1
00:00:06,480 --> 00:00:08,220
- Welcome to Lesson 22:

2
00:00:08,220 --> 00:00:09,150
Given a Scenario,

3
00:00:09,150 --> 00:00:12,300
Use Data Sources to
Support an Investigation.

4
00:00:12,300 --> 00:00:14,550
In this Lesson 22.1,

5
00:00:14,550 --> 00:00:18,750
we're going to focus in on
the particular data sources.

6
00:00:18,750 --> 00:00:20,160
Now, incident investigation

7
00:00:20,160 --> 00:00:23,520
often requires analysis
of several data sources

8
00:00:23,520 --> 00:00:26,190
in order to draw defensible conclusion,

9
00:00:26,190 --> 00:00:28,860
and even before that, to
even just try to figure out

10
00:00:28,860 --> 00:00:31,173
what's going on, what happened.

11
00:00:32,220 --> 00:00:34,350
And we can use vulnerability scan output

12
00:00:34,350 --> 00:00:37,640
to identify weaknesses and
potential attack vectors.

13
00:00:37,640 --> 00:00:40,260
We can use log files,
which you know I love,

14
00:00:40,260 --> 00:00:42,030
for device, application,

15
00:00:42,030 --> 00:00:45,480
and user specific
activity and/or anomalies.

16
00:00:45,480 --> 00:00:49,200
We can use SIEM dashboards
for broad overview,

17
00:00:49,200 --> 00:00:52,530
for trend analysis, for
alerts, and correlation.

18
00:00:52,530 --> 00:00:55,350
We can use metadata
for supporting details,

19
00:00:55,350 --> 00:00:58,683
and we can use packet
capture for network traffic.

20
00:01:00,240 --> 00:01:01,170
And just as a refresher,

21
00:01:01,170 --> 00:01:03,870
we've already talked about
doing vulnerability scans,

22
00:01:03,870 --> 00:01:05,820
but there are different
types of scans, right?

23
00:01:05,820 --> 00:01:07,890
We have network scans, host scans,

24
00:01:07,890 --> 00:01:12,330
wireless scans, application
scans, even database scans.

25
00:01:12,330 --> 00:01:14,370
A network scan can identify

26
00:01:14,370 --> 00:01:18,660
possible network security attack
points and vulnerabilities.

27
00:01:18,660 --> 00:01:20,610
Our host-based scan gives us visibility

28
00:01:20,610 --> 00:01:22,757
into local host vulnerabilities

29
00:01:22,757 --> 00:01:27,060
as well as configuration
settings and patch status.

30
00:01:27,060 --> 00:01:29,100
We can use a wireless vulnerability scan

31
00:01:29,100 --> 00:01:31,560
to identify rogue access points,

32
00:01:31,560 --> 00:01:35,373
or SSID broadcasts, or
the use of weak protocols.

33
00:01:36,297 --> 00:01:38,910
We can use application vulnerability scans

34
00:01:38,910 --> 00:01:42,570
to detect software vulnerabilities
and configuration issues,

35
00:01:42,570 --> 00:01:45,180
including input and output validation.

36
00:01:45,180 --> 00:01:48,450
And we can even do vulnerability
scanning on a database

37
00:01:48,450 --> 00:01:50,670
to identify weak authentication

38
00:01:50,670 --> 00:01:53,913
and security design and
configuration issues.

39
00:01:56,610 --> 00:01:58,020
And then there's log data, right?

40
00:01:58,020 --> 00:01:59,850
Log data is so useful.

41
00:01:59,850 --> 00:02:02,310
It's one of the best
data sources there is.

42
00:02:02,310 --> 00:02:05,340
So let's look at what we can
get from our operating system,

43
00:02:05,340 --> 00:02:08,700
our service and application
logs, our network device logs,

44
00:02:08,700 --> 00:02:11,553
our NetFlow logs, even our DNS logs.

