Blueprint: Build the Best in Cyber Defense

Blueprint: Build the Best in Cyber Defense

By SANS InstituteTechnology
Download on the App Store

Blueprint: Build the Best in Cyber Defense episodes

  • Rob Lee: Training and Reskilling in Cyber Security

    Many of us are either looking to start a cyber security career, improve our knowledge and skills to further our career, or hire a team that has the most skilled and promising candidates. In this special episode with Rob Lee, Chief Curriculum Director of the SANS Institute, we discuss strategies for building, improving, and testing your cyber security group’s skill levels, and working to keep our knowledge as current as possible - a critical skill for anyone in the fast moving world of cyber security.

    Rob Lee

    Rob Lee is the Chief Curriculum Director and Faculty Lead at SANS Institute and runs his own consulting business specializing in information security, incident response, threat hunting, and digital forensics. With more than 20 years of experience in digital forensics, vulnerability and exploit discovery, intrusion detection/prevention, and incident response, he is known as “The Godfather of DFIR”. Rob co-authored the book Know Your Enemy, 2nd Edition, and is course co-author of FOR500: Windows Forensic Analysis and FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics.

    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.

    Check out the details at sansurl.com/450  Hope to see you in class!


    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

    Follow John Hubbard: Twitter | LinkedIn


    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    51 min
  • Jaron Bradley: Securing Enterprise macOS

    In this episode of the Blueprint Podcast, we cover monitoring and securing macOS in an enterprise environment at scale with Jaron Bradley, Threat Detection lead at Jamf. We discuss the ups and downs of Apple's approach to macOS data collection over the years, the data sources and types that are accessible to defenders, what 3rd party agents bring to the table for security monitoring, and much more. Plus, Jaron gives us some great bonus tips for finding persistence mechanisms and malicious processes in enterprise macOS devices.

    Our Guest - Jaron Bradley

    Jaron has a background in Incident Response, threat hunting, and detections development. After focusing on large scale APT attacks he developed an interest in the more niche spaces of lesser explored operating systems. He has experience as both a SOC analyst as well as detections engineering at the endpoint level.Jaron currently works as the macOS Detections Lead at Jamf Threat Labs and manages his own security tools and content for security researchers atthemittenmac.com. He is also the author of OS X Incident Response Scripting and Analysis. A book he claims is slightly outdated but still relevant to a lot of macOS analysis today.

    Resources mentioned in this episode

    Websites

    • https://www.themittenmac.com (my website)
    • objective-see.com (great mac security website)
    • Major Blogs Referenced by Jamf Threat Labs
      • https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/
      • https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/
      • https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/
      • https://www.jamf.com/threat-labs/ (threat labs home)

    Conferences

    • Jamf Nation User Conference -> https://www.jamf.com/events/jamf-nation-user-conference/2022/
    • Objective by the sea 5.0 -> https://objectivebythesea.org/v5/index.html

    Support for the Blueprint podcast comes from the SANS Institute.

    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

    Follow John Hubbard: Twitter | LinkedIn


    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    59 min
  • Alexia Crumpton: MITRE ATT&CK for Defenders

    One of the best frameworks that showed up within the last 5 or so years is undoubtedly the MITRE ATT&CK® framework. Many of us may know about it in passing and even reference from time to time, but very few people seem to know the true depth of knowledge contained - everything from analytics to threat groups, specific mitigation and detection opportunities, and with the newest versions, even specific data sources. In this episode we talk to the Defensive Lead of ATT&CK from MITRE, Lex Crumpton, about what every blue team member needs to know about this framework, and more!

    Alexia Crumpton

    Alexia Crumpton is a Defensive Cyber Operations Researcher with over seven years of experience in software development, SOCs, and Malware Reverse Engineering. Her passion lies in heuristic behavior analysis in regards to adversary TTPs and countermeasures used to defend against them. 

    Follow Alexia

    LinkedIn: https://www.linkedin.com/in/alexia-crumpton-99930659/


    Resources mentioned in this episode:

    CAR - The MITRE Cyber Analytics Repository (CAR) is a knowledge base of analytics developed by MITRE based on the MITRE ATT&CK adversary model.


    Top ATT&CK Techniques – Medium Blog, Github, Calculator

    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need t

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    43 min
  • Cat Self: macOS and Linux Security

    Ever wonder why there’s so little information regarding macOS and Linux-oriented attacks? In this episode, we get the answer from  the multi-talented Cat Self - an Adversary Emulation Engineer at MITRE, Cyber Threat Intelligence Team Leader on ATT&CK Evaluations and macOS/ Lead on MITRE ATT&CK Enterprise. We discuss defense tools,  attacker TTPs, and what to consider when approaching defense for a macOS and Linux environment, and what trends we can expect in the future for these operating systems. Check out the resources below for links mentioned during this enlightening conversation!

    Our Guest: Cat Self

    Cat Self is the CTI Lead for MITRE ATT&CK® Evaluations, macOS/Linux Lead for ATT&CK® and serves as a leader of people at MITRE. Cat started her cyber security career at Target and has worked as a developer, internal red team operator, and Threat Hunter. Cat is a former military intelligence veteran and pays it forward through mentorship, technical macOS hunting workshops, and public speaking. Outside of work, she is often planning an epic adventure or climbing mountains in foreign lands. 


    Follow Cat on Social Media

    Twitter: @coolestcatiknow

    LinkedIn: Cat Self


    Resources mentioned in this episode:

    A highlight of new security changes in macOS Ventura:

    https://www.sentinelone.com/blog/apples-macos-ventura-7-new-security-changes-to-be-aware-of/

     

    For securing a macOS device, I highly recommend installing Patrick Wardle’s endpoint tools. https://objective-see.org/tools.html My favorites are BlockBlock, KnockKnock, Lulu, & Netiquette. 

     

    Cat's “GoTo” blogs

    Patrick Wardle Objective-See

    Jaron Bradley The Mitten Mac

    Howard Oakley The Eclectic Light Company

    Cody Thomas Medium

    Sarah Edwards mac4n6

    Leo Pitt Medium

    Christopher Ross Medium

    Csaba Fitzl THEEVILBIT Blog

     

    Open Source Projects

    Playbooks with Datasets to practice OTRF

    Code snippets aligned to MITRE ATT&CK Atomic Red Team

    Jupyter notebook environment setup by Anna Pastushko

    Virtual environment setup Hold My Beer


    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands 

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    57 min
  • Corissa Koopmans and Mark Morowczynski: Azure AD Threat Detection and Logging

    Nearly every organization is using Microsoft Azure AD services in some respect, but monitoring Azure AD for threats is a significantly different skill that traditional Windows logging. In this episode we have 2 experts from Microsoft, Corissa Koopmans, and 3rd time returning guest Mark Morowczynski, to tell us about the important work that’s been done to help organizations understand their data and detect Azure AD attacks. We cover log sources, the new Microsoft security operations guide, standardized dashboards and visualizations you can leverage to jump right in with best practice, and much more. You don’t want to miss this one!

    Corissa Koopmans and Mark Morowczynski

    Corissa Koopmans (@Corissalea) is part of the "Get to Production" team in the Microsoft Identity and Network Access Division, focusing on incorporating customer feedback to improve our products. She is very active in driving community contribution to AzureMonitor Log Analytics and increasing awareness of the power of log data by presenting at industry events including BSides, The Experts Conference (TEC), SPARK, & Microsoft MVP Summits.

    Mark Morowczynski (@markmorow) is a Principal Program Manager on the customer success team in the Microsoft Identity division. He spends most of his time working with customers on their deployments of Azure Active Directory. Previously he was Premier Field Engineer supporting Active Directory, Active Directory Federation Services and Windows Client performance. He's spoken at various industry events such as Black Hat, Defcon Blue TeamVillage, Blue Team Con, GrayHat, several BSides, and more. He can be frequently found on Twitter as @markmorow arguing about baseball and making sometimes funny gifs.

    Azure AD SecOps - aka.ms/azureadsecops

    Azure Monitor Log Analytics and KQL resources: aka.ms/KQLBlueTeam

    For community contribution, please follow these prerequisites (these steps are also available at aka.ms/KQLBlueTeaml):
    1.      Have a GitHub account
    2.      Belong to the Microsoft Organization in GitHub
    a.      If you do not yet belong, click on this link: https://repos.opensource.microsoft.com/ and then select “Microsoft” to join their organization
    3.      Be a member of the @azure-ad-workbooks team in GitHub
    a.      if you are not yet a member, go to the Microsoft Organization in GitHub and search for the @azure-ad-workbooks team and request access for approval by owner

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    48 min
  • Tony Turner: Securing the Cyber Supply Chain

    John and Fortress Vice President of Research and Development Tony Turner share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at the Cyber Supply Chain in 2022 and beyond.

    Follow Tony Turner

    LinkedIn: https://www.linkedin.com/in/tonyturnercissp/

    Web: https://www.fortressinfosec.com/team/tony-turner


    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.

    Check out the details at sansurl.com/450  Hope to see you in class!


