Botconf Author Listing

Kurtis Armour


Last known affiliation: eSentire Inc

Date: 2016-12-02
Preventing File-Based Botnet Persistence and Growth
Kurtis Armour 🗣

Abstract (click to view)

In the current threat landscape, we see most botnets propagating via exploits and file based malware. Anything that touches the disk has the ability to be blocked via access controls on the host. New techniques utilize more than just binaries to execute malicious code which is why there is a need for execution control. The main techniques we see botnets attempting to grow is through malware utilizing javascript payloads, standard binaries, doc macros and powershell payloads. In light of these techniques this talk will cover methods for implementing appropriate application whitelists and configuration changes that make it easier for security administrators / security professionals to protect and maintain a secure environment. In addition to block rules and best practices the presentation will go over audit based policies that can be implemented.

Slides Icon
PDF
Video
Date: 2015-12-03
Slides Icon
PDF
Date: 2015-12-03
Slides Icon
PDF
Scroll to Top