ISC StormCast for Friday, December 9th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 December 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, December 9th, 2020 edition of the Sands and the Storm Center's Stormcast. |
| 0:08.4 | My name is Johannes Ulrich and today I'm recording from San Francisco, California. |
| 0:14.4 | Rob's diary today looks for a difference, not the logs that you actually have, but the logs that you are missing. |
| 0:22.7 | The incident that Rob is talking about is an outage in a firewall, and well, the challenge here was |
| 0:29.7 | figuring out basically how much logs are we missing, when did the outage start, when did the end, |
| 0:36.8 | basically, when was there no logging |
| 0:39.1 | from that particular device. Part of the challenge was the volume of logs, of course, |
| 0:44.4 | that you had to deal with. So what better than to create a little script in order to identify |
| 0:50.9 | the gap in the logs and also identify how long it lasted. |
| 0:56.8 | Rob is going over this particular problem and then presenting the little script that he ended up using |
| 1:01.1 | that worked in this particular case to nicely identify the missed time gap and also give them hints |
| 1:09.4 | about what actually happened here. |
| 1:12.6 | And the Google Threat Analysis Team has an interesting blog post with details regarding an |
| 1:19.7 | Internet Explorer Saturday that was used in late October. |
| 1:25.9 | In late October, due to overcrowding at an outdoor Halloween event, |
| 1:31.3 | a large number of people were actually killed and injured, |
| 1:35.5 | and this particular malicious work document used this incident as a lure |
| 1:40.7 | in order to trick people into opening the document, |
| 1:46.8 | which then rendered HTML, |
| 1:54.4 | and well, HTML in office is rendered using Internet Explorer, which then triggered this at the time unknown vulnerability. Google reported this vulnerability to Microsoft and Microsoft fixed it pretty quickly |
| 2:03.3 | in the November update. So more details now about the vulnerability and also about this particular |
| 2:11.3 | malicious document and how it worked from Google's threat analysis group. And don't have the skills to write your own malware, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

