Security Artifacts – The Hunt for Forensic Residue

Email     |     Share  
1 | 2 | 3 | 4 | 5 | 6 | 7
Next Security Artifacts – The Hunt for Forensic Residue-3 Next

Attack Lessons

Artifacts can teach security professionals valuable lessons about attacks.

Forensic residue left on a disk can describe past activities going back months or even years. Residue and artifacts can provide deep insight to scope a breach, helping organizations create a timeline of a hacker's lateral movement to locate "patient zero." Employees working against you as "insider threats" leave large trails of evidence and are primarily caught with forensics.

A quiet, underground revolution is taking place in the security industry as companies shift from focusing on the perimeter to capturing and analyzing the residue left on endpoint devices by hackers and cyber attacks. Several years ago, a community of forensic researchers began reverse engineering the innards of operating systems. Their efforts led to finding "artifacts," which reveal almost all users and application interaction with the operating system. These breadcrumbs can be found deep within file systems, memory and OS system files. Unlike clearing log files, artifacts are nearly impossible to manipulate.

The residue or artifacts left behind can provide clues about an intruder to IT security professionals. For example, RAT (Remote Access Trojan) residue was important in investigating the cause of the Office of Personnel Management's (OPM) breach. OPM's intrusion prevention system essentially logged data that was being exfiltrated without detecting any of the breadcrumbs that attackers left behind.

Today's incident response and endpoint detection tools use forensic artifacts that have accumulated on endpoints. Advanced rootkits, zero-day attacks and command and control incidents leave an abundance of artifacts. Avoiding leaving a forensic trail is almost impossible.

In this slideshow, Paul Shomo, senior technical manager, Strategic Partnerships, Guidance Software, looks at forensic residue and how it can help organizations better protect themselves from security threats, both inside and outside the organization.


Related Topics : Unisys, Stimulus Package, Security Breaches, Symantec, Electronic Surveillance

More Slideshows

infra100-190x128 Top 10 Strategic Technology Trends for 2017

Here are the top 10 strategic technology trends that will impact most organizations in 2017. Strategic technology trends are defined as those with substantial disruptive potential or those reaching the tipping point over the next five years. ...  More >>

Compliance4-190x128 GRC Programs: Building the Business Case for Value

Experience shows that organizations that manage GRC as an integrated program — involving people, processes and technologies — are more successful in delivering value to their organizations ...  More >>

Social14-190x128.jpg 10 Ways to Improve Your Social Media Security Policy and Posture

When phone calls, video conference information, pictures, chat logs, etc. are all stored in a central location via social media, a potential hacker has access to just about everything, quickly and easily. ...  More >>

Subscribe to our Newsletters

Sign up now and get the best business technology insights direct to your inbox.