3min chapter

Detection: Challenging Paradigms cover image

Episode 27: Roberto Rodriguez

Detection: Challenging Paradigms

CHAPTER

The Importance of Client Side Triage in Kerbros Attacks

Roberto: A lot of these kerbros based things, but like I really in order to identify like 4768 So the events for um a tgt or a tgs for 487 c9 doesn't tell me much. Is there a way to actually tie that to whatever the client was and in this case that would be between two remote hosts and two In on those two different processes? He says detection should focus on the server side triage should help fill in the blinks to go to the client side To help define those malicious and non malicious.

00:00

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode