Friay 30 September 2022, 10:00 - 10:30
Gabriela Nicolao (Deloitte)
Santiago Abastante (Deloitte)
Lapsus$, or as some of us know it, leaks.direct, is a cybercriminal group known for generating a lot of noise between the end of 2021 and the beginning of 2022, having compromised large global companies.
From our incident response team we had the opportunity to participate in six incidents related to Lapsus$, which gave us a global perspective on the actor and allowed us to generate intelligence based on its infrastructure, means of operation and... the actor's mistakes.
Since the actors behind Lapsus$ are people, and people make mistakes, we were able to take advantage of their mistakes to, for example, take ownership of the repository server used by the threat actors, thus having internal visibility of group actions. Nevertheless, this does not mean that they were relentless when it came to attacking.
We will show you how far a threat actor can go to be root within an AWS environment and... nuke it? Or how a Jenkins exposed to the internet can lead to absolute devastation.
Join us for this talk if you are interested in experiencing how an incident response team deals with these types of threats and survives to tell the tale.
Gabriela Nicolao Gabriela has a degree in information systems engineering from the Universidad Tecnológica Nacional (UTN) and a postgraduate degree in cryptography and teleinformatics security specialization from Escuela Superior Técnica of Facultad del Ejercito in Argentina. She works at Deloitte in the cyber threat intelligence area. Her tasks include malware analysis, network traffic analysis, incident response and indicators of compromise (IoC) hunting. She has nine years of experience in the security field. She is also a teacher at UTN.
|
|
Santiago Abastante Santiago is an ex-police officer and a cybersecurity specialist with 10+years of IT experience. During the course of his career, Santiago has worn many different hats, being able to intervene in incidents of multiple magnitudes in both the private and public sector, from bank robberies to cybersecurity breaches to confidential information leaks, leading multidisciplinary teams, learning and improving our security posture with strategic focus. |