SAINTCON 2016 - Neil Wyler (Grifter) - Left of Owned

Join Neil Wyler (Grifter) as he shares his expertise on red teaming, threat hunting, and incident response at SAINTCON 2016. Learn how to think like an attacker, identify weaknesses, and improve your organization's defense.

Key takeaways
  • To think like an attacker, you need to know their mindset and tactics.
  • Red teaming is essential to improve incident response and threat hunting.
  • It’s crucial to have a good understanding of your environment and baseline behavior.
  • Situational awareness is key to identifying potential threats.
  • Constant communication and update are necessary during an incident.
  • Full packet captures are essential for analysis.
  • Red teaming can help identify weaknesses and improve incident response.
  • Threat hunters need to be skilled, motivated, and persistent.
  • Documentation is crucial for tracking and analyzing incidents.
  • Proactive measures can help prevent incidents and reduce the impact of attacks.
  • Hunting for threats is a continuous process that requires constant learning and improvement.
  • Threat hunters need to be able to adapt to new tactics and techniques.
  • Good tools and training are essential for effective threat hunting.
  • Communication and collaboration are critical during an incident.
  • Red teaming can help identify areas for improvement in incident response.
  • Threat hunters need to be able to think critically and make quick decisions.
  • Constantly updating knowledge and skills is necessary for effective threat hunting.
  • Red teaming can help identify new threats and tactics.
  • Threat hunters need to be able to work well under pressure and make quick decisions.
  • Good communication is essential for effective incident response.
  • Proactive measures can help prevent incidents and reduce the impact of attacks.
  • Threat hunters need to be able to identify and prioritize potential threats.
  • Constantly reviewing and updating incident response plans is necessary for effective threat hunting.
  • Red teaming can help identify areas for improvement in incident response.