<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - threat-hunting</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/threat-hunting/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2017-06-21T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/threat-hunting/atom.xml</id>
    <entry xml:lang="en">
        <title>Internet of Everything: Hands-On Cyber Security</title>
        <published>2017-06-21T00:00:00+00:00</published>
        <updated>2017-06-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/"/>
        <id>https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night Internet of Everything workshop on June 21, 2017, by Matthew J.
Harmon frames the cybersecurity challenges posed by a rapidly expanding
landscape of interconnected devices and emphasizes why smart often means
exploitable.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;legal-hurdles&quot;&gt;Legal Hurdles&lt;&#x2F;h2&gt;
&lt;p&gt;Harmon begins by unpacking the legal hurdles around IoT security research
including reverse-engineering restrictions and patent ambiguities and uses an
analogy to routine maintenance to stress the need for continuous device hygiene.
He then quantifies the IoT explosion (8 billion connections in 2016 per Cisco,
460 million responsive IPs in the Carna botnet census) and surveys Shodans index
of exposed smart endpoints. Drawing on the OWASP IoT Attack Surface model, he
breaks down exploitable vectorsdefault credentials, unencrypted data flows,
firmware backdoors, sensor privacy leaksi and poses probing questions (e.g., Is
your dishwasher a web-server?) to underline the urgency of visibility and risk
awareness.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;hands-on&quot;&gt;Hands-On&lt;&#x2F;h2&gt;
&lt;p&gt;In the hands-on segment, participants build a known state monitoring stack:
deploying Security Onion for network visibility; integrating Darkstat and ntopng
for passive traffic analysis; and using Bro for protocol inspection, alongside
OSSEC and Sysmon for host telemetry. Harmon extends the lab with DCIM&#x2F;IPAM via
NetBox and leverages MITREs Cyber Analytics Repository (CAR) and ATT&amp;amp;CK
frameworks to detect lateral movement and prune low-hanging IoT risks. Through
systematic enumeration of devices, data stores, and normal traffic baselines,
the workshop demonstrates how comprehensive visibility transforms an
overwhelming IoT attack surface into manageable, proactive security controls.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57925_2017-06-21_MJH_Internet_of_Everything-SANS.pdf&quot;&gt;SANS @ Night: Internet of Everything
Workshop&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
