1
00:00:06,540 --> 00:00:07,920
- So welcome to lesson eight,

2
00:00:07,920 --> 00:00:12,180
given a scenario, analyze
indicators of malicious activity.

3
00:00:12,180 --> 00:00:14,250
In our first lesson 8.1,

4
00:00:14,250 --> 00:00:16,200
we're gonna talk specifically about,

5
00:00:16,200 --> 00:00:19,293
what is an indicator
of malicious activity?

6
00:00:20,310 --> 00:00:22,680
Now, there are two primary
types of indicators

7
00:00:22,680 --> 00:00:24,810
that are used to help identify

8
00:00:24,810 --> 00:00:27,720
and detect cybersecurity threats.

9
00:00:27,720 --> 00:00:30,600
We have Indicators of
Attacks, known as IoAs,

10
00:00:30,600 --> 00:00:33,810
and Indicators of
Compromise known as IoCs.

11
00:00:33,810 --> 00:00:38,220
Now, IoAs, Indicators of
Attack, are behaviors or actions

12
00:00:38,220 --> 00:00:41,550
that suggest an attack
is happening right now

13
00:00:41,550 --> 00:00:43,290
or is about to happen.

14
00:00:43,290 --> 00:00:45,843
Now IoAs are proactive.

15
00:00:46,710 --> 00:00:49,110
Indicators of Compromise, IoCs,

16
00:00:49,110 --> 00:00:52,860
are evidence that a system
may have been compromised.

17
00:00:52,860 --> 00:00:54,270
IoCs are reactive.

18
00:00:54,270 --> 00:00:58,023
So we're gonna take a look
at both IoAs and IoCs.

19
00:00:59,607 --> 00:01:02,520
Now, Indicators of Attack
are used to detect threats

20
00:01:02,520 --> 00:01:06,600
before they cause significant
damage or compromise.

21
00:01:06,600 --> 00:01:09,480
That Indicators of Attack in
the aggregate are gonna be

22
00:01:09,480 --> 00:01:11,610
a set of behaviors or actions,

23
00:01:11,610 --> 00:01:13,740
sometimes referred to as the tradecraft,

24
00:01:13,740 --> 00:01:15,300
that are typically observed

25
00:01:15,300 --> 00:01:17,610
during the early stage of an attack

26
00:01:17,610 --> 00:01:19,980
although they could be identified anywhere

27
00:01:19,980 --> 00:01:21,420
throughout the Cyber Kill Chain.

28
00:01:21,420 --> 00:01:24,450
And I'll do the Cyber Kill
Chain with you in just a sec.

29
00:01:24,450 --> 00:01:27,600
Now, these behaviors include
network traffic patterns,

30
00:01:27,600 --> 00:01:30,813
system events, and user activities.

31
00:01:32,190 --> 00:01:34,770
Now, the Cyber Kill Chain
framework was actually developed

32
00:01:34,770 --> 00:01:35,910
by Lockheed Martin,

33
00:01:35,910 --> 00:01:38,880
and it explains how attackers
move through a network

34
00:01:38,880 --> 00:01:42,333
to identify vulnerabilities
that they can exploit.

35
00:01:43,230 --> 00:01:45,660
So it generally starts with
a reconnaissance, right,

36
00:01:45,660 --> 00:01:49,410
learning about the target,
then weaponization.

37
00:01:49,410 --> 00:01:51,120
So they learn about the target.

38
00:01:51,120 --> 00:01:53,400
They determine how
they're going to attack.

39
00:01:53,400 --> 00:01:56,280
So they go through the
weaponization process.

40
00:01:56,280 --> 00:01:58,980
They deliver whatever
the weaponization is.

41
00:01:58,980 --> 00:02:00,510
Maybe it's malware.

42
00:02:00,510 --> 00:02:01,950
Maybe it's injection.

43
00:02:01,950 --> 00:02:05,163
Maybe it is a physical attack.

44
00:02:06,030 --> 00:02:08,580
Then there's the exploitation.

45
00:02:08,580 --> 00:02:10,860
And lastly, the installation.

