Transcript
Page 1: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 2: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 3: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 4: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 5: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 6: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 7: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 8: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Threat Intelligence

Vulnerability Management

Incident Response

Continuous Monitoring

Page 9: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 10: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

HTTPS://ATTACK.MITRE.ORG/

Page 11: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

TTPs

Tools

Network/Host Artifacts

Domains

IP Addresses

Hash Values

• http://detect-

respond.blogspot.com/2013/03/t

he-pyramid-of-pain.html

• Written by David J

Bianco

Page 12: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

USE

CASE:

Windows

EventID

USE CASE:

Scanning

USE CASE: Log into

disabled accounts

USE CASE: C2/

Configuration

Changes

USE CASE: PowerShell

download and execution

Page 13: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 14: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

••

• HTTPS://WWW.SPLUNK.COM/BLOG/2017/08/07/PEEPING-THROUGH-WINDOWS-LOGS.HTML

Page 15: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

• HTTPS://WWW.SPLUNK.COM/BLOG/2017/07/06/HUNTI

NG-WITH-SPLUNK-THE-BASICS.HTML

Page 16: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 17: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

• HTTPS://WWW.SPLUNK.COM/BLOG/2017/11/0

3/YOU-CAN-T-HYDE-FROM-DR-LEVENSHTEIN-

WHEN-YOU-USE-URL-TOOLBOX.HTML

Page 18: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 19: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 20: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

• HTTPS://WWW.SECUREWORKS.COM/RESEARCH/SAKULA-MALWARE-FAMILY

Page 21: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 22: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 23: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

• HTTPS://WWW.SPLUNK.COM/BLOG/2018/03/20/HUNTIN

G-YOUR-DNS-DRAGONS.HTML

Page 24: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 25: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected
Page 26: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

• HTTPS://WWW.SPLUNK.COM/BLOG/2018/03/20/H

UNTING-YOUR-DNS-DRAGONS.HTML

Page 27: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Page 28: Use Case Development as a Driver for SOC Maturation...Search site ID G0009 Contributors: Andrew Smith, @jakx_ Version . 1.0 Home > Groups > Deep Panda Deep Panda Deep Panda is a suspected

Recommended