We are live, everyone. Thank you for joining me for the Splunk Attack Analyzer demo day. We're going to go through some really cool things here today. First, I'm going to kind of take my time here and let some of the rest of us kind of trickle in. We've still got people joining the webinar here, so we're going to slow it down a little bit, let some of the folks trickle in. We've got a good crowd now. Really excited about today. We're going to go through some really exciting things. I'm going to share a lot with you. Hopefully, you'll have a lot of questions, and we can both learn from each other, and you can learn some of the cool things that Attack Analyzer does that'll help improve your efficiency and your productivity and help you level up your skills as well. While folks are trickling in, I'm just going to kind of go through who I am. I'm Jerald Perry, one of the Senior Technical Marketing Engineers here at Splunk. Attack Analyzer is one of my core products. That's why, as you can see, I'm very fired up about it, as well as a few other technologies. I'm overall fired up about our portfolio as well. I can't thank you guys enough for joining, being willing to sit and spend an hour of your time with us, go through some things, means a lot to us. We're going to make sure that you get a bang for your buck today. As we get into this, I want to encourage folks, if you have questions, don't be afraid to chime into your question box. Put any questions in. There's no such thing as a bad question or a, pardon my language, but a stupid question. There's no such thing here. If you have a question, please chime in. We'll get back to you, if not during the webinar, at the Q&A at the very end. Don't hesitate to do that. Let's go ahead and jump right into this. We're going to go ahead and start here by just kind of giving you an idea of Attack Analyzer. We're going to go through a couple of slides before we really jump and dive deep into this demonstration. We're going to talk about some things and some of the challenges that Attack Analyzer helps, that kind of helps you solve out there. Some of you may be facing those challenges now, or some of you guys may be planning security operations center and things like that in the future. Whether you're dealing with it now or you're planning to move forward into this space, this is all great information to know. Let's go ahead and look at this slide here. One of the challenges with security operations is struggling to understand and analyze your threats. As you guys know, we are an ever-evolving attack surface. Your attack surface grows, it expands, it retracts with auto scaling and things like that. It's constantly moving. The velocity of attacks, credential phishing, and malware, things like that, are always moving on the fly. As we're in this dynamic space with cloud, things of that nature, we have very limited visibility and context to this because it's always changing. What that does is that puts us in a lot of different spaces, and it causes a lack of analyst bandwidth and being able to respond to everything. That's very important to think about as we move through this slide deck. With all that that we just talked about, throw into the fact that attacks are becoming a lot more complex. What attackers are doing, as you can see in the slide, is they're putting in a lot of hoops to help evade detection and analysis, as we like to call obfuscation. There's multiple different things, whether it's bloated executables, that often expands your attack surface, builds in more code, slows down systems, your CAPTCHAs, QR codes. That's another big topic that we're going to talk about in detail as we go through this demo and this webinar. We're going to talk about QR codes and how they are used to kind of lure people away from traditional defense mechanisms of your corporate environment, try to lure you over onto your mobile devices. That takes us over to the lure pages. We talk about redirection. We talk about different custom malwares, different compiled zips, just different things, password-protected files. That's another very important thing that we'll talk about. You'll learn a lot more about that today during this presentation as well. Again, a lot of different evasion methods and detections, and that's where Attack Analyzer really shines. That's one of the things that I'm really excited about to get into this with you, and we'll really talk about that. What is needed? It's often, when you look at the statistics and the different security platforms out there, some of us, those of us that deal with this on a day-to-day basis, are more than well aware that it probably takes a multitude of different tools and technologies to be able to manage an environment like that. On estimate, it says about six different tools are used on average to investigate an alert. What we want to do here is we want to take that manual analysis out of threats. We want to improve the standards for investigation while still removing manual analysis. That comes with being able to do what a SOC analyst would do or what a human would do. We want to provide thorough investigations with the rapid response without sacrificing the integrity and quality of the investigation. That's very important here. We'll dive deeper into that. But first, let's talk about some of the traditional tools and how they address problems. Traditional tools typically come at every layer, whether it's your next-gen firewall, your security email gateway. There's multiple endpoint detection response. There's a multitude of tools out there that receive information, emails, files, URLs, things of that nature. That goes through your prevention layer. From there, it goes to your analysts. That is where we kind of hit