45
00:02:12,630 --> 00:02:16,110
So our logs from operating
systems, authentication servers,

46
00:02:16,110 --> 00:02:18,000
services, and applications

47
00:02:18,000 --> 00:02:21,570
can really be used to identify
which accounts were accessed

48
00:02:21,570 --> 00:02:24,153
and what actions were performed.

49
00:02:25,369 --> 00:02:27,240
Our network device logs

50
00:02:27,240 --> 00:02:30,930
from devices such as
firewalls and IDS/IPSs,

51
00:02:30,930 --> 00:02:34,410
can be used to identify
ingress and egress access,

52
00:02:34,410 --> 00:02:36,630
connections to malware downloads,

53
00:02:36,630 --> 00:02:39,750
command and control
adversaries, that's our CNC,

54
00:02:39,750 --> 00:02:43,203
data exfiltration, and event correlation.

55
00:02:44,280 --> 00:02:47,777
We can use our NetFlows or
our network flow information

56
00:02:47,777 --> 00:02:52,560
to find anomalous network
activity caused by malware,

57
00:02:52,560 --> 00:02:55,653
data exfiltration, and
other malicious acts.

58
00:02:56,490 --> 00:02:58,530
And then DNS events can be collected

59
00:02:58,530 --> 00:03:02,130
to include dynamic
updates, zone transfers,

60
00:03:02,130 --> 00:03:03,453
resolution queries.

61
00:03:03,453 --> 00:03:05,460
Now, this information can be really useful

62
00:03:05,460 --> 00:03:08,340
for identifying a DNS-related attack,

63
00:03:08,340 --> 00:03:10,623
such as DDoS or poisoning.

64
00:03:11,700 --> 00:03:12,533
I would also say

65
00:03:12,533 --> 00:03:15,900
going back to operating system
service and application,

66
00:03:15,900 --> 00:03:18,210
we wanna think about
things like browser logs

67
00:03:18,210 --> 00:03:19,350
and browser history

68
00:03:19,350 --> 00:03:23,853
to be able to create complete
timelines of user activity.

69
00:03:26,109 --> 00:03:29,190
Now, maybe you haven't had much
experience working with logs

70
00:03:29,190 --> 00:03:31,770
and you really wanna get
some hands-on experience.

71
00:03:31,770 --> 00:03:35,610
There is a a free open-source
log collection tool

72
00:03:35,610 --> 00:03:37,650
that you could use in your home lab.

73
00:03:37,650 --> 00:03:40,530
It's called the NXLog Community Edition.

74
00:03:40,530 --> 00:03:43,680
Again, free open-source
log collection tool.

75
00:03:43,680 --> 00:03:44,940
It's multi-platform,

76
00:03:44,940 --> 00:03:48,930
so it works on Windows and on GNU/Linux.

77
00:03:48,930 --> 00:03:50,940
It's got a really light footprint.

78
00:03:50,940 --> 00:03:54,000
It collects data from
most common log sources,

79
00:03:54,000 --> 00:03:55,890
and it has very structured logging.

80
00:03:55,890 --> 00:03:58,650
So in addition to full syslog capability,

81
00:03:58,650 --> 00:04:03,650
it can also parse and generate
CSV, a W3C file, a GELF file,

82
00:04:05,280 --> 00:04:09,240
a JASON, XML, or KVP formats,

83
00:04:09,240 --> 00:04:13,190
and it has its own binary
data transport format.

84
00:04:13,190 --> 00:04:14,610
So if you wanna download it,

85
00:04:14,610 --> 00:04:16,050
take a look at it, work with it,

86
00:04:16,050 --> 00:04:16,883
you just go out

87
00:04:16,883 --> 00:04:21,590
to
nxlog.co/products/nxlog-community-edition.

88
00:04:25,050 --> 00:04:26,370
Now, another data source

89
00:04:26,370 --> 00:04:29,760
is going to come from our log
analysis and response tools.

