Slidedeck from March 2022's DC44191 event. Andrew Waite (@infosanity) walks through a hypothetical compromise, what to do if you ever find yourself in a similar scenario; and ends with some deep dive ideas for honeypots to monitor for malicious activity. For more information, see: https://blog.infosanity.co.uk/?p=1463