the choke point. That's where things start to become throttled. That is where the manual analysis must take place. That is where sandboxes, traditional analysis tools, things of that nature, when we go back to that obfuscation slide that we talked about, that is where some of those can become kind of challenged to keep up with the complex attack chains. It'll be really cool for me to demonstrate that to you guys as we go into this. As these threats go through this manual analysis and go through these traditional analysis tools, threats often go undetected. That leaves your dwell time to increase substantially, which is not what we want because a good attacker does not want to be discovered. The longer an attacker can stay in your network, the better for them. There are a lot of different challenges that come with that that we'll be able to talk about here. The cost of inaction is, you know, that's just something that within your environment, there's going to be a cost for downtime. There's going to be a cost for compromise, whether it's ransomware, whether it's an attacker gaining access to a critical system. There's going to be a cost for that. The average time dedicated to resolving investigations is around three hours when you kind of calculate that. What we want to do is eliminate these longer dwell times. We want to eliminate the struggles to keep up with the pivots between tools because that is a big deal when you're dealing with your server logs, you're dealing with your endpoint detection, you're dealing with your intrusion prevention, your next-gen firewalls, and going back and forth between all these tools. Even if you do have a tool that you can put data into one location, is it providing the context for you? A lot of resource constraints there trying to keep up with that. How do we solve this? Attack Analyzer does a great job of that because we come with a very new and needed, a much-needed new approach to solving this. That is to keep you from having to play security tool DJ with all of your different platforms to solve problems. That is where Attack Analyzer comes into play. We automate threat analysis of suspected malware and credential phishing. We take that manual work out of the threat analysis. We do not compromise the quality of the work by doing that because we are able to ask, what would a SOC analyst do, or what would a human do at that time? You gain consistent, comprehensive, high-quality threat analysis during this process, which is very important. We provide intelligent automation for end-to-end threat analysis, provide automated responses when you integrate into that core Splunk ecosystem. It just becomes extremely powerful what it brings to the table and a lot of the headache that it eliminates. It frees you up to go out and do some of the more beneficial things to your environment and bring more value to yourself and for your organization. Again, we talked about the hoops. These hoops are important because you're going to see real time how Attack Analyzer helps you jump through these hoops, how we do the work for you. We do the CAPTCHAs for you, the password protection. We avoid the lower pages, the QR codes, and we're able to process each step of the complex attack chain. This is where traditional methods and sandboxes and malware analysis tools fall short because attack chains are very complex. With these evasion tactics, they're designed to do that. They are designed to take you out of the flow of your traditional security tools, and they're designed to be read as benign. Keep that in mind too. We'll demonstrate how Attack Analyzer helps you overcome all of these methods without you having to do it manually yourself. With Attack Analyzer, we'll help you enhance your security architecture. We do this by providing automated threat analysis. Here you look at your perimeter protections. Each environment may vary. Some environments have your secure email gateways, the integrated secure email in the cloud, your EDR and AV, your SWIGs, your proxy SWIG, a secure web gateway for those who may not be aware. You're going to have your traditional methods at the perimeter. One thing I want you to know is there's multiple ways to submit data into Attack Analyzer, and we'll talk about that, whether it's email, whether it's through SOAR. There's multiple ways to do that, and we'll dig into that when we first start the demo. Then you have your secondary defenses, your threat detection, different vigilant employees, alerts, and threat hunting. You have all these different things and different methods for all this data to come in. This is where Attack Analyzer comes into play. We help you solve out the false negatives. We help you solve out the false positives. We help you square away what is actually malware, what is actually phishing, what is malware, what is spam. Attack Analyzer provides that additional level of defense for your organization. Now that we've went through that, now it's time to really step into this demo, and we'll talk about, and I'll demonstrate all the things that we've talked about. I see there may be some questions coming in. Let me just take a quick look if there is. We've got a lot of attendees here again. Thank you for everyone joining. This is pretty awesome. I'm very excited. We've got a question here I want to answer before we slide into this demo here. It says, I'm not 100% sure. It says, okay, probably why use the automation in this tool over using a SOAR tool? Can they work in tandem with each other? Absolutely. Actually, towards the end of this demo, I will actually show you kind of within Enterprise 8.0, some of the integrations in terms of SOAR and Attack Analyzer. You can actually do both. That's a great question. There's no dumb