April 3, 2023, 6:39 p.m. | SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response www.youtube.com

SANS Cyber Threat Intelligence Summit 2023

Breaking the Ransomware Tool Set: When a Threat Actor Opsec FailureBecame a Threat Intelligence Gold Mine
Nicklas Keijser

During a recent incident response engagement I was assigned to reverse engineer the RAT that the threat actor had deployed in the environment. During the malware analysis a suspicious string was found in the memory, https://ipnumber/list.txt. The list contained a not only a complete inventory that the threat actor had, but also a link to the …

actor analysis computers copy cyber cyber threat cyber threat intelligence down find intelligence intrusion keys logs malware malware analysis opsec ransomware sans summit techniques threat threat actor threat actors threat intelligence tool turn undetected virus

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Level 1 SOC Analyst

@ Telefonica Tech | Dublin, Ireland

Specialist, Database Security

@ OP Financial Group | Helsinki, FI

Senior Manager, Cyber Offensive Security

@ Edwards Lifesciences | Poland-Remote

Information System Security Officer

@ Booz Allen Hamilton | USA, AL, Huntsville (4200 Rideout Rd SW)

Senior Security Analyst - Protective Security (Open to remote across ANZ)

@ Canva | Sydney, Australia