1
1

00:00:00,990  -->  00:00:02,040
<v Instructor>Endpoint detection</v>
2

2

00:00:02,040  -->  00:00:04,380
and response configuration.
3

3

00:00:04,380  -->  00:00:07,020
Now, like any other automated intrusion detection,
4

4

00:00:07,020  -->  00:00:10,080
endpoint detection response requires tuning
5

5

00:00:10,080  -->  00:00:12,240
to reduce your false positives
6

6

00:00:12,240  -->  00:00:14,520
because these rules that we use can actually
7

7

00:00:14,520  -->  00:00:16,680
start generating a lot of false positives for us.
8

8

00:00:16,680  -->  00:00:19,620
And if they do, that starts distracting our analysts
9

9

00:00:19,620  -->  00:00:21,150
and buries them in information,
10

10

00:00:21,150  -->  00:00:23,490
so they can't identify what's real.
11

11

00:00:23,490  -->  00:00:25,020
So one of the ways we can do this
12

12

00:00:25,020  -->  00:00:27,300
is we can take something that we think is malware
13

13

00:00:27,300  -->  00:00:30,030
and we can share it with other people in the community.
14

14

00:00:30,030  -->  00:00:31,890
By working together with different community
15

15

00:00:31,890  -->  00:00:34,320
and industry portals we can share that information
16

16

00:00:34,320  -->  00:00:35,790
and that threat intelligence and we can
17

17

00:00:35,790  -->  00:00:37,800
all learn from each other, this will help us
18

18

00:00:37,800  -->  00:00:38,970
develop better signatures
19

19

00:00:38,970  -->  00:00:41,610
and therefore, reduce our false positives.
20

20

00:00:41,610  -->  00:00:44,190
One such tool is called VirusTotal.
21

21

00:00:44,190  -->  00:00:45,810
Now, VirusTotal is going to inspect
22

22

00:00:45,810  -->  00:00:48,780
your items with over 70 different antivirus scanners,
23

23

00:00:48,780  -->  00:00:51,510
and URL and domain blacklisting services.
24

24

00:00:51,510  -->  00:00:53,340
In addition to a myriad of other tools
25

25

00:00:53,340  -->  00:00:56,700
they have to extract signals from the study content.
26

26

00:00:56,700  -->  00:00:58,860
This allows VirusTotal to get more information
27

27

00:00:58,860  -->  00:01:00,690
about more malware, and they share that
28

28

00:01:00,690  -->  00:01:02,400
with all the different antivirus companies
29

29

00:01:02,400  -->  00:01:03,780
so we can develop better signatures
30

30

00:01:03,780  -->  00:01:05,760
and get them out to you faster.
31

31

00:01:05,760  -->  00:01:07,620
Now, one note about VirusTotal,
32

32

00:01:07,620  -->  00:01:09,690
before you upload a file there
33

33

00:01:09,690  -->  00:01:12,300
you need to make sure your organization is okay with it.
34

34

00:01:12,300  -->  00:01:15,000
The reason I say this is because if you have been infected
35

35

00:01:15,000  -->  00:01:17,340
with malware and you take that and submit it
36

36

00:01:17,340  -->  00:01:19,800
to VirusTotal to let the rest of the community know
37

37

00:01:19,800  -->  00:01:22,200
the attackers also monitor VirusTotal.
38

38

00:01:22,200  -->  00:01:25,350
And so, they would know that their malware is now known
39

39

00:01:25,350  -->  00:01:27,900
and they might then change their techniques again.
40

40

00:01:27,900  -->  00:01:29,460
And so, this is something you have to think about.
41

41

00:01:29,460  -->  00:01:31,200
It's more of a risk versus reward.
42

42

00:01:31,200  -->  00:01:33,660
But, in general, VirusTotal is a great thing to use
43

43

00:01:33,660  -->  00:01:35,880
and it is free to be a part of their community,
44

44

00:01:35,880  -->  00:01:38,490
and be able to submit things and get results back.
45

