1
1

00:00:00,330  -->  00:00:02,250
<v Instructor>Host-related IOCs</v>
2

2

00:00:02,250  -->  00:00:04,650
or indicators of compromise.
3

3

00:00:04,650  -->  00:00:06,300
Now, there are many contexts
4

4

00:00:06,300  -->  00:00:09,540
for analyzing indicators of compromise, or IOCs,
5

5

00:00:09,540  -->  00:00:12,210
including instant response, forensic investigations,
6

6

00:00:12,210  -->  00:00:15,540
and proactive threat hunting, as we've discussed before.
7

7

00:00:15,540  -->  00:00:16,800
Now, in the last section,
8

8

00:00:16,800  -->  00:00:19,230
we focused on network-related IOCs,
9

9

00:00:19,230  -->  00:00:21,180
but in this section, we're going to focus
10

10

00:00:21,180  -->  00:00:23,880
on host-related indicators of compromise.
11

11

00:00:23,880  -->  00:00:26,700
Now, what exactly do we consider a host?
12

12

00:00:26,700  -->  00:00:28,470
Well, for the purposes of this section,
13

13

00:00:28,470  -->  00:00:31,260
we're really going to focus on the world's most popular hosts,
14

14

00:00:31,260  -->  00:00:34,710
Windows-based computers, laptops, and tablets.
15

15

00:00:34,710  -->  00:00:37,500
Now, while it's true that things like smartphones, tablets,
16

16

00:00:37,500  -->  00:00:39,870
and other devices can be considered hosts,
17

17

00:00:39,870  -->  00:00:41,787
we really are going to be focused more on Windows,
18

18

00:00:41,787  -->  00:00:44,490
and to some extent, Linux in this section
19

19

00:00:44,490  -->  00:00:47,310
due to their popularity as workstations and servers
20

20

00:00:47,310  -->  00:00:49,020
in the business environment.
21

21

00:00:49,020  -->  00:00:50,190
In a later section,
22

22

00:00:50,190  -->  00:00:52,470
we're going to cover mobile IOCs separately
23

23

00:00:52,470  -->  00:00:55,020
because those are going to rely on different operating systems
24

24

00:00:55,020  -->  00:00:57,420
and different tools to analyze them.
25

25

00:00:57,420  -->  00:00:58,727
So in the rest of this section,
26

26

00:00:58,727  -->  00:01:00,780
we are going to focus on the different ways
27

27

00:01:00,780  -->  00:01:03,930
of identifying bad behavior on a given host.
28

28

00:01:03,930  -->  00:01:07,230
Essentially, we need to find an indicator of compromise,
29

29

00:01:07,230  -->  00:01:10,200
which we define as a sign that an asset has been attacked
30

30

00:01:10,200  -->  00:01:12,000
or is currently under attack.
31

31

00:01:12,000  -->  00:01:14,460
Now, once we find an indicator of compromise,
32

32

00:01:14,460  -->  00:01:16,980
we can then use that IOC to create defenses
33

33

00:01:16,980  -->  00:01:18,240
against these attacks,
34

34

00:01:18,240  -->  00:01:20,640
and we can use them in our threat hunting.
35

35

00:01:20,640  -->  00:01:23,070
These indicators of compromised can help us identify
36

36

00:01:23,070  -->  00:01:24,960
the presence of malware on a host,
37

37

00:01:24,960  -->  00:01:26,220
whether unauthorized accounts
38

38

00:01:26,220  -->  00:01:27,630
and permissions have been created,
39

39

00:01:27,630  -->  00:01:30,270
and if the files have been accessed or exfiltrated.
40

40

00:01:30,270  -->  00:01:32,730
So let's start identifying these IOCs
41

41

00:01:32,730  -->  00:01:35,040
by examining system memory, the file system,
42

42

00:01:35,040  -->  00:01:37,383
and the operating system logs on a given host.