90
00:04:29,760 --> 00:04:31,200
We've talked about all of these already.

91
00:04:31,200 --> 00:04:34,530
So a quick refresher, our SIEM, or SIEM,

92
00:04:34,530 --> 00:04:37,020
which is our Security
Information Event Management,

93
00:04:37,020 --> 00:04:40,200
being our automation tool
for real-time data capture,

94
00:04:40,200 --> 00:04:42,840
event correlation,
analysis, and reporting.

95
00:04:42,840 --> 00:04:45,030
Our Threat Intelligence Platforms.

96
00:04:45,030 --> 00:04:48,000
Our User and Entity Behavior Analytics.

97
00:04:48,000 --> 00:04:50,010
Again, another automation tool

98
00:04:50,010 --> 00:04:52,650
that models the behavior
of humans and machines

99
00:04:52,650 --> 00:04:55,800
to identify normal and abnormal behavior.

100
00:04:55,800 --> 00:04:56,850
And then SOAR,

101
00:04:56,850 --> 00:05:00,000
our Security, Orchestration,
Automation, and Response

102
00:05:00,000 --> 00:05:02,040
being our automated response tool

103
00:05:02,040 --> 00:05:04,470
that responds to alerts, triages the data,

104
00:05:04,470 --> 00:05:06,060
and takes remediation steps,

105
00:05:06,060 --> 00:05:07,800
but as part of that whole process,

106
00:05:07,800 --> 00:05:10,893
is a really valuable data source
for what it's discovering.

107
00:05:12,270 --> 00:05:13,980
And then we have metadata.

108
00:05:13,980 --> 00:05:16,140
Metadata is just data about data.

109
00:05:16,140 --> 00:05:18,930
It's machine-readable and it's searchable.

110
00:05:18,930 --> 00:05:22,830
So example, the content
of a photo is the data,

111
00:05:22,830 --> 00:05:24,510
what you see in the picture,

112
00:05:24,510 --> 00:05:26,760
but where the picture was taken,

113
00:05:26,760 --> 00:05:28,830
the date, the time, the direction,

114
00:05:28,830 --> 00:05:31,830
the camera setting, the
editing, and the copyright,

115
00:05:31,830 --> 00:05:35,340
those are all metadata
extracts, data about the data.

116
00:05:35,340 --> 00:05:36,420
And let me give you an example.

117
00:05:36,420 --> 00:05:40,050
So there's a picture of me,
and there is all the metadata.

118
00:05:40,050 --> 00:05:43,503
So that's all the metadata
about that particular picture.

119
00:05:44,400 --> 00:05:46,230
Now, there are other types of metadata

120
00:05:46,230 --> 00:05:49,246
that are more useful than pictures of me.

121
00:05:49,246 --> 00:05:52,800
We have file system metadata,
we have application metadata,

122
00:05:52,800 --> 00:05:56,370
we have pseudo metadata,
and we have email metadata.

123
00:05:56,370 --> 00:05:59,610
The file system metadata is
created by the operating system

124
00:05:59,610 --> 00:06:03,420
and it includes file attributes
and security permissions.

125
00:06:03,420 --> 00:06:06,540
So for example, file size,
location, creation date,

126
00:06:06,540 --> 00:06:09,600
date of last access, date of last write,

127
00:06:09,600 --> 00:06:13,620
whether a file is hidden
or compressed or archived.

128
00:06:13,620 --> 00:06:16,830
Application metadata is created
by specific applications

129
00:06:16,830 --> 00:06:19,950
and include user and file
activity information,

130
00:06:19,950 --> 00:06:23,100
so things like title,
author, subject, keywords,

131
00:06:23,100 --> 00:06:24,810
creation and modification date,

132
00:06:24,810 --> 00:06:26,763
time and use, and revision history.

133
00:06:27,810 --> 00:06:31,200
Pseudo metadata is kind called pseudo

134
00:06:31,200 --> 00:06:33,210
'cause it's not really metadata.