45

00:01:38,490  -->  00:01:39,750
And this will help you figure out
46

46

00:01:39,750  -->  00:01:41,460
if you have a piece of malware on your hands,
47

47

00:01:41,460  -->  00:01:44,250
or if it's just a file that looks a little suspicious.
48

48

00:01:44,250  -->  00:01:46,290
Now another thing you can do with your malware samples
49

49

00:01:46,290  -->  00:01:48,780
is you can actually submit them to your antivirus company,
50

50

00:01:48,780  -->  00:01:50,940
or your cyber threat intelligence vendor.
51

51

00:01:50,940  -->  00:01:52,050
If you have a subscription with
52

52

00:01:52,050  -->  00:01:54,360
a cyber threat intelligence vendor, like FireEye,
53

53

00:01:54,360  -->  00:01:57,540
or Semantic, or Microsoft, or somebody like that
54

54

00:01:57,540  -->  00:02:00,060
they would actually like you to send them their samples
55

55

00:02:00,060  -->  00:02:02,160
because they can use that to build better rules
56

56

00:02:02,160  -->  00:02:04,440
and protect you and their other customers better.
57

57

00:02:04,440  -->  00:02:06,690
Now, your organization may also need to create
58

58

00:02:06,690  -->  00:02:10,050
your own custom malware signature or detection rules.
59

59

00:02:10,050  -->  00:02:12,630
Now, this is only done in very certain circumstances
60

60

00:02:12,630  -->  00:02:15,300
and depending on the type of organization you work for.
61

61

00:02:15,300  -->  00:02:17,460
Most organizations don't have to really get
62

62

00:02:17,460  -->  00:02:19,620
too in depth in making custom signatures.
63

63

00:02:19,620  -->  00:02:22,860
But depending on your use case, you may be asked to do this.
64

64

00:02:22,860  -->  00:02:25,290
If you are, you need to be able to make
65

65

00:02:25,290  -->  00:02:27,780
your signatures work with other programs though.
66

66

00:02:27,780  -->  00:02:29,430
And to do this you can make sure
67

67

00:02:29,430  -->  00:02:31,380
that you're using a certain scheme.
68

68

00:02:31,380  -->  00:02:33,270
One of the most common ones out there
69

69

00:02:33,270  -->  00:02:37,020
is Malware Attribute Enumeration and Characterization Scheme
70

70

00:02:37,020  -->  00:02:39,030
or MAEC, as it's pronounced.
71

71

00:02:39,030  -->  00:02:40,860
Now, MAEC is a standardized language
72

72

00:02:40,860  -->  00:02:43,650
for sharing structured information about malware.
73

73

00:02:43,650  -->  00:02:45,330
And it is complementary to STIX
74

74

00:02:45,330  -->  00:02:47,640
and TAXII to improve the automated sharing
75

75

00:02:47,640  -->  00:02:49,800
of threat intelligence between people.
76

76

00:02:49,800  -->  00:02:51,270
So if your organization wants to share it
77

77

00:02:51,270  -->  00:02:53,100
with somebody else, putting it in this format
78

78

00:02:53,100  -->  00:02:54,780
is going to be a great thing to do
79

79

00:02:54,780  -->  00:02:56,730
'cause both of you can talk in that same format
80

80

00:02:56,730  -->  00:02:58,920
because it's using STIX and TAXII.
81

81

00:02:58,920  -->  00:03:01,590
Now, another thing we can use is what's called Yara.
82

82

00:03:01,590  -->  00:03:03,960
Now, Yara is a multi-platform program
83

83

00:03:03,960  -->  00:03:06,750
that runs on Windows, Linux, and Mac OS X
84

84

00:03:06,750  -->  00:03:08,820
and allows you to identify, classify
85

85

00:03:08,820  -->  00:03:10,920
and describe malware samples.
86

86

00:03:10,920  -->  00:03:13,770
Now, Yara creates these things called Yara rules.
87

