Skip to main content
webinar register page
The webinar has ended
Register to watch this recording on-demand
Facebook
Twitter
LinkedIn
Microsoft (Outlook)
Topic
Intermediate Purple Team Workshop - Detection Engineering
Description
Join Chris Peacock for a three hour Hands-On Purple Team Exercise Workshop focused on Detection Engineering. This is an intermediate level workshop that does not require, but does recommend, you to have taken the Introduction to Purple Team Exercise workshop.
***REGISTRATION REQUIRED***
***Use a real email address***
The workshop will guide attendees through the detection engineering process. Attendees will take curated threat actor procedures to emulate and detect. The process will include how to determine which log sources to target for investigation. After verifying the appropriate log sources, attendees will learn to hunt through and narrow down results until they have an actionable query to deploy as detection logic.
First, we will cover the structured process of detection engineering. Then, after going over each step of the cycle, we will dive into a hands-on workshop to put the method to practical use.
Not everyone will have a threat intelligence team to prioritize new detections. Therefore, attendees will walk through a cyber intelligence process of collecting and extracting Tactics, Techniques, and Procedures (TTPs) to guide content development.
Next, attendees will emulate procured Tactics, Techniques, and Procedures (TTPs) commonly found in modern attacks. Each emulation phase will generate data to use in detection engineering. Then, leveraging MITRE ATT&CK, we will pivot from the emulations to potential log sources. At times, log sources may not exist yet, and we will go over troubleshooting log sources to resolve logging issues.
In the final stage attendees will learn to develop hypotheses to conduct hunting through data that drives rule creation to uncover the adversary procedures. Attendees will develop hunting queries that transition into polished alert rules. Lastly, for instances where direct pattern matching will not suffice, attendees will learn how to baseline and detect anomalies.
Recording Duration
03:11:00
*
Required information
Loading
Register
Speakers
Christopher Peacock
Adversary Emulation-Detection Engineer
@
SCYTHE
×
Share via Email
All fields are required
Your Information
Send to
Message preview
Hi there, You are invited to a Zoom webinar. When: May 20, 2022 01:00 PM Eastern Time (US and Canada) Topic: Intermediate Purple Team Workshop - Detection Engineering Register in advance for this webinar: https://us06web.zoom.us/webinar/register/WN_x7iJ0tj_SFSoG_Oh1bGEiA Or an H.323/SIP room system: H.323: 162.255.37.11 (US West) 162.255.36.11 (US East) 115.114.131.7 (India Mumbai) 115.114.115.7 (India Hyderabad) 213.19.144.110 (Amsterdam Netherlands) 213.244.140.110 (Germany) 103.122.166.55 (Australia Sydney) 103.122.167.55 (Australia Melbourne) 149.137.40.110 (Singapore) 64.211.144.160 (Brazil) 149.137.68.253 (Mexico) 69.174.57.160 (Canada Toronto) 65.39.152.160 (Canada Vancouver) 207.226.132.110 (Japan Tokyo) 149.137.24.110 (Japan Osaka) Meeting ID: 832 3587 9244 SIP: 83235879244@zoomcrc.com After registering, you will receive a confirmation email containing information about joining the webinar. ---------- Webinar Speakers Christopher Peacock (Adversary Emulation-Detection Engineer @SCYTHE)
×
Switch Time Zone
Time Zone:
(GMT-11:00) Midway Island, Samoa
(GMT-11:00) Pago Pago