135
00:06:33,210 --> 00:06:36,060
It was information that
was created by the user

136
00:06:36,060 --> 00:06:38,760
that's hidden or embedded in the document.

137
00:06:38,760 --> 00:06:42,330
So that's things like comments,
track changes, formulas,

138
00:06:42,330 --> 00:06:47,130
speaker notes, embedded graphics,
and audio and video files.

139
00:06:47,130 --> 00:06:49,440
And then lastly, email metadata,

140
00:06:49,440 --> 00:06:52,050
which is created by
our email applications,

141
00:06:52,050 --> 00:06:54,090
generally embedded in the message,

142
00:06:54,090 --> 00:06:55,350
things like the route,

143
00:06:55,350 --> 00:06:59,583
the extracted frequency of
contact, and the IP geolocation.

144
00:07:01,127 --> 00:07:05,010
Now, another really useful
tool is packet capture.

145
00:07:05,010 --> 00:07:07,020
Packet capture is the process

146
00:07:07,020 --> 00:07:11,670
of intercepting and logging
traffic for analysis.

147
00:07:11,670 --> 00:07:14,430
A protocol analyzer, also
referred to as a sniffer,

148
00:07:14,430 --> 00:07:15,630
is a tool that we can use

149
00:07:15,630 --> 00:07:18,150
to capture and analyze network packets.

150
00:07:18,150 --> 00:07:20,940
Now, it can also be used
to analyze network packets

151
00:07:20,940 --> 00:07:24,930
that have been captured by
other devices or other programs.

152
00:07:24,930 --> 00:07:27,360
A port mirror captures network traffic

153
00:07:27,360 --> 00:07:29,520
on one or several ports of a switch

154
00:07:29,520 --> 00:07:31,620
and then forwards a copy of the traffic

155
00:07:31,620 --> 00:07:33,330
to an analysis device.

156
00:07:33,330 --> 00:07:36,240
And a network TAP, which
we did talk about earlier,

157
00:07:36,240 --> 00:07:37,980
is a dedicated hardware device

158
00:07:37,980 --> 00:07:40,440
that's inserted between network devices

159
00:07:40,440 --> 00:07:42,150
like a switch and router

160
00:07:42,150 --> 00:07:44,160
and makes copies of the traffic,

161
00:07:44,160 --> 00:07:47,640
and again, forwards to an analysis device.

162
00:07:47,640 --> 00:07:50,430
There are multiple packet capture modes.

163
00:07:50,430 --> 00:07:53,100
First two, normal and promiscuous.

164
00:07:53,100 --> 00:07:55,710
Normal is that the network interface card

165
00:07:55,710 --> 00:07:58,830
only captures frames
intended for the interface,

166
00:07:58,830 --> 00:08:01,230
and it does that by
filtering by MAC address.

167
00:08:01,230 --> 00:08:04,140
So only if it was intended
for that MAC interface,

168
00:08:04,140 --> 00:08:05,250
it says, "Okay, I'll capture it.

169
00:08:05,250 --> 00:08:07,410
Everything else, I'm gonna ignore,"

170
00:08:07,410 --> 00:08:10,200
where promiscuous says
the network interface card

171
00:08:10,200 --> 00:08:13,530
is instructed to accept
every frame it captures,

172
00:08:13,530 --> 00:08:15,750
even if it's not the intended recipient.

173
00:08:15,750 --> 00:08:18,900
So normal is very myopic.

174
00:08:18,900 --> 00:08:21,660
I'm only capturing what's
intended for that interface.

175
00:08:21,660 --> 00:08:24,090
Promiscuous says, "I'm gonna
capture everything I can hear,

176
00:08:24,090 --> 00:08:25,490
everything I can listen to."

177
00:08:26,400 --> 00:08:28,020
And then our two other modes

178
00:08:28,020 --> 00:08:29,760
are unfiltered and filtered.