87

00:03:13,770  -->  00:03:15,900
And a Yara rule is a test for matching
88

88

00:03:15,900  -->  00:03:18,840
certain string combinations within a given data source.
89

89

00:03:18,840  -->  00:03:20,940
And that data source can be a binary file,
90

90

00:03:20,940  -->  00:03:24,480
a log file, a packet capture, or even an email.
91

91

00:03:24,480  -->  00:03:26,280
Now what you do is you create this rule
92

92

00:03:26,280  -->  00:03:27,990
that looks something like this.
93

93

00:03:27,990  -->  00:03:29,760
Here is a Yara rule set that was created
94

94

00:03:29,760  -->  00:03:33,210
by somebody back in 2015, and you can see the format here.
95

95

00:03:33,210  -->  00:03:36,210
The rule is called backdoor, and then it has some metadata,
96

96

00:03:36,210  -->  00:03:38,550
a description about what it is, in this case,
97

97

00:03:38,550  -->  00:03:42,150
an auto-generated rule called filebackdoor.exe.
98

98

00:03:42,150  -->  00:03:43,440
It tells you who the author was.
99

99

00:03:43,440  -->  00:03:46,470
In this case, it was an auto-generated rule by the software.
100

100

00:03:46,470  -->  00:03:48,810
The reference was not set, that reference could be
101

101

00:03:48,810  -->  00:03:50,910
something like a Mitre attack number.
102

102

00:03:50,910  -->  00:03:52,170
And then, we have the date it was created
103

103

00:03:52,170  -->  00:03:54,030
and the hash value for this rule.
104

104

00:03:54,030  -->  00:03:56,790
That gives it the integrity to know nothing's been changed.
105

105

00:03:56,790  -->  00:03:58,800
And then, you see all the different strings.
106

106

00:03:58,800  -->  00:04:00,990
These are different strings that it's looking for.
107

107

00:04:00,990  -->  00:04:03,630
Based on these strings, these are the things that it found
108

108

00:04:03,630  -->  00:04:06,150
and it's going to use those to detect other copies
109

109

00:04:06,150  -->  00:04:08,490
of this malware as it goes across the network
110

110

00:04:08,490  -->  00:04:10,410
and as it goes through that data set.
111

111

00:04:10,410  -->  00:04:12,510
This is how you generate a rule.
112

112

00:04:12,510  -->  00:04:14,490
Now again, for the exam, you don't have
113

113

00:04:14,490  -->  00:04:16,140
to write your own Yara rules.
114

114

00:04:16,140  -->  00:04:17,760
I'm just showing this to you because this is
115

115

00:04:17,760  -->  00:04:19,680
something you will use in the real world
116

116

00:04:19,680  -->  00:04:21,390
when you do your threat hunting.
117

117

00:04:21,390  -->  00:04:22,890
I have a lot of friends who still work
118

118

00:04:22,890  -->  00:04:25,380
in the incident response and threat hunting world
119

119

00:04:25,380  -->  00:04:27,120
and they use Yara a lot.
120

120

00:04:27,120  -->  00:04:28,650
By creating these rules, they're able
121

121

00:04:28,650  -->  00:04:30,180
to search for basically that needle
122

122

00:04:30,180  -->  00:04:32,580
in a haystack of what they're looking for.
123

123

00:04:32,580  -->  00:04:35,520
Most often, they'll set these up against a packet capture
124

124

00:04:35,520  -->  00:04:37,320
because they'll have a network sniffer set up
125

125

00:04:37,320  -->  00:04:39,090
like Security Onion, they'll be grabbing
126

126

00:04:39,090  -->  00:04:41,340
all that data off the network and running it
127

127

00:04:41,340  -->  00:04:43,320
through Yara to see if they're going to get
128

128

00:04:43,320  -->  00:04:45,240
any hits on what they're looking for.
129

129

00:04:45,240  -->  00:04:46,560
Particularly a piece of malware
130

130

00:04:46,560  -->  00:04:48,360
to verify an infection has occurred.
