Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Threat Actor Collaboration and Framework for Comparative Attribution - A Case Study

SANS via YouTube

Overview

Coursera Plus Annual Sale: All Certificates & Courses 25% Off!
Explore a 35-minute conference talk from SANS that delves into the evolving landscape of threat actor collaboration and attribution challenges. Learn how cyber criminals are monetizing their operations through shared capabilities, from selling stolen credentials to renting out ransomware-as-a-service. Examine the historical leadership of espionage-motivated threat actors, particularly those from China, in tool sharing practices like PlugX, ShadowPad, and PoisonIvy. Follow a detailed case study of the China-based threat actor "Red Ishtar" to understand the complexities of tracking and attributing cyber threats across multiple intrusion sets. Gain practical insights through a threat-agnostic framework for comparative attribution analysis, designed to help navigate intelligence from various sources and understand threat actor behavior in an increasingly collaborative cyber threat landscape. Presented by Jono Davis, Senior Analyst from PwC Global Threat Intelligence Team, this talk equips security professionals with tools to detect and analyze shared capabilities among threat actors.

Syllabus

What a Cluster: A Case Study in Threat Actor Collaboration & Framework for Comparative Attribution

Taught by

SANS Digital Forensics and Incident Response

Reviews

Start your review of Threat Actor Collaboration and Framework for Comparative Attribution - A Case Study

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.