179
00:08:29,760 --> 00:08:33,810
Unfiltered, we are capturing
regardless of data elements.

180
00:08:33,810 --> 00:08:35,460
Filtered says our packet capture

181
00:08:35,460 --> 00:08:38,253
is limited to specific data elements.

182
00:08:39,360 --> 00:08:42,390
Packet captures could
be incredibly useful.

183
00:08:42,390 --> 00:08:45,000
You just see a quick
little illustration here

184
00:08:45,000 --> 00:08:46,350
of doing a packet capture.

185
00:08:46,350 --> 00:08:47,400
I can see all the packets,

186
00:08:47,400 --> 00:08:51,600
I can see the source address,
the destination address.

187
00:08:51,600 --> 00:08:55,290
I can see information about
the the port and the protocol.

188
00:08:55,290 --> 00:08:57,240
And then if you go all the
way down to the bottom,

189
00:08:57,240 --> 00:08:59,160
you can actually see what's in the packet.

190
00:08:59,160 --> 00:09:00,870
Now, in this case, we're not seeing much,

191
00:09:00,870 --> 00:09:02,160
but if it's a clear text packet,

192
00:09:02,160 --> 00:09:04,320
we would see exactly what's in there.

193
00:09:04,320 --> 00:09:08,070
In between, we're seeing
things about the routing,

194
00:09:08,070 --> 00:09:10,020
about the IP version,

195
00:09:10,020 --> 00:09:12,660
and other information
about the packet itself.

196
00:09:12,660 --> 00:09:14,910
So really, really good data source,

197
00:09:14,910 --> 00:09:18,150
packet capture and analysis, right?

198
00:09:18,150 --> 00:09:21,150
And that brings us to a
three-second challenge.

199
00:09:21,150 --> 00:09:23,940
Five challenge questions,
three seconds each.

200
00:09:23,940 --> 00:09:25,320
The type of vulnerability scan

201
00:09:25,320 --> 00:09:27,753
that can identify rogue access points.

202
00:09:28,650 --> 00:09:30,660
One, two, three.

203
00:09:30,660 --> 00:09:33,510
It's gonna be a wireless
vulnerability scan.

204
00:09:33,510 --> 00:09:34,740
How about number two?

205
00:09:34,740 --> 00:09:36,240
Data about data.

206
00:09:36,240 --> 00:09:37,410
I know you're gonna get this one.

207
00:09:37,410 --> 00:09:40,620
Data about data is, one, two, three.

208
00:09:40,620 --> 00:09:42,330
Metadata.

209
00:09:42,330 --> 00:09:43,560
Number three,

210
00:09:43,560 --> 00:09:46,920
tool used to capture and
analyze network packets.

211
00:09:46,920 --> 00:09:48,390
We just looked at it.

212
00:09:48,390 --> 00:09:50,880
One, two, three.

213
00:09:50,880 --> 00:09:53,463
That's gonna be a protocol
analyzer or a sniffer.

214
00:09:55,440 --> 00:09:59,640
Number four, an automation tool
for real-time data capture,

215
00:09:59,640 --> 00:10:03,183
event correlation,
analysis, and reporting.

216
00:10:04,320 --> 00:10:06,033
One, two, three.

217
00:10:07,050 --> 00:10:08,550
And that's gonna be your SIEM.

218
00:10:10,170 --> 00:10:12,870
And lastly, number five,
packet capture mode

219
00:10:12,870 --> 00:10:15,510
that instructs a network
interface card, or the NIC,

220
00:10:15,510 --> 00:10:17,970
to accept any frame it captures,

221
00:10:17,970 --> 00:10:19,923
even if not the intended recipient.

222
00:10:21,360 --> 00:10:23,400
One, two, three.

223
00:10:23,400 --> 00:10:25,440
That's gonna be promiscuous.

