While investigating a potentially compromised host, you've discovered %LOCALAPPDATA%\Syncthing\config.xml. The user has no knowledge of ever using this application.
What do you look for to investigate whether the tool was used for malicious purposes?
Investigation Scenario 🔎
While investigating potential intellectual property theft, you discover the pictured registry artifact on a Windows 11 system.
The user claims they only connected a USB-C docking station.
What do you look for to investigate whether an incident occurred? Extra credit for focusing on the distinct order of operations you would take.
Investigation Scenario 🔎
A workstation’s $UsnJrnl shows a .lnk file created and deleted from %APPDATA%\Microsoft\Windows\Recent\ within 4 seconds, but the referenced file never appears in the MFT.
What do you look for next to determine what the user actually opened and whether malicious execution followed?
Investigation Scenario 🔎
Your SIEM alerted on mshta.exe spawning PowerShell, but an overly aggressive analyst reimaged the host before you could investigate. You only have Windows Event Logs (default config) and network sensor data. What do you look for to determine whether an incident occurred?