ISC StormCast for Friday, January 13th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 January 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 13th, 2017 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:12.1 | You may have run into this where you had a compromise system, but really the system wasn't configured with any kind of central logging and well not really configured much for security at |
| 0:24.0 | all so how do you analyze an event like this well in the windows world you have a pretty interesting |
| 0:30.0 | tool as mark points out the system resource utilization monitor problem with that was well |
| 0:37.2 | the file it leaves with all the |
| 0:39.3 | information. There wasn't really a convenient way to access the data short of buying the fairly |
| 0:45.9 | expensive NK's product. To help with that, Mark wrote a little program that will dump the information |
| 0:53.9 | from this file into an Excel spreadsheet |
| 0:56.8 | and then will allow you to review it. |
| 1:00.1 | You'll get a lot of details about which programs first started and who started them |
| 1:05.1 | and lots of context around that. |
| 1:07.4 | And of course the tool is available for free. |
| 1:10.1 | Mark has a GitHub repository |
| 1:12.5 | from which you can download it. And Docker released a security announcement and with that |
| 1:18.8 | an update to Docker version 1.12.6. This update fixes a privilege escalation vulnerability |
| 1:27.0 | that could allow an attacker to escape out of a container. |
| 1:32.5 | Now, usually previous escalation vulnerabilities aren't really all that super critical, |
| 1:37.2 | but in this particular case, because Docker is often used to isolate untrusted processes, |
| 1:43.8 | it's probably something that you would like to |
| 1:46.3 | address rather quickly. And then we have yet another reminder how important it is to keep track |
| 1:52.7 | of your DNS configuration. In this latest example, the problem was that a domain that was used by |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