46
00:02:10,860 --> 00:02:13,950
So the installation of whatever
they had in that network,

47
00:02:13,950 --> 00:02:16,600
if they're putting something
into the network itself.

48
00:02:17,580 --> 00:02:21,750
And then a connection back to
a command and control center,

49
00:02:21,750 --> 00:02:23,970
and then action on objectives.

50
00:02:23,970 --> 00:02:26,520
Now I put a little URL down
on the bottom of the slide.

51
00:02:26,520 --> 00:02:27,420
If you wanna learn more

52
00:02:27,420 --> 00:02:30,330
about the Lockheed
Martin Cyber Kill Chain,

53
00:02:30,330 --> 00:02:32,610
go ahead right through that URL

54
00:02:32,610 --> 00:02:35,460
and you can get lots of
information about how this works.

55
00:02:37,800 --> 00:02:39,960
The common Indicators of Attack include

56
00:02:39,960 --> 00:02:43,050
unusual network traffic, phishing emails,

57
00:02:43,050 --> 00:02:44,850
unusual system events,

58
00:02:44,850 --> 00:02:47,760
or unauthorized software being installed.

59
00:02:47,760 --> 00:02:51,510
So unusual network traffic
and/or geographic irregularities,

60
00:02:51,510 --> 00:02:53,100
like access from places

61
00:02:53,100 --> 00:02:56,580
that normally don't come to
your network could be indicative

62
00:02:56,580 --> 00:03:00,150
of communications with a C&C,
a command and control server,

63
00:03:00,150 --> 00:03:01,980
or indicative of data exfiltration

64
00:03:01,980 --> 00:03:03,753
or reconnaissance activity.

65
00:03:04,590 --> 00:03:07,260
Phishing emails are
designed to trick our users

66
00:03:07,260 --> 00:03:08,910
into taking an action, right?

67
00:03:08,910 --> 00:03:11,520
An increase in the volume
of phishing emails could be

68
00:03:11,520 --> 00:03:13,053
an indicator of attack.

69
00:03:13,890 --> 00:03:17,910
Unusual system events
such as errors, warnings,

70
00:03:17,910 --> 00:03:21,900
system crashes, account
lockouts, missing system logs,

71
00:03:21,900 --> 00:03:24,570
any anomalies in admin activity,

72
00:03:24,570 --> 00:03:26,793
all could be indicators of an attack.

73
00:03:27,810 --> 00:03:29,340
And unauthorized software,

74
00:03:29,340 --> 00:03:33,000
meaning the presence of
unauthorized software or files

75
00:03:33,000 --> 00:03:35,430
or unapproved devices on our network,

76
00:03:35,430 --> 00:03:38,040
again, could all be
indicators of an attack,

77
00:03:38,040 --> 00:03:40,983
an attack that is happening
or is about to happen.

78
00:03:42,840 --> 00:03:45,030
Indicators of Compromise are artifacts

79
00:03:45,030 --> 00:03:47,280
about an event that has already happened.

80
00:03:47,280 --> 00:03:50,670
And we use our Indicators
of Compromise to identify,

81
00:03:50,670 --> 00:03:53,103
has there been a security breach?

82
00:03:54,060 --> 00:03:57,060
Now, Indicators of Compromise
rely on known artifacts.

83
00:03:57,060 --> 00:04:00,210
Another way to think about an
artifact is evidence or clues.

84
00:04:00,210 --> 00:04:02,430
Typical artifacts that are left behind

85
00:04:02,430 --> 00:04:05,340
by an attacker include new user accounts,

86
00:04:05,340 --> 00:04:08,970
or file hashes, virus
signatures, malicious files,

87
00:04:08,970 --> 00:04:10,950
command and control connections,

88
00:04:10,950 --> 00:04:14,070
modification of the system
or registry settings,

89
00:04:14,070 --> 00:04:16,440
evidence of data exfiltration,

90
00:04:16,440 --> 00:04:18,963
or patterns of suspicious behavior.

91
00:04:20,880 --> 00:04:24,900
Now, not all IoCs necessarily
indicate a compromise.

