Episode 9 -Unmasking APT40 (Leviathan): Tactics, Challenges, and Defense Strategies

Episode 9 -Unmasking APT40 (Leviathan): Tactics, Challenges, and Defense Strategies

Send a text

Episode Title: "Unmasking APT40: Tactics, Challenges, and Defense Strategies"
Key Takeaways:

APT40 is a sophisticated Chinese state-sponsored cyber espionage group active since 2009.
They target various sectors including academia, aerospace, defense, healthcare, and maritime industries.
APT40 uses advanced tactics such as spear phishing, watering hole attacks, and living off the land binaries (LOLBINS).
Digital forensics faces challenges in detecting APT40 due to their use of legitimate tools and anti-forensics techniques.
Effective defense against APT40 requires a comprehensive, layered security approach.

Engaging Quotes:
"APT40 represents a significant and evolving threat in the cyber landscape. Their sophisticated attacks, large scope targets and state sponsorship make them a formidable adversary." - Clint Marsden
"Defense against groups like APT40 it is not about implementing a single solution. What matters is creating a comprehensive and layered security approach that can adapt to evolving threats." - Clint Marsden

Resources Mentioned:

MITRE ATT&CK Framework: https://attack.mitre.org/
Pyramid of Pain by David J. Bianco: https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html
NIST Computer Security Incident Handling Guide: https://csrc.nist.gov/pubs/sp/800/61/r2/final
Sysmon (System Monitor): https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon

Action Points:

Implement robust email security measures, including secure email gateways and employee training.
Keep all systems and software up-to-date to reduce vulnerabilities.
Use multi-factor authentication to protect against credential theft.
Implement network segmentation to limit lateral movement.
Deploy advanced endpoint detection and response (EDR) tools.
Conduct regular threat hunting exercises.
Implement data loss prevention (DLP) solutions.
Develop a comprehensive cloud security strategy.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(25)

Episode 24: Voice AI Under Attack: Hackers Exploit AI Call Agents | Traffic Light Protocol Podcast

Episode 24: Voice AI Under Attack: Hackers Exploit AI Call Agents | Traffic Light Protocol Podcast

Send a textVoice AI is moving fast — but so are the attackers.In this episode of the Traffic Light Protocol Podcast, Clint and Myles break down how scammers are exploiting Voice AI platforms with the ...

16 Sep 202554min

Episode 23:AI Voice Agent Security: Voice AI Under Siege: SIP Spoofing, Cost Drain, and How to Fight Back

Episode 23:AI Voice Agent Security: Voice AI Under Siege: SIP Spoofing, Cost Drain, and How to Fight Back

Send a textIn this episode of Traffic Light Protocol, we kick off our AI series with a hard look at how voice AI agents are being targeted; and how fast small businesses and startups can rack up serio...

5 Sep 202533min

Episode 22:AI Chat Forensics: How to Find, Investigate, and Analyse Evidence from ChatGPT, Claude & Gemini

Episode 22:AI Chat Forensics: How to Find, Investigate, and Analyse Evidence from ChatGPT, Claude & Gemini

Send a textUnlock the secrets behind digital forensic investigations into AI chat platforms like ChatGPT, Claude, and Google's Gemini in this insightful episode. Learn the precise methods for discover...

22 Jun 202540min

Episode 21: How IRCO is Changing DFIR: The AI Copilot for Real-Time Cyber Investigations

Episode 21: How IRCO is Changing DFIR: The AI Copilot for Real-Time Cyber Investigations

Send a textLink to IRCO- Incident Response Copilot on Chat  GPThttps://chatgpt.com/g/g-68033ce1b26481919b26df0737241bac-irco-incident-response-co-pilotIn this episode of TLP: The Digital Forensics Pod...

10 Jun 202515min

Episode 20:What Makes an Elite Incident Response Team: Mindset, Mastery, and Real-World DFIR Lessons

Episode 20:What Makes an Elite Incident Response Team: Mindset, Mastery, and Real-World DFIR Lessons

Send a textDrawing inspiration from observing military special forces and over five years of hands-on DFIR experience, Clint explores the mindset, habits, and tactical processes that set top-performin...

4 Jun 202538min

Episode 19: AI Data Poisoning: How Bad Actors Corrupt Machine Learning Systems for Under $60

Episode 19: AI Data Poisoning: How Bad Actors Corrupt Machine Learning Systems for Under $60

Send a textClint Marsden breaks down a critical cybersecurity report from intelligence agencies including the CSA, NSA, and FBI about the growing threat of AI data poisoning. Learn how malicious actor...

26 Mai 202526min

Audiobook - Mastering Sysmon. Deploying, Configuring, and Tuning in 10 easy steps

Audiobook - Mastering Sysmon. Deploying, Configuring, and Tuning in 10 easy steps

Send a textThis episode features the complete narration of my ebook: Mastering Sysmon – Deploying, Configuring, and Tuning in 10 Easy Steps, providing a step-by-step guide to getting Sysmon up and run...

28 Feb 202543min

Episode 17 - Building a CTF

Episode 17 - Building a CTF

Send a textSo You Want to Build Your Own DFIR CTF? Ever wanted to build your own Digital Forensics and Incident Response (DFIR) Capture the Flag (CTF) challenge but weren’t sure where to start? In thi...

27 Feb 202528min

Populært innen Teknologi

teknisk-sett
lydartikler-fra-aftenposten
energi-og-klima
rss-ki-praten
elektropodden
hans-petter-og-co
smart-forklart
rss-alt-som-gar-pa-strom
rss-snakk-om-sikkerhet
fornybaren
shifter
rss-ai-forklart
tomprat-med-gunnar-tjomlid
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
teknologi-og-mennesker
pedagogisk-intelligens
nasjonal-sikkerhetsmyndighet-nsm
rss-alt-vi-kan
rss-ki-til-kaffen
plattformpodden