Black Hills Information Security 09月29日
黑山信息安全破解端点安全研讨会
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文介绍了黑山信息安全(BHIS)如何绕过端点安全保护,并讨论了防御深度和供应商夸大其词的问题。



























It is another year for the Sacred Cash Cow Tipping Webcast. For those of you who are new to our email list within the past year, this is a webcast where we cover the various tools and techniques that Black Hills Information Security (BHIS) uses to bypass endpoint security protections. The point of this webcast is not so much to teach people how to bypass these products, but rather to show that they can be bypassed. Hopefully, this leads to some conversations about defense-in-depth and how many vendors exaggerate their capabilities.



We also discuss how simply writing signatures for specific strains of malware is a waste of time. Well, I mean, it has its place. But it is not something that should be the primary cornerstone of your security support structure. 



There is a lot to unpack in this webcast, one of the main things to unpack is why we are still doing it. We are still doing this because it is still necessary. We still have vendors and CISOs perpetuating the myth that a security product can protect you from all attacks. This is an oversimplification, and it needs to be exterminated like a termite or a cockroach. 



In past years we have had vendors threaten to sue… and some cooler vendors send us beer.  



Hopefully, this year ends in beer.



Join the BHIS Community Discord: https://discord.gg/bhis



0:00:00​ – PreShow Banter™ — We Love You 3000



0:02:56​ – PreShow Banter™ — SolarWinds Forever



0:07:26​ – PreShow Banter™ — Watching Bitcoins Being Mined



0:08:53​ – PreShow Banter™ — TeacherCoin™



0:11:12​ – PreShow Banter™ — Babies’ Toys For Your Hands



0:15:45​ – FEATURE PRESENTATION: Sacred Cash Cow Tipping 2021



0:21:28​ – Ralph May: Due Diligence



0:25:42​ – Ralph May: ScareCrow



0:32:56​ – Ralph May: RDP



0:35:51​ – Marcello: Sentinel One



<a href="https://www.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

黑山信息安全 端点安全 破解技术 防御深度 供应商夸大
相关文章