Live Incident Response with Velociraptor

  Рет қаралды 24,239

Recon InfoSec

Recon InfoSec

2 жыл бұрын

Recon InfoSec CTO, Eric Capuano, performs a hands-on demonstration of a live incident response against a compromised environment using nothing but the free and open source Velociraptor agent. Gain exposure to this incredibly powerful tool and many of its most common use-cases for IR, including use of notebooks for analysis and enrichment.
Notebook examples can be found here: gist.github.com/ecapuano/daee...

Пікірлер: 31
@velocidexenterprises8702
@velocidexenterprises8702 2 жыл бұрын
Really excellent talk with so much information. Great to see Velociraptor wielded by such a skillful defender! A must watch presentation for any Blue Teamer or defender out there!
@rpt3066
@rpt3066 Жыл бұрын
Dont know what more motivation is needed to use this awesome tool - for FREE! Thank you Eric C for sharing invaluable experience for FREE & Mike C for sharing this tech for FREE 👑🙌
@edwardwhite8253
@edwardwhite8253 Жыл бұрын
Absolutely incredible and in-depth demo! The pacing, the contents are all great! Bravo Eric!
@gerarddunphy
@gerarddunphy 3 ай бұрын
Incredible demo showing how Velociraptor truly takes IR capabilities to a whole other level! This is a game changer! The only thing missing was did the threat actor actually exfil those plans to the death star :) Thank you for this great insight! I have a new lab to build post haste!
@KenPryor
@KenPryor Жыл бұрын
This was amazing. I just started learning about Velociraptor recently and have much to learn. This video was extremely helpful.
@domiflichi
@domiflichi Жыл бұрын
Wow! Incredible video, thank you!
@rolyperez8695
@rolyperez8695 Жыл бұрын
I heard about this at the NCFI and started using it. Cederpelta was the one i used to use. Greetings from LaredoTx.
@Impact_Creativity
@Impact_Creativity Жыл бұрын
what an amazing video! thanks for all the info, really usefull!
@getoutmore
@getoutmore Жыл бұрын
This was so awesome!!! I could have watched this for hours. Motivated me so much to get my hands on this. Do you have more stuff Like this? Im hungry to learn! Thanks you for the Video
@dananderson6992
@dananderson6992 2 жыл бұрын
Well done live hunt. thanks for sharing.
@WarThunderista
@WarThunderista 4 ай бұрын
Amazing stuff :D
@shamshoque2546
@shamshoque2546 2 ай бұрын
Really great structured information. Thanks. How to integrate hyabusa in hunt profile????
@frzen
@frzen Жыл бұрын
Great talk thanks
@PrinterJamOnToast
@PrinterJamOnToast 2 жыл бұрын
This is so cool, I hope to work for a company that uses this some day.
@TurboRetard
@TurboRetard Жыл бұрын
Im deploying it where I work, glad the sysadmin is open minded to give me free reign on cyber security
@mitchimpey1726
@mitchimpey1726 2 жыл бұрын
Great Demo Eric. Excellent example and a great presentation. Thanks, appreciated !
@EricCapuano
@EricCapuano 2 жыл бұрын
Thank you! Glad you enjoyed it.
@civicnox
@civicnox Жыл бұрын
Good video
@MuhammadImran-xu4fw
@MuhammadImran-xu4fw Жыл бұрын
Awesome, impressed :) How about if the adversary does the cleanup while doing lateral movement?
@holeraholera
@holeraholera 10 ай бұрын
Great stuff! Thank you. Have you thought about releasing the collected data so that we can play with it in our own velociraptor server?
@aliakbar307
@aliakbar307 9 ай бұрын
Hi, thanks for the great video. I have a question. How the shellcode is decrypted and which component will decrypt it?
@sirisiri2048
@sirisiri2048 Жыл бұрын
This is awesome Really in-depth analysis Just had one question where can I find this data or the malware ? Is their a repository you have used for this ?
@EricCapuano
@EricCapuano Жыл бұрын