(GMT-10:00) Hawaii
(GMT-8:00) Alaska
(GMT-8:00) Juneau
(GMT-7:00) Vancouver
(GMT-7:00) Pacific Time (US and Canada)
(GMT-7:00) Tijuana
(GMT-7:00) Arizona
(GMT-7:00) Yukon
(GMT-6:00) Edmonton
(GMT-6:00) Mountain Time (US and Canada)
(GMT-6:00) Mazatlan
(GMT-6:00) Saskatchewan
(GMT-6:00) Guatemala
(GMT-6:00) El Salvador
(GMT-6:00) Managua
(GMT-6:00) Costa Rica
(GMT-6:00) Tegucigalpa
(GMT-6:00) Chihuahua
(GMT-5:00) Winnipeg
(GMT-5:00) Central Time (US and Canada)
(GMT-5:00) Mexico City
(GMT-5:00) Panama
(GMT-5:00) Bogota
(GMT-5:00) Lima
(GMT-5:00) Monterrey
(GMT-5:00) Acre
(GMT-4:00) Montreal
(GMT-4:00) Eastern Time (US and Canada)
(GMT-4:00) Indiana (East)
(GMT-4:00) Puerto Rico
(GMT-4:00) Caracas
(GMT-4:00) Santiago
(GMT-4:00) La Paz
(GMT-4:00) Guyana
(GMT-3:00) Halifax
(GMT-3:00) Montevideo
(GMT-3:00) Recife
(GMT-3:00) Buenos Aires, Georgetown
(GMT-3:00) Sao Paulo
(GMT-3:00) Atlantic Time (Canada)
(GMT-2:30) Newfoundland and Labrador
(GMT-2:00) Greenland
(GMT-2:00) Fernando de Noronha
(GMT-1:00) Cape Verde Islands
(GMT+0:00) Azores
(GMT+0:00) Universal Time UTC
(GMT+0:00) Greenwich Mean Time
(GMT+0:00) Reykjavik
(GMT+0:00) Nouakchott
(GMT+1:00) Dublin
(GMT+1:00) London
(GMT+1:00) Lisbon
(GMT+1:00) Casablanca
(GMT+1:00) West Central Africa
(GMT+1:00) Algiers
(GMT+1:00) Tunis
(GMT+2:00) Belgrade, Bratislava, Ljubljana
(GMT+2:00) Sarajevo, Skopje, Zagreb
(GMT+2:00) Oslo
(GMT+2:00) Copenhagen
(GMT+2:00) Brussels
(GMT+2:00) Amsterdam, Berlin, Rome, Stockholm, Vienna
(GMT+2:00) Amsterdam
(GMT+2:00) Rome
(GMT+2:00) Stockholm
(GMT+2:00) Vienna
(GMT+2:00) Luxembourg
(GMT+2:00) Paris
(GMT+2:00) Zurich
(GMT+2:00) Madrid
(GMT+2:00) Harare, Pretoria
(GMT+2:00) Warsaw
(GMT+2:00) Prague Bratislava
(GMT+2:00) Budapest
(GMT+2:00) Tripoli
(GMT+2:00) Cairo
(GMT+2:00) Johannesburg
(GMT+2:00) Khartoum
(GMT+3:00) Helsinki
(GMT+3:00) Nairobi
(GMT+3:00) Sofia
(GMT+3:00) Istanbul
(GMT+3:00) Athens
(GMT+3:00) Bucharest
(GMT+3:00) Nicosia
(GMT+3:00) Beirut
(GMT+3:00) Damascus
(GMT+3:00) Jerusalem
(GMT+3:00) Amman
(GMT+3:00) Moscow
(GMT+3:00) Baghdad
(GMT+3:00) Kuwait
(GMT+3:00) Riyadh
(GMT+3:00) Bahrain
(GMT+3:00) Qatar
(GMT+3:00) Aden
(GMT+3:00) Djibouti
(GMT+3:00) Mogadishu
(GMT+3:00) Kiev
(GMT+3:00) Minsk
(GMT+3:00) Chisinau
(GMT+4:00) Dubai
(GMT+4:00) Muscat
(GMT+4:00) Baku, Tbilisi, Yerevan
(GMT+4:30) Tehran
(GMT+4:30) Kabul
(GMT+5:00) Yekaterinburg
(GMT+5:00) Islamabad, Karachi, Tashkent
(GMT+5:30) India
(GMT+5:30) Mumbai, Kolkata, New Delhi
(GMT+5:30) Colombo
(GMT+5:45) Kathmandu
(GMT+6:00) Almaty
(GMT+6:00) Dacca
(GMT+6:00) Astana, Dhaka
(GMT+6:30) Rangoon
(GMT+7:00) Novosibirsk
(GMT+7:00) Krasnoyarsk
(GMT+7:00) Bangkok
(GMT+7:00) Vietnam
(GMT+7:00) Jakarta
(GMT+8:00) Irkutsk, Ulaanbaatar
(GMT+8:00) Beijing, Shanghai
(GMT+8:00) Hong Kong SAR
(GMT+8:00) Taipei
(GMT+8:00) Kuala Lumpur
(GMT+8:00) Singapore
(GMT+8:00) Perth
(GMT+9:00) Yakutsk
(GMT+9:00) Seoul
(GMT+9:00) Osaka, Sapporo, Tokyo
(GMT+9:30) Darwin
(GMT+9:30) Adelaide
(GMT+10:00) Vladivostok
(GMT+10:00) Guam, Port Moresby
(GMT+10:00) Brisbane
(GMT+10:00) Canberra, Melbourne, Sydney
(GMT+10:00) Hobart
(GMT+10:30) Lord Howe IsIand
(GMT+11:00) Magadan
(GMT+11:00) Solomon Islands
(GMT+11:00) New Caledonia
(GMT+12:00) Kamchatka
(GMT+12:00) Fiji Islands, Marshall Islands
(GMT+12:00) Auckland, Wellington
(GMT+13:00) Independent State of Samoa
×
Continue to PayPal
Click to Continue
×
×
Upcoming Meetings
Would you like to start this meeting?
Would you like to start one of these meetings?
View more...