92
00:04:24,900 --> 00:04:26,220
So you might have an IoC,

93
00:04:26,220 --> 00:04:29,280
but it doesn't mean that there
definitely was a compromise,

94
00:04:29,280 --> 00:04:31,470
that you need to do validation.

95
00:04:31,470 --> 00:04:34,710
So multiple IoCs may need to be correlated

96
00:04:34,710 --> 00:04:37,440
to confirm a compromise.

97
00:04:37,440 --> 00:04:38,700
It's really important

98
00:04:38,700 --> 00:04:42,180
that we have a strong incident
response plan in place

99
00:04:42,180 --> 00:04:45,120
in our organizations to quickly detect

100
00:04:45,120 --> 00:04:47,940
and respond to Indicators of Attack

101
00:04:47,940 --> 00:04:49,890
and Indicators of Compromise.

102
00:04:49,890 --> 00:04:51,810
And we'll be talking in later lessons

103
00:04:51,810 --> 00:04:55,170
about a strong incident response plan.

104
00:04:55,170 --> 00:04:58,170
And that, my friends, brings
us to three-second challenge,

105
00:04:58,170 --> 00:04:59,880
five challenge questions,
three seconds each.

106
00:04:59,880 --> 00:05:00,980
You know how to do it.

107
00:05:01,830 --> 00:05:03,450
Evidence or clues used to determine

108
00:05:03,450 --> 00:05:06,090
if a compromise has occurred.

109
00:05:06,090 --> 00:05:08,610
One, two, three.

110
00:05:08,610 --> 00:05:10,053
That's gonna be artifacts.

111
00:05:11,070 --> 00:05:12,510
Number two, a remote device

112
00:05:12,510 --> 00:05:14,823
that issues malicious instructions.

113
00:05:15,870 --> 00:05:18,180
One, two, three.

114
00:05:18,180 --> 00:05:21,363
That's gonna be a command
and control server, or a C2.

115
00:05:23,010 --> 00:05:27,210
Number three, gathering
information to use in an attack.

116
00:05:27,210 --> 00:05:28,770
This was the very first thing we saw

117
00:05:28,770 --> 00:05:30,690
in the Cyber Kill Chain.

118
00:05:30,690 --> 00:05:32,640
One, two, three.

119
00:05:32,640 --> 00:05:33,873
That's reconnaissance.

120
00:05:34,950 --> 00:05:38,040
Number four, the stages of an attack

121
00:05:38,040 --> 00:05:40,143
as described by Lockheed Martin.

122
00:05:41,370 --> 00:05:43,710
One, two, three.

123
00:05:43,710 --> 00:05:45,933
That is our Cyber Kill Chain framework.

124
00:05:47,220 --> 00:05:48,870
And lastly, number five,

125
00:05:48,870 --> 00:05:51,273
tricking a user into performing an action.

126
00:05:52,350 --> 00:05:53,883
One, two, three.

127
00:05:55,170 --> 00:05:56,490
That's social engineering.

128
00:05:56,490 --> 00:05:57,720
We did a whole lesson on that.

129
00:05:57,720 --> 00:05:59,120
Hope you got that one right.

130
00:06:00,840 --> 00:06:05,490
All right, let's do a
security-in-action about indicators.

131
00:06:05,490 --> 00:06:06,900
Really short little one here.

132
00:06:06,900 --> 00:06:08,610
You're staffing the Help Desk.

133
00:06:08,610 --> 00:06:10,410
A user calls in to report

134
00:06:10,410 --> 00:06:14,970
that his laptop has been
"acting funny" all day.

135
00:06:14,970 --> 00:06:16,290
That's all they say.

136
00:06:16,290 --> 00:06:19,110
So my question to you is,
how are you gonna respond?

137
00:06:19,110 --> 00:06:20,377
Now, hopefully you don't say,

138
00:06:20,377 --> 00:06:22,290
"Yeah, yeah, right, bye," right?

139
00:06:22,290 --> 00:06:24,000
You take it seriously.