Sadly this was run inside of our live training range so the data is not available otherwise. I’ll see about trying to capture and release the data in the future!
@clomok
@clomok 2 жыл бұрын
Wow, such a cool talk. Does velociraptor have to be implemented with a single network? Is there a way to have velociraptor clients from different networks communicate with a single server?
@EricCapuano
@EricCapuano 2 жыл бұрын
Absolutely. The server doesn’t know/care what network the agent checks in from. You can host the server in the cloud and have hosts on many different networks checking in.
@clomok
@clomok 2 жыл бұрын
@@EricCapuano that sounds like a wonderful setup. Can you imagine a situation where velociraptor replaces a MSP's end point detection and aggregates all clients to a universal dashboard?
@user-zi9mg6mf5v
@user-zi9mg6mf5v Жыл бұрын
How did you prepared the demo environment with more than 60 workstations? is that a simulator tool? awsome talk by the way and thank you!
@EricCapuano
@EricCapuano Жыл бұрын
I used a large virtual environment we've built for other trainings like OpenSOC & our Network Defense Range.
@EIDEID99
@EIDEID99 2 жыл бұрын
wait @23:39 , if a user login , will 4624 stored in the AD on in his/her PC.
@EricCapuano
@EricCapuano 2 жыл бұрын
A 4624 (successful logon) gets generated on the system being logged onto to... The authentication event (4768) shows up on the domain controller.
@ChristopherReevesNZ
@ChristopherReevesNZ Жыл бұрын
Issues that I see with this: 1. This seems to rely on AD GPO (or some sort of deployment tool), these days people are also using Macs and *inux so you might not get all the coverage. Secondly on this point is if GPO is disabled at the AD / workstation level then this too is rendered useless. 2. I personally don't know of one analyst that knows VQL let alone SQL 3. The UI is 🤮 4. Tools like Crowdstrike kinda do this using ML/AI without all the manual stuff 5. Dropping session seems quite POCCY to me 6. A lot of this stuff can be done using windows remote management in a scripted way
Starting with Velociraptor Incident Response
48:32
DFIRScience
Рет қаралды 18 М.
Investigating WMI Attacks
1:00:43
SANS Digital Forensics and Incident Response
Рет қаралды 26 М.
Final muy increíble 😱
00:46
Juan De Dios Pantoja 2
Рет қаралды 51 МЛН
Smart Sigma Kid #funny #sigma #comedy
00:25
CRAZY GREAPA
Рет қаралды 16 МЛН
THEY made a RAINBOW M&M 🤩😳 LeoNata family #shorts
00:49
LeoNata Family
Рет қаралды 30 МЛН
OMG🤪 #tiktok #shorts #potapova_blog
00:50
Potapova_blog
Рет қаралды 18 МЛН
Rapid Windows Endpoint Investigations with Velociraptor & KAPE w/ Patterson
1:18:13
Black Hills Information Security
Рет қаралды 4,4 М.
License to Kill: Malware Hunting with the Sysinternals Tools
1:18:10
Mark Russinovich
Рет қаралды 75 М.
Intro to Velociraptor or How to eliminate a red team in under 30min
14:56
Hunt for Hackers with Velociraptor
13:51
John Hammond
Рет қаралды 93 М.
Cyber Security Incident Response - How SOC Responds, See LIVE
25:55
Threat Hunting with Velociraptor w/ Eric Capuano & Whitney Champion
58:40
Antisyphon Training
Рет қаралды 2 М.
SANS DFIR Webcast - Incident Response Event Log Analysis
48:50
SANS Digital Forensics and Incident Response
Рет қаралды 80 М.
Mass Digital Forensics & Incident Response with Velociraptor
34:54
John Hammond
Рет қаралды 14 М.
Complete Beginner Guide to Velociraptor | Digital Forensics | TryHackMe
44:15
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00
Корнеич
Рет қаралды 3,7 МЛН
Спутниковый телефон #обзор #товары
0:35
Product show
Рет қаралды 2,2 МЛН
YOTAPHONE 2 - СПУСТЯ 10 ЛЕТ
15:13
ЗЕ МАККЕРС
Рет қаралды 180 М.
Klavye İle Trafik Işığını Yönetmek #shorts
0:18
Osman Kabadayı
Рет қаралды 217 М.