Per Scholas/FOUR18 Cohort Threat Briefing on Nation State Campaign Capstone
Per Scholas and FOUR18 Intelligence joined forces to give graduates the opportunity to gain hands-on experience as SOC Analysts. We learned various hands-on techniques to analyze Splunk logs to search for anomalies and IOCs. We learned how to determine if a URL is malicious or not. And best of all, we learned to safely detonate and analyze the malware itself. This all culminates into a Capstone. I had the pleasure of being the team lead and the following is the briefing of how we used DEF3NSE- which supplies real-time threat data- and investigative tools to analyze potentially malicious URLs. Our findings of the investigation into a suspicious URL and its payload, and the history of an IP address led to a connection to the Amadey Botnet.
Here is a clip from our Q&A.
Thanks for watching!