Emulating, Detecting, and Responding to LOLBAS Attacks – A SEC699 Update Preview



Join SANS Certified Instructor Jean-François Maes as he previews new material directly from the updated SANS SEC699: Purple Team Tactics - Adversary Emulation for Breach Prevention & Detection. Once attackers have gained initial access, they do not want to get caught by the suite of security tools on modern Windows systems. To stay under the radar, attackers leverage Living Off the Land Binaries and Scripts (LOLBAS). These are signed, allowed, and often built-in binaries, scripts, and libraries that have additional functionality attackers can abuse. In this webcast, Jean will introduce various LOLBAS, how to emulate them, detect, and respond to them in a true purple team fashion. As usual, expect demos and dad jokes.

Speaker and Presenter Information

Jean-François Maes

Relevant Government Agencies

Other Federal Agencies, Federal Government, State & Local Government


Event Type
Webcast


When
Tue, Sep 20, 2022, 2:00pm ET


Cost
Complimentary:    $ 0.00


Website
Click here to visit event website


Organizer
SANS Institute


Contact Event Organizer



Return to search results