questions, but that is a very fantastic question. I'm going to go ahead and mark that as answered here. Awesome. Fantastic. I'm going to go ahead and share my screen here, and now we will jump back into this demo. We will go ahead and jump, dive right into this live demonstration, and we're going to have this is where the fun starts. Okay, so I've got my screen shared. If you have any questions and you can't see the screen, please let us know in the chat. We'll work with you on that, but this should be squared away here. You should see my entire screen. What you're looking at here is the homepage of Attack Analyzer. When you first log in, this is what you see. You see all of these different submissions here within Attack Analyzer. You have multiple methods of submitting your data. You have API submissions. You have email submissions. You have API via SOAR. You can submit data directly from SOAR, which can grab your Attack Analyzer, submit, I mean, your malicious payload or content and submit it to Attack Analyzer for you. It can be set up with Enterprise Security and SOAR to grab that for you. Attack Analyzer does a multitude of automation itself. There are multiple things that you can do and multiple approaches, and there's a lot of flexibility as well. One of the things I do like to point out is that if you currently have email as email augmentation is a very, very popular way of using Attack Analyzer. One of the things I want to point out before we really get into this is Attack Analyzer is not going to replace your email gateway. I want to make sure that we kind of get that clear before we really dive into this. If you're using it to augment your email gateway, that's the best approach. There's going to be a lot of emails that come through, and some emails will get through there. People will have some questions and often have a button that says, "Hey, if something looks familiar, click this button." That is where, in terms of email protection, that is where Attack Analyzer excels because you have an email gateway. If something gets through that is suspicious, why would you want to submit it back to the platform that just let it through? We provide a different method with more advanced analytics to allow you to take that email and go through it with a fine-toothed comb and go through all the attack chains. Throughout this demo, we're going to take a look at why some of the different traditional methods for malware and phishing and things like that often rule a lot of things benign. Let's go ahead and go through here. We are going to look at a submitted email here for, say, mobile activation. I'm going to click that. I'm going to take a quick drink of water here. Now that we have clicked on the mobile activation email that was submitted to Attack Analyzer, what you're going to see here at the very top is your overall score for this submission here. Attack Analyzer is going to provide you a lot of information just upfront because it's going to, we want to equip you with as much information that you can provide to your managers, your coworkers on shift handoffs, your managers, important people that need to be aware of what's actually taking place, especially if something is very important or critical. We're going to provide you with that information right upfront. Here you can see that on this particular email, the verdict is ruled a phish. There are different verdicts. You can have phish, you can have malware, or you can have spam. Here, the verdict is a phish. We're going to also tell you what the malware family here is. You see that? Here it's Agent Tesla XOR. We're going to tell you what the phish brands are, and we're going to gather that information based on the images that we see in there, the different information that we pull. It's all provided for you in this report here, which is pretty awesome. We're going to go through and just give you the SHA-256 and what type of file, the simple things here. What we're also going to do now, let's go down here and talk about the resources analyzed. This is where we get into the complex attack chains. This is where Attack Analyzer really provides its value for you because Attack Analyzer has the ability to go through the complex attack chains and ask, what would a SOC analyst do? You're going to hear me say that throughout this demo. What would a SOC analyst do, or what would a human do? Attack Analyzer has the ability to do that. Now let's kind of, we're going to walk through this before we really get deep. Here you see the mobile email was submitted for analysis. Someone saw this, or your secure, your SIEM picked this up. Someone saw this and said, "Hey, this is definitely a concern. We need to analyze this." That is picked up. Within this email, there's a PDF file. That PDF file is an attachment within the email. As you can see here, it required some sort of decryption. It was password protected. Attack Analyzer is able to go through this actual email, analyze the contents of the email, decrypt the actual PDF file. From the PDF file, there's two different logins. You have a QR code here that Attack Analyzer is actually able to go through that QR code. We talked about in the beginning, QR codes are a way to evade detection. QR codes are a way to take you away from traditional security methods. QR codes are more so designed to get you on a phone. Think about that. That is very important. Attack Analyzer is able to determine, "Hey, this is a QR code." We are going to look at the QR code and say, "What user agent or what type of device should we actually click this code with so that the attack takes, so it does not evade the attack?" Because device fencing is made to say, "Hey, this is not the type of device we expect it to click this. Do