Angriffe durch „Advanced Threat Analytics“ erkennen

15
SECURE YOUR ENTERPRISE Microsoft Advanced Threat Analytics

Transcript of Angriffe durch „Advanced Threat Analytics“ erkennen

Page 1: Angriffe durch „Advanced Threat Analytics“ erkennen

SECURE YOUR ENTERPRISE

Microsoft Advanced Threat Analytics

Page 2: Angriffe durch „Advanced Threat Analytics“ erkennen

WHAT IS CYBERCRIME?

2016 - SBA Research gGmbH

Page 3: Angriffe durch „Advanced Threat Analytics“ erkennen

Cybercrime is…

2016 - SBA Research gGmbH

…Money

€ 57 Billion

Damage due to cybercrime in the EU

10.000

Criminal complaints / year in Austria

$ 500 BillionEstimated cybercrime damage worldwide

Page 4: Angriffe durch „Advanced Threat Analytics“ erkennen

Cybercrime is…

2016 - SBA Research gGmbH

…Business

Page 5: Angriffe durch „Advanced Threat Analytics“ erkennen

Cybercrime is…

2016 - SBA Research gGmbH

…Sophisticated

Source: Mandiant M-Trends Report 2016

Page 6: Angriffe durch „Advanced Threat Analytics“ erkennen

ADVANCED ATTACKS NEED ADVANCED DEFENSES

Microsoft Advanced Threat Analytics (ATA)

2016 - SBA Research gGmbH

Page 7: Angriffe durch „Advanced Threat Analytics“ erkennen

Threat Analytics in a Nutshell

2016 - SBA Research gGmbH

Page 8: Angriffe durch „Advanced Threat Analytics“ erkennen

Threat Analytics detects…

Page 9: Angriffe durch „Advanced Threat Analytics“ erkennen

How it works

2016 - SBA Research gGmbH

Page 10: Angriffe durch „Advanced Threat Analytics“ erkennen

Reconnaissance

2016 - SBA Research gGmbH

Page 11: Angriffe durch „Advanced Threat Analytics“ erkennen

Password Guessing

2016 - SBA Research gGmbH

Page 12: Angriffe durch „Advanced Threat Analytics“ erkennen

The Archenemy of Windows

Pass-the-Hash

• Attacker uses stolen password hash to target clients• Search until higher privilged account is found• Compromise other systems or whole infrastructure

2016 - SBA Research gGmbH

Page 13: Angriffe durch „Advanced Threat Analytics“ erkennen

Kerberos Pass-the-Ticket

2016 - SBA Research gGmbH

Page 14: Angriffe durch „Advanced Threat Analytics“ erkennen

2016 - SBA Research gGmbH

DEMOS

Detecting Zone Transfers, Failed OWA Logins,and Pass-The-Ticket Attacks

Page 15: Angriffe durch „Advanced Threat Analytics“ erkennen

Andreas Tomek

SBA Research gGmbHFavoritenstraße 16, 1040 Wien+43 699 [email protected]