224
00:10:25,440 --> 00:10:27,510
All right, let's do a security-in-action,

225
00:10:27,510 --> 00:10:29,793
and this one's about a
suspicious phone call.

226
00:10:30,840 --> 00:10:33,780
One of your colleagues overheard
a suspicious phone call

227
00:10:33,780 --> 00:10:36,102
leading you to suspect that an insider

228
00:10:36,102 --> 00:10:39,240
has been collaborating
with an external adversary

229
00:10:39,240 --> 00:10:41,940
who's attempting to exfiltrate data.

230
00:10:41,940 --> 00:10:46,470
Your company does not record
calls or maintain a transcript.

231
00:10:46,470 --> 00:10:48,360
So is this a dead end

232
00:10:48,360 --> 00:10:51,600
or is there potentially
any useful information

233
00:10:51,600 --> 00:10:54,840
that you could use for
investigative purposes?

234
00:10:54,840 --> 00:10:56,340
So again, our recap.

235
00:10:56,340 --> 00:10:58,140
Now, one of your colleagues overheard

236
00:10:58,140 --> 00:11:00,330
the suspicious phone call,

237
00:11:00,330 --> 00:11:03,090
and that leads you to suspect
that we have an insider

238
00:11:03,090 --> 00:11:05,820
who's been collaborating
with an external adversary

239
00:11:05,820 --> 00:11:08,730
who's attempting to exfiltrate data.

240
00:11:08,730 --> 00:11:10,080
But you don't record the calls

241
00:11:10,080 --> 00:11:12,660
and there's no transcript for the calls.

242
00:11:12,660 --> 00:11:14,130
Is there anything,

243
00:11:14,130 --> 00:11:17,340
any information at all that
would be potentially useful

244
00:11:17,340 --> 00:11:19,740
that you could use for
an investigative purpose?

245
00:11:21,480 --> 00:11:23,943
You get a little hint
already about metadata,

246
00:11:25,290 --> 00:11:27,360
so go ahead and think
about that, if you want.

247
00:11:27,360 --> 00:11:28,710
Put me on pause, come on back,

248
00:11:28,710 --> 00:11:30,260
and tell me what you could use.

249
00:11:31,860 --> 00:11:36,270
Remember, metadata is data
about data, and in this case,

250
00:11:36,270 --> 00:11:40,200
we probably can find some data
about the phone call itself.

251
00:11:40,200 --> 00:11:43,140
Now, most phone systems
maintain call detail records

252
00:11:43,140 --> 00:11:47,220
known as CDRs, which contain
the following metadata.

253
00:11:47,220 --> 00:11:49,980
When the call took place, date, and time,

254
00:11:49,980 --> 00:11:53,010
how long the call lasted in minutes,

255
00:11:53,010 --> 00:11:57,090
who called whom, so source
and destination phone numbers,

256
00:11:57,090 --> 00:11:58,440
and what kind of call was made?

257
00:11:58,440 --> 00:12:01,443
Was it inbound, outbound, or toll-free?

258
00:12:02,520 --> 00:12:05,940
Now, this information could prove useful

259
00:12:05,940 --> 00:12:09,480
especially when correlated
with other activity.

260
00:12:09,480 --> 00:12:12,930
So don't discount the usefulness
about data about data,

261
00:12:12,930 --> 00:12:15,720
which you and I know as metadata.

262
00:12:15,720 --> 00:12:18,240
And that, my friends,
is security-in-action.

263
00:12:18,240 --> 00:12:21,180
There's your word cloud,
probably a lot of new terms here.

264
00:12:21,180 --> 00:12:22,650
Again, make sure that you're comfortable

265
00:12:22,650 --> 00:12:24,360
and confident in all of them.

266
00:12:24,360 --> 00:12:25,530
And then when you're ready,

267
00:12:25,530 --> 00:12:27,600
well, we only have one
lesson in this lesson,

268
00:12:27,600 --> 00:12:30,100
so come on over and we'll
do a five-question quiz.
