ISC StormCast for Tuesday, January 12th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 January 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, January 12, 2021 edition of the Sandstone at Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.8 | And this week I'm actually teaching the SEC 5-22 defending web application class in Washington, D.C. |
| 0:20.2 | At least, well, that's sort of the virtual location |
| 0:23.5 | of our Cloud Defender event this week. |
| 0:29.2 | Rob today completed his three-part series about how to use the NIST National Vulnerability |
| 0:36.6 | database with automated PowerShell tools in order |
| 0:40.1 | to augment and assist with your vulnerability management program. |
| 0:46.4 | Interesting PowerShell script that he came up with in the end, and it is available on GitHub. |
| 0:54.0 | And Microsoft released a new version of the SIS Internals tool |
| 0:58.0 | with two significant updates to SysMON and Process Monitor. |
| 1:04.0 | SISMON added additional events that will alert you |
| 1:08.0 | if a mapped image file in memory doesn't match the on-disc image file. |
| 1:13.6 | Also, if the image is locked for exclusive access, which is of course a common sign that process |
| 1:22.6 | hollowing does take place. |
| 1:24.6 | That's where an attacker essentially modifies an image of a process in memory |
| 1:29.5 | in order to inject malicious code. And process monitor will now also monitor the rec safe key, |
| 1:37.5 | reg load key, and rec restore key APIs. In particular, the Sysmon update sounds really interesting and would be interesting |
| 1:46.0 | to hear from you if that works for you, if you detected anything, if there are any false |
| 1:51.6 | positive issues with this new feature. Based on that I in the past have gotten quite a few |
| 1:58.0 | requests for how to install our honeypot behind ubiquity |
| 2:02.1 | perimeter device. I'm assuming that quite a few of you are using ubiquity equipment, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

