14. 14
• Saved Searches Are Awesome!
ê 25%+ of SOC Tickets
• Alert: PowerShell Using “ -enc”
ê Also Alerted: “ -exec bypass”
ê Not Caught by Security Stack Tools
• Used to Base64 Encode
ê Detec;on Avoidance Mechanism
Use Case 1
“Tripping Over The Needle”
25. 25
Use Case 2
• Intel is Now Ubiquitous
ê Paid Feeds
ê Open Source (Blogs/Twirer)
ê That Girl You Worked with Two
Companies Ago
• Indicators of Compromise
ê IOCs Everywhere!
ê How Do We Process Them All?
Ve†ng Threat Intel