140
00:06:24,000 --> 00:06:25,170
But what are you gonna do?

141
00:06:25,170 --> 00:06:27,030
That's all you've got to go on,

142
00:06:27,030 --> 00:06:30,930
that his laptop has been
acting funny all day.

143
00:06:30,930 --> 00:06:32,340
How are you gonna respond?

144
00:06:32,340 --> 00:06:34,350
Go ahead and put me on
pause, jot down some notes,

145
00:06:34,350 --> 00:06:36,550
come back, and we'll
do a response together.

146
00:06:38,820 --> 00:06:39,653
Well, number one,

147
00:06:39,653 --> 00:06:42,000
you really wanna take
the caller seriously.

148
00:06:42,000 --> 00:06:42,930
Even if it's someone

149
00:06:42,930 --> 00:06:44,850
who's like just normally
a pain in the butt

150
00:06:44,850 --> 00:06:45,683
and you're like,

151
00:06:45,683 --> 00:06:47,130
"Oh God, this person's always calling me,"

152
00:06:47,130 --> 00:06:49,743
you still need to take
the caller seriously.

153
00:06:50,880 --> 00:06:54,330
You wanna work with the caller
to describe acting funny.

154
00:06:54,330 --> 00:06:55,890
What does acting funny mean?

155
00:06:55,890 --> 00:06:58,800
See if you can really get him or her

156
00:06:58,800 --> 00:07:01,023
to be much more detailed.

157
00:07:02,640 --> 00:07:04,950
Now, if warranted, we can
collaborate with the user

158
00:07:04,950 --> 00:07:06,450
to create an activity trail

159
00:07:06,450 --> 00:07:09,000
that includes suspicious emails or calls,

160
00:07:09,000 --> 00:07:10,920
maybe any links they've clicked on,

161
00:07:10,920 --> 00:07:14,070
any unexpected attachments
that they opened,

162
00:07:14,070 --> 00:07:15,843
or any web browsing they did.

163
00:07:16,710 --> 00:07:18,630
And then we wanna investigate

164
00:07:18,630 --> 00:07:20,370
any corresponding artifacts right?

165
00:07:20,370 --> 00:07:23,100
Firewall logs, maybe the
local browser history,

166
00:07:23,100 --> 00:07:26,193
or DLP, data loss prevention activity.

167
00:07:28,260 --> 00:07:30,270
And if appropriate, right,

168
00:07:30,270 --> 00:07:31,380
we're going to escalate

169
00:07:31,380 --> 00:07:34,440
and follow our incident
response protocols.

170
00:07:34,440 --> 00:07:36,390
But when they call, just acting funny,

171
00:07:36,390 --> 00:07:38,100
we don't know what that means, right?

172
00:07:38,100 --> 00:07:39,600
Is that an indicator of attack?

173
00:07:39,600 --> 00:07:41,850
Is that an indicator of compromise?

174
00:07:41,850 --> 00:07:43,560
Is it maybe nothing?

175
00:07:43,560 --> 00:07:46,200
But we still need to take
the caller seriously?

176
00:07:46,200 --> 00:07:48,540
We need to try to define what happened

177
00:07:48,540 --> 00:07:51,690
a little bit more precisely, right?

178
00:07:51,690 --> 00:07:54,540
Then we need to perhaps
looking for those artifacts

179
00:07:54,540 --> 00:07:57,690
and investigating them
and trying to determine

180
00:07:57,690 --> 00:07:58,950
what might have happened.

181
00:07:58,950 --> 00:08:00,180
And then if it's warranted,

182
00:08:00,180 --> 00:08:03,900
we wanna initiate our
incident response protocols.

183
00:08:03,900 --> 00:08:06,483
Doing that, definitely security-in-action.

184
00:08:08,580 --> 00:08:10,260
That takes us to our word cloud.

185
00:08:10,260 --> 00:08:11,610
Not much there, right?

186
00:08:11,610 --> 00:08:14,100
I know you can do all
of these pretty easily.

187
00:08:14,100 --> 00:08:16,323
So let's move right on to our next lesson.
