Accenture Cybersecurity Pavilion Theater (CST)

Presentation CST-7: Integrating Host and Network Forensics For Incident Detection, Analysis and Remediation

March 24, 2010

10:20 AM

Prerequisite: None

MJ Staggs

Ph.D.

Presented by AccessData

Leveraging both host-based and network forensics gives you the ability to see the whole picture, which is critical for both proactive and reactive cyber security practices. This presentation will focus on integrating and employing both enterprise-class computer forensics and network forensics across a large organization to identify, analyze and remediate threats. This is a step-by-step illustration of threat identification methodology, forensic analysis and remediation techniques. Attendees will learn best-practice approaches to locating suspicious system processes, creating identifying hash lists, searching for further occurrence of these rogue processes, and ultimately, remediating the threat.