Antisyphon Training Anticasts

Investigating Nix Endpoints for Incident Response - Patterson Cake


Listen Later

How many endpoint Operating Systems are there?
 
SPOILER alert – the answer is two!

🛝 Webcast Slides - 
https://www.antisyphontraining.com/wp-content/uploads/2026/04/REI-Nix-042026.pdf
 
Join Patterson Cake, Director of Incident Response at Black Hills Infosec, as he guides through his “rapid endpoint investigations” workflow for the “other” (not Windows) Operating System…*Nix (Linux/Mac).
 
We’ll learn how to select, acquire, and analyze Linux and Mac investigative artifacts, using Velociraptor offline collector, CatScale, and UAC scripts.
 
Windows gets a lot of attention and rightfully so!
 
However, Linux and Mac are part of every enterprise ecosystem and represent a critical attack surface. You need a simple, effective, repeatable plan for investigating these endpoints.

Chapters

  • (00:00) - Intro - Investigating Nix Endpoints for Incident Response - Patterson Cake
  • (00:43) - April is the cruelest month
  • (02:36) - AGENDA
  • (04:32) - ENDPOINT & IDENTITY
  • (05:10) - ENDPOINT = ?
  • (07:22) - OS = Windows vs Linux vs Mac?
  • (09:00) - Linux “Use Cases”
  • (10:40) - Endpoint Investigations: Linux
  • (12:57) - Rapid Endpoint Investigations: Linux
  • (13:48) - THREAT-ACTOR SOP*
  • (17:27) - ENDPOINT ATTACK SURFACE
  • (19:10) - RAPID TRIAGE WORKFLOW
  • (20:18) - Linux Artifacts
  • (22:25) - COLLECT...PARSE...REDUCE/REFINE
  • (23:33) - COLLECT ARTIFACTS
  • (27:13) - ANALYSIS WORKFLOW
  • (28:01) - OUTPUT REVIEW
  • (32:51) - Other = Mac (Business Desktops 10%)
  • (34:46) - Mac “Threat-Actor SoP”
  • (36:48) - Mac Artifacts
  • (40:19) - Mac UAC Execution
  • (42:06) - Mac Artificats (again)
  • (50:41) - ENDPOINT & IDENTITY - Mac
  • (52:43) - Resources
  • (54:03) - Q&A

  • Credits
    Creators & Guests
    • Patterson Cake - Guest
    • Zach Hill - Host
    • Ryan Poirier - Producer

    • Chat with your fellow attendees in the BHIS Discord server:
      https://discord.gg/bhis
      in the #🔴live-chat channel

      🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
      https://poweredbybhis.com

      Click here to watch a video of this episode.

      Brought to you by:

      Black Hills Information Security 

      https://www.blackhillsinfosec.com


      Antisyphon Training

      https://www.antisyphontraining.com/


      Active Countermeasures

      https://www.activecountermeasures.com


      Wild West Hackin Fest

      https://wildwesthackinfest.com

      Click here to view the episode transcript.

      ...more
      View all episodesView all episodes
      Download on the App Store

      Antisyphon Training AnticastsBy Antisyphon Training