This presentation forms part of the CTA's Threat Intelligence Practitioners' Summit
Thursday 29 September 2022, 14:30 - 15:00
Michael Gorelik (Morphisec)
Cybersecurity challenges: Dynamic detection of malicious shellcode using current indicators of compromise (IOCs) and threat hunting tools presents a challenge. We will ask the following questions and will provide a solution to those questions:
Cybersecurity solution: Extended dynamic threat intelligence for runtime detection. We will present an innovative threat intelligence approach that augments existing STIX and TAXI formats by leveraging advanced technologies. Security vendors that implement runtime detection mechanisms will be able optimize their shellcode detection techniques while reducing the impact on usability. (We will present detailed examples for such structures.)
During this presentation we will elaborate on the runtime detection paradigm and provide examples of failed and successful attempts implemented by security vendors and organizations. We will also identify possible IOCs that can represent Cobalt and Metasploit backdoors, as well as Conti ransomware.
Michael Gorelik Michael Gorelik is CTO of Morphisec, where he leads the malware research operation and sets technology strategy. He has extensive experience leading diverse cybersecurity software development projects and experience in the software industry in general. Prior to Morphisec, Michael was the VP R&D at MotionLogic GmbH and before that served in senior leadership positions at Deutsche Telekom Labs. Michael has extensive experience as a red teamer, reverse engineer and contributor to the MITRE CVE database. He has worked extensively with the FBI and US Department of Homeland Security on countering global cybercrime. Michael is a noted speaker, having presented at multiple industry conferences, such as SANS, BSides and RSA. Michael holds B.Sc. and M.Sc. degrees from the Computer Science department at Ben-Gurion University, focusing on synchronization in different OS architectures. He also jointly holds seven patents in the IT space. |