Professional Documents
Culture Documents
10.10.17
Advanced Policies with Cb Defense
How to tailor your prevention to maximize effectiveness
NOVICE EXPERT
Identify
Develop the
a place to
new policy
improve
Deploy the
policy
Test for
efficacy
& false
positives
ADVANCED ADVANCED
(policies with same settings)
TRIAGE FOR
INTERMEDIATE INTERMEDIATE
ADVANCED
(policies with same settings)
TRIAGE FOR
BASIC BASIC
INTERMEDIATE
(policies with same settings)
INSTALL
(processEffectiveReputation:NOT_LISTED OR
processReputationProperty:NOT_LISTED) AND
(threatIndicators:INJECT_CODE OR
threatIndicators:HAS_INJECTED_CODE OR
threatIndicators:COMPROMISED_PROCESS OR
threatIndicators:PROCESS_IMAGE_REPLACED OR
threatIndicators:MODIFY_PROCESS OR
threatIndicators:HOLLOW_PROCESS)
(threatIndicators:UNKNOWN_APP OR
processEffectiveReputation:UNKNOWN OR
processReputationProperty:UNKNOWN) AND
(threatIndicators:INJECT_CODE OR
threatIndicators:HAS_INJECTED_CODE OR
threatIndicators:COMPROMISED_PROCESS OR
threatIndicators:PROCESS_IMAGE_REPLACED OR
threatIndicators:MODIFY_PROCESS OR
threatIndicators:HOLLOW_PROCESS)
(processEffectiveReputation:NOT_LISTED OR
processReputationProperty:NOT_LISTED) AND
(threatIndicators:SCRAPE_MEMORY OR
threatIndicators:RAM_SCRAPING OR
threatIndicators:READ_SECURITY_DATA)
(threatIndicators:UNKNOWN_APP OR
processEffectiveReputation:UNKNOWN OR
processReputationProperty:UNKNOWN) AND
(threatIndicators:SCRAPE_MEMORY OR
threatIndicators:RAM_SCRAPING OR
threatIndicators:READ_SECURITY_DATA)
+ https://github.com/hslatman/aweso
me-threat-intelligence
+ http://reddit.com/r/netsec
+ http://reddit.com/r/sysadmin
(processEffectiveReputation:PUP OR
processReputationProperty:PUP)
(processEffectiveReputation:SUSPECT_MALWARE
OR
processReputationProperty:SUSPECT_MALWARE)
OR (targetEffectiveReputation:SUSPECT_MALWARE
OR targetReputationProperty:SUSPECT_MALWARE)
+ Toolbar that engages in all sorts of unnecessary operations, such as memory scraping.
+ Security tool that can be used against you, like a port mapper or penetration toolkit.
SHARE NOW
NOVICE EXPERT
THANK YOU