Threat Vector by Unit 42 cover image

Threat Vector by Unit 42

Mastering IR Sniping A Deliberate Approach to Cybersecurity Investigations with Chris Brewer

Sep 7, 2023
In this episode, Chris Brewer, Director at Unit 42, shares insights on "IR Sniping," a targeted approach in cybersecurity investigations. He discusses guiding principles, the benefits of IR sniping, and the importance of analyzing data. Tune in for expert strategies to enhance your incident response tactics!
05:21

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • IR sniping is a deliberate and targeted methodology that accelerates cybersecurity investigations by focusing on four key questions: what data was taken, is the attacker still present, what is the lateral movement, and how did they gain access?
  • IR sniping assigns workstream leads to specific questions, repeats investigative steps, and prioritizes important information, resulting in quicker resolutions and improved quality control in incident response investigations within 72 hours.

Deep dives

IR sniping: A targeted and deliberate approach to investigations

IR sniping is a methodology that involves taking a targeted and deliberate approach to investigations, particularly in cases with large numbers of hosts. The guiding principles of this methodology, such as the LOKARED exchange principle and Occam's razor, emphasize the importance of leaving traces behind during criminal activity and seeking the simplest explanation. IR sniping helps investigators achieve better and faster results by focusing on four key questions: what data was taken, is the attacker still present, what is the lateral movement, and how did they gain access? This approach allows for efficient allocation of resources and effective analysis of data, resulting in quicker resolutions.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode