ISC StormCast for Friday, June 18th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 June 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, June 18th, 2021 edition of the Sandcented Storm Center's Stormcast. |
| 0:07.6 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.1 | In today's diary by Daniel, you'll learn how to do network forensics in Microsoft Asia. |
| 0:20.1 | The trickier is, of course, that unlike in an on-premise |
| 0:23.5 | network, you don't really have sort of access to switches and you aren't really able to |
| 0:29.2 | deploy span ports. But Microsoft has a couple of different options for you. First of all, |
| 0:35.5 | there's network watcher. Network Watcher actually delivers |
| 0:38.9 | full P-Caps, but only five hours at a time, and then you have to restart this feature. |
| 0:47.6 | The second option is flow logs. Flowlogs or NetFlow is of course always great to look for anomalies |
| 0:54.0 | or search for indicators of compromise if you're into that. |
| 0:59.3 | The problem, of course, is no payload. |
| 1:02.0 | On the other hand, not that hard to throw net flow logs into some kind of log management system like Elasticsearch or Splunk, as Daniel points out. And on Friday, |
| 1:14.3 | so by the time you listen to this, it may be available. Daniel will post a second diary talking |
| 1:20.7 | about Asia Minor Insights and how to use it to keep track of your network traffic. |
| 1:28.8 | And customers of Ledger, a company that is making hardware cryptocurrency wallets, |
| 1:35.4 | are apparently being targeted by some relatively sophisticated scams. |
| 1:40.4 | July last year, Ledger suffered a preach, and as part of this preach, about a quarter million |
| 1:46.2 | different customer records were leaked. In December of last year, these customer records were |
| 1:54.4 | actually also made public, and since then, there was a number of attempts to take advantage of these customers. |
| 2:03.4 | Now, note that the breach did not really affect the security of the existing ledger wallets. |
| 2:10.1 | The data did include personal details like names, mailing addresses, and the like of these customers. |
| 2:16.4 | In the latest scam, customers from this breach are receiving what looks like a modified or tampered |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

