BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Obsidian CTH: Hunting for Adversary's Schedule\n   W
 hen: Friday\, Aug 12\, 13:00 - 13:59 PDT\n   Where: Flamingo - Savoy Ballr
 oom - BTV Project Obsidian: Track 0x42\n   (In-person) - [1]Map\n\n   Spea
 kerBio:Cyb3rHawk\n   No BIO available\n\n   Description:\n   Once an adver
 sary gained a foothold\, they typically would like to keep\n   their acces
 s. Here\, I'm using the term ""access"" loosely where it\n   could be many
  things like C2 beacon\, script\, binary\, security source\n   providers\,
  shortcuts\, and so on. This is called Persistence and in\n   MITRE speak 
 ""TA0003"" [3]. We take a look at one such persistence\n   method\, Schedu
 led Task. Scheduled tasks are one of the most commonly\n   used persistenc
 e techniques in adversary intrusions and for a good\n   reason. It provide
 s flexibility to be created on local and remote\n   machines and provides 
 several ways to be created (from GUI to\n   Net32API)\, along with the abi
 lity to combine/achieve tactics like\n   Execution and Privilege Escalatio
 n. We start with the basics of\n   scheduled tasks\, and why and when an a
 dversary would like to use them.\n   Then we jump into the hell of threat 
 hunting to see some ways to\n   create a hypothesis and investigate the re
 sult set. In the end\, we\n   take a stab at detection engineering concept
 s surrounding the\n   creation/revision of detections/analytics from queri
 es/results we got\n   from hunting this technique.\n\n   Blue Team Village
 ’s Project Obsidian is an immersive\, defensive\n   cybersecurity learni
 ng experience that provides attendees with the\n   opportunity to gain kno
 wledge of Incident Response (IR)\, Digital\n   Forensics (DF)\, Reverse En
 gineering Malware (REM)\, Cyber Threat\n   Intelligence (CTI)\, and Cyber 
 Threat Hunting (CTH).\n\n   Once an adversary gained a foothold\, they typ
 ically would like to keep\n   their access and establish persistence. Sche
 duled tasks are one of the\n   most commonly used persistence techniques i
 n adversary intrusions and\n   for a good reason. In this session we take 
 a look at Scheduled Tasks.\n   We start with the basics\, and then learn h
 ow to create a hypothesis to\n   conduct a threat hunt. In the end\, we'll
  take a stab at detection\n   engineering concepts surrounding the creatio
 n/revision of\n   detections/analytics from telemetry we obtain from hunti
 ng this\n   technique.\n\n   Project Obsidian is an immersive\, defensive 
 cybersecurity learning\n   experience.\n\n   '\n\n   1. https://defcon.out
 el.org/consolidated_page.html#FlamingoThirdFloor\n\n\n
DTEND:20220812T205900Z
DTSTART:20220812T200000Z
LOCATION:BTV - Flamingo - Savoy Ballroom - BTV Project Obsidian: Track 0x42
  (In-person)
SUMMARY:Obsidian CTH: Hunting for Adversary's Schedule
END:VEVENT
END:VCALENDAR
