ISC StormCast for Thursday, August 13th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 August 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, August 13th, 2020 edition of the Sand Center at Storm Center's |
| 0:06.2 | Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. |
| 0:13.2 | In diaries today, we have one by Russ, who as usual talks about tools that he lately came across |
| 0:20.6 | and found useful. Now, actually, two tools that he lately came across and found useful. |
| 0:22.3 | Now, actually, two things that he's sort of mixing up here. |
| 0:26.7 | First one is the motor project. |
| 0:29.4 | It looks really interesting in that it does provide standard data sets |
| 0:34.2 | that essentially record what happens during some specific adversarial techniques. |
| 0:41.3 | This is something I often hear people ask for, where, you know, where can I find essentially sort of a packet capture that shows a particular type of attack or other logs related to this. |
| 0:53.3 | And that's exactly what the |
| 0:55.2 | mortar project is doing and not just packet captures but actually you know the |
| 1:01.7 | whole data set from some of these attacks and they sort of came up with their |
| 1:07.2 | standard JSON format to express all the data that they have to offer. |
| 1:13.6 | Now, Russ uses the data from Mordor to actually introduce a tool, and that tool here is Prim. |
| 1:21.6 | I was actually surprised that I didn't come across this tool earlier. |
| 1:26.6 | It really sort of tries to be similar to |
| 1:29.9 | WyrShark, but for large datasets. So Prim can digest multi-gigabyte files, which of course |
| 1:38.9 | Wireshark has problems with, provides some similar functionality, but can also ingest seek logs. |
| 1:48.7 | And then with the combination of having PCAP data and seek logs in one console, also |
| 1:55.1 | having a query language available to query all of those logs and correlate them. |
| 2:01.8 | Looks like a real powerful tool. |
| 2:04.1 | Haven't had a lot of time today to really experiment with the tool, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

