Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo...

30
Cyberwar & Splunk Demonstration Sam Bowne

Transcript of Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo...

Page 1: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Cyberwar & Splunk Demonstration

Sam Bowne

Page 2: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Twitter

Page 3: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 4: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 5: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

• https://www.rfa.org/english/news/china/hacking-02222013121848.html

Page 6: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Kill Chain

Page 7: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 8: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

https://www.businessinsider.com/fbi-aristedes-mahairas-these-4-nations-pose-biggest-cyber-risk-to-us-2018-6

Page 9: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

• https://graquantum.com/a-brief-history-of-cyberwarfare/

A Brief History of Cyberwarfare

Page 10: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Scorecard

• https://warontherocks.com/2017/07/cyber-attacks-whos-keeping-score/

Page 11: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Scorecard

• https://warontherocks.com/2017/07/cyber-attacks-whos-keeping-score/

Page 12: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Chinese Attacks

https://www.belfercenter.org

Page 13: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 14: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Russian Cyberattacks

Page 15: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Iranian Attacks

https://www.recordedfuture.com

Page 16: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 17: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 18: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 19: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

Russian Attacks

2006: Litvineko poisioned in London with Polonium-210

2007: Cyberattack on Estonia

2008: Invasion of Georgia

2016: Cyberattacks to influence US election

2018: Skripal poisioned with Novichok nerve agent in Salisbury, England

Page 20: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 21: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 22: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 23: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

US Attack Tools

Page 24: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/

Page 25: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific

https://www2.cs.arizona.edu/~collberg/Teaching/466-566/2012/Resources/presentations/2012/topic9-final/report.pdf

Page 26: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 27: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 28: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 29: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific
Page 30: Cyberwar & Splunk Demonstrationsplunk> CORE CERTIFIED USER e 6) a https// samsclass. nfo 150/oroi/ourale-bots.htm Purple Team 4: Threat Hunting with Splunk (325 pts) Scores from Pacific