    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    48 min
  • Mark Orlando: Building a Stronger Blue Team

    There are many technical factors that contribute to the success of a security operations team, but you need more than just tech skills for mounting a solid defense. In this episode of Blueprint we bring back previous guest Mark Orlando to talk about his BlackHat 2022 presentation with Dr. Daniel Shore (PhD in workplace psychology) . We discuss team dynamics, how the mapping of multi-team systems can improve the flow of your incident response activities, and much more.

    Check out the related BlackHat talk here: https://www.youtube.com/watch?v=CtkJ84bc50g

    Our Guest - Mark Orlando

    Mark Orlando is a SANS Associate Instructor, co-author MGT551: Building and Leading Security Operations Centers, instructor for SEC450: Blue Team Fundamentals: Security Operations and Analysis, and the Co-Founder and CEO of Bionic Cyber. Prior to Bionic, Mark built, assessed, and managed security teams at the Pentagon, the White House, the Department of Energy, and numerous Fortune 500 clients. Mark has presented on security operations and assessment at DefCon's Blue Team Village, the Institute for Applied Network Security (IANS) Forum, BSidesDC, and the RSA Conference and has been quoted in the New York Times, the Washington Post, Forbes, and many other publications. He holds a Bachelor's Degree in Advanced Information Technology from George Mason University and served in the US Marine Corps as an Artillery Non-Commissioned Officer.


    Follow Mark Orlando

    Twitter: https://twitter.com/markaorlando

    LinkedIn: https://www.linkedin.com/in/marko16/

    Web: https://www.sans.org/profiles/mark-orlando/


    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.

    Check out the details at sansurl.com/450  Hope to see you in class!


    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    50 min
  • Blueprint Live at SANSFIRE 2022: A panel with Heather Mahalik, Katie Nickels and Jeff McJunkin

    Host John Hubbard, Blueprint host and SANS Cyber Defense Curriculum Lead, moderated a panel of cyber security experts including Heather Mahalik, Katie Nickels and Jeff McJunkin for this powerful discussion.

    John and guests share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at cyber defense in 2022 and beyond.

    Guests:
    Heather Mahalik
    Katie Nickels
    Jeff McJunkin

    Filmed live at SANSFIRE 2022

    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.

    Check out the details at sansurl.com/450  Hope to see you in class!


    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    59 min
  • David Hoelzer: Threat Detection with Machine Learning and AI

    Many of us with the typical IT and security backgrounds might not have the slightest idea what to expect when we hear the terms “this product uses advanced machine learning…”, but that claim certainly conjures up a lot of skepticism due to the opaque nature of the algorithms in many of these products. In this episode we discuss what AI and ML are best used for, and what they can, can’t, and shouldn’t be used for with guest Dave Hoelzer.


    Our Guest - Dave Hoelzer

    David Hoelzer, a SANS Fellow and author of more than twenty days of SANS courseware, is an expert in a variety of information security fields, having served in most major roles in the IT and security industries over the past twenty-five years. Currently, David serves as the principal examiner and director of research for Enclave Forensics, a New York/Las Vegas based incident response and forensics company. He also serves as the chief information security officer for Cyber-Defense, an open-source security software solution provider.


    Follow Dave

    Twitter: https://twitter.com/it_audit 

    LinkedIn: https://www.linkedin.com/in/davidhoelzer/ 

    --

    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    50 min
  • James Rowley: Creating and Running an Insider Threat Program

    While malicious insiders are a threat that most of us would like to imagine we might never have to deal with, it’s still one of the cyber threats you must realistically consider and plan for. But how do you identify malicious intent and potential attacks from those already inside our network that have legitimate access to our data? Check out this episode where James Rowley lays out what you need to consider when it comes to insider threat detection. 


    Our Guest - James Rowley

    James Rowley is a cybersecurity-consultant-turned-dectection-engineer building the next generation of insider threat detections. As a Detection Engineer, James is responsible for merging the world of blue team and insider threat, moving the needle on how we approach insider detections within cyberspace. James outside of the workspace is passionate about most things related to outdoors, beer, whiskey, wine, food, travel, and Minnesota sports teams. You will find James enjoying these things and more with his fiance and two dogs, Marshall (Bernese Mountain Dog) and Maya (Basset Hound).

    --

    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.

    Check out the details at http://sans.org/sec450 Hope to see you in class!

    --

    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    1 hr

About Blueprint: Build the Best in Cyber Defense

From the publisher's feed

Are you a cyber defender looking to keep up on the newest tools, technology, and security concepts? Then BLUEPRINT is the podcast for you! Tune in to hear the latest in cyber defense and security…

More shows like Blueprint: Build the Best in Cyber Defense

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

The Daily by The New York Times

The Daily

111,845 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners