Top Banner
SECURE YOUR ENTERPRISE Microsoft Advanced Threat Analytics
15

Angriffe durch „Advanced Threat Analytics“ erkennen

Apr 16, 2017

Download

Technology

SBA-Research
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Angriffe durch „Advanced Threat Analytics“ erkennen

SECURE YOUR ENTERPRISE

Microsoft Advanced Threat Analytics

Page 2: Angriffe durch „Advanced Threat Analytics“ erkennen

WHAT IS CYBERCRIME?

2016 - SBA Research gGmbH

Page 3: Angriffe durch „Advanced Threat Analytics“ erkennen

Cybercrime is…

2016 - SBA Research gGmbH

…Money

€ 57 Billion

Damage due to cybercrime in the EU

10.000

Criminal complaints / year in Austria

$ 500 BillionEstimated cybercrime damage worldwide

Page 4: Angriffe durch „Advanced Threat Analytics“ erkennen

Cybercrime is…

2016 - SBA Research gGmbH

…Business

Page 5: Angriffe durch „Advanced Threat Analytics“ erkennen

Cybercrime is…

2016 - SBA Research gGmbH

…Sophisticated

Source: Mandiant M-Trends Report 2016

Page 6: Angriffe durch „Advanced Threat Analytics“ erkennen

ADVANCED ATTACKS NEED ADVANCED DEFENSES

Microsoft Advanced Threat Analytics (ATA)

2016 - SBA Research gGmbH

Page 7: Angriffe durch „Advanced Threat Analytics“ erkennen

Threat Analytics in a Nutshell

2016 - SBA Research gGmbH

Page 8: Angriffe durch „Advanced Threat Analytics“ erkennen

Threat Analytics detects…

Page 9: Angriffe durch „Advanced Threat Analytics“ erkennen

How it works

2016 - SBA Research gGmbH

Page 10: Angriffe durch „Advanced Threat Analytics“ erkennen

Reconnaissance

2016 - SBA Research gGmbH

Page 11: Angriffe durch „Advanced Threat Analytics“ erkennen

Password Guessing

2016 - SBA Research gGmbH

Page 12: Angriffe durch „Advanced Threat Analytics“ erkennen

The Archenemy of Windows

Pass-the-Hash

• Attacker uses stolen password hash to target clients• Search until higher privilged account is found• Compromise other systems or whole infrastructure

2016 - SBA Research gGmbH

Page 13: Angriffe durch „Advanced Threat Analytics“ erkennen

Kerberos Pass-the-Ticket

2016 - SBA Research gGmbH

Page 14: Angriffe durch „Advanced Threat Analytics“ erkennen

2016 - SBA Research gGmbH

DEMOS

Detecting Zone Transfers, Failed OWA Logins,and Pass-The-Ticket Attacks

Page 15: Angriffe durch „Advanced Threat Analytics“ erkennen

Andreas Tomek

SBA Research gGmbHFavoritenstraße 16, 1040 Wien+43 699 [email protected]