PIPEDREAM - Most Flexible & Capable ICS Malware To Date

  Рет қаралды 9,263

S4 Events

S4 Events

Күн бұрын

Rob Lee, founder and CEO of Dragos, gives the opening keynote of S4x22 Day 2 on the ICS malware they call PIPEDREAM. The first third of the keynote focuses on what this means for asset owners and how they should react. Who should prioritize threat hunting ("you don't get to vote if you are a target")?
The remainder of the talk is on the malware itself and a bit on mitigations. The PLC Proxy capabilities is particularly interesting. Even if you have heard about INCONTROLLER/PIPEDREAM before you will find this a worthwhile watch.

Пікірлер: 11
@believe_it712
@believe_it712 2 жыл бұрын
Haha love the final part message to the adversaries
@tonio071273
@tonio071273 2 жыл бұрын
Great mapping of Pipedream along Purdue and MITRE, thx Mr. Lee!🙌
@aryamarga108
@aryamarga108 Жыл бұрын
Also a very good point by Robert in regards to predicting threat actors' targeting. It's a waste of time to debate whether you are likely to be targeted or not. Focus on deploying robust security controls and always be prepared for the unexpected.
@aryamarga108
@aryamarga108 Жыл бұрын
Schrodinger ICS, haha. Good point to invest more in detection and response as opposed to concentrating all resources on prevention.
@aryamarga108
@aryamarga108 Жыл бұрын
Lateral movement monitoring. Not just what comes in and goes out.
@HexaSquirrel
@HexaSquirrel 2 жыл бұрын
Great talk, Rob!
@aryamarga108
@aryamarga108 Жыл бұрын
These threat actors are really organized. I didn't know there were separate groups that specialized in access or the activity in itself.
@fredericoferreira5581
@fredericoferreira5581 2 жыл бұрын
Great talk
@aryamarga108
@aryamarga108 Жыл бұрын
Very interesting that Dragos does not do attribution unless it affects the incident response process. It seems like an efficient way to approach things given that the priority should be to formulate how to properly defend the systems at hand.
@ranikehat3913
@ranikehat3913 2 жыл бұрын
Great Talk
@The-Blind-Witch
@The-Blind-Witch 2 жыл бұрын
Are you certain the adversaries' tradecraft error wasn't intentional as a warning signal from the adversary nation state to the USA?
Is The Purdue Model Dead?
30:39
S4 Events
Рет қаралды 6 М.
Industroyer2 with Robert Lipovsky of ESET
32:44
S4 Events
Рет қаралды 1,3 М.
Inside Out 2: Who is the strongest? Joy vs Envy vs Anger #shorts #animation
00:22
Получилось у Миланы?😂
00:13
ХАБИБ
Рет қаралды 4,6 МЛН
Slow motion boy #shorts by Tsuriki Show
00:14
Tsuriki Show
Рет қаралды 9 МЛН
6. The Threat To ICS with Rob Lee
48:38
S4 Events
Рет қаралды 5 М.
Exploiting Omron's NEX PLC Runtime And Protocol
24:50
S4 Events
Рет қаралды 200
S4x24 Main Stage Interview With Rob Lee
33:31
S4 Events
Рет қаралды 1,6 М.
A Hacker's Eye View On CISA's Secure By Design
36:12
S4 Events
Рет қаралды 393
2. ICS Security Architecture with Dale Peterson
45:45
S4 Events
Рет қаралды 5 М.
TRITON - Schneider Electric Analysis and Disclosure
25:52
S4 Events
Рет қаралды 12 М.
The Five ICS Cybersecurity Critical Controls Webcast
1:05:41
SANS ICS Security
Рет қаралды 5 М.
Network Security - Deep Dive Replay
3:08:19
Kevin Wallace Training, LLC
Рет қаралды 141 М.
Опасность фирменной зарядки Apple
0:57
SuperCrastan
Рет қаралды 11 МЛН
My iPhone 15 pro max 😱🫣😂
0:21
Nadir Show
Рет қаралды 1,2 МЛН
Better Than Smart Phones☠️🤯 | #trollface
0:11
Not Sanu Moments
Рет қаралды 15 МЛН
تجربة أغرب توصيلة شحن ضد القطع تماما
0:56
صدام العزي
Рет қаралды 63 МЛН