not do anything. Let's just kind of send you to some random web page or some Wikipedia page or something like that to avoid our true intent. Attack Analyzer is able to click this QR code with an actual user agent or device platform so that it activates. From here, go to the true login page, download a zip file, excuse me, download a zip file right here, and then unzip and go into what we call the more traditional sandbox methods here, which is just file analysis. That right there is just in a nutshell what a complex attack chain looks like. Before we go through all these steps one by one, what I want to show you is how Attack Analyzer provides this information for you really fast. If there's a lot of things that you are unaware of or you're not too familiar with, Attack Analyzer is going to teach you. I like to work with tools that kind of educate me as I go. We often think that we know everything, but that's not always the case. Attack Analyzer does a great job of educating you as you go along. When you look at this, you can scroll down and look at all the components of the attack as you go through this. It's really cool, and you can do it one by one. What we're going to do now is we're going to go through the different detection engines here on the left side pane so that you can get a clear understanding of everything. Now let's scroll down. I'm going to go ahead and click this email, which when you click there, if you notice, it'll move that for you. I'm going to click this email here. Now in the initial phase, this email was submitted. We're using the email analyzer engine. The score here itself is only 50. If you look up here, the total score is 100. This is very important when we're talking about complex attack chains. The reason this is important is because Attack Analyzer uses informational detection, and we take all of the different factors and calculate your overall score. That'll be important a little bit later. Now as we go down here and we look at this email, one of the detections here, email contains a suspicious sender and attachment. You can always click Attack Analyzer and gain more information just so you know. You can always click and look further into it if that's what you choose to do. We are going to kind of go through this at a more high level just so we can get through this demo because we could be here for hours. What it's going to do is it's going to take us to this email page. What you see is the actual email. You see the actual email here that is what was submitted and what the user saw as a security analyst. You see the information here. You see an embedded, an attachment of a PDF. You see that there are no actual URLs here. There are no executables here. There are no URLs. What it's trying to do is it's trying to get you to open an attachment and follow these instructions with an activation code. This is important because Attack Analyzer will take that activation code. We look at all the information, use optical character recognition, and we store information throughout the attack chain process, and we can use that information later. That's important as well. Note that. Just looking at this email, it's a PDF file. It's not an executable. There are no links in here. This could be benign when you look at that. Attack Analyzer takes this information. We grab this activation code, and now we go into the actual static doc analysis. That's the next phase. Let's go ahead and pivot here. Now that we've taken this document, this document, first I want to note here, if you look at this area for the mobile login activation PDF, you have no triggers. You have no score. That's because it's encrypted. We're taking the password from here, and now we've decrypted that. When you look down here, now we're at the decryption phase. Excuse me, I just had to clear my throat a little bit. Now we're at the decryption phase. Now we have a score of 90 on this static document. This is where Attack Analyzer starts to do some really cool things here. It starts to go through everything and says, "Hey, this likely Microsoft QR code lure PDF document." We're able to go through the visuals and the information there, and we're able to look and see, is this involved with something else? Was this involved with some sort of phish kit or something like that? QR code URL contains commonly abused TLD, top-level domain. Single PDF URL, zero trigger there. You scroll down, that's just kind of some metadata here, document information. Here, let's take a look at this. Now that the PDF is decrypted, here we have an image. We have wording here, and then we have this QR code. We have an 0365 page here. I'll say it again, QR codes are used to evade detection. The whole premise of an attacker is to evade detection, have a long, I mean, a long lure time as possible so they can look at your information. They're going to pull all of your information into a database that they export out of your environment so that they can then go back and analyze what their next pivot is. These QR codes are designed to do that, which is important. That is where Attack Analyzer is able to say, "Okay, let's go ahead and make sure that we execute this, we scan this QR code with the mobile device." That way, the code built into this does not reject that. When you go down here, you have all your extracted images as well. This is where we're pulling this information. We're gathering all of the data. At the end of this, when you see the summary report, it will all make sense because all of this factors into your overall score. It will all make sense when we get there, but hopefully it makes sense here as well. Now that we've scanned this QR code, which Attack Analyzer has done that for you, we're going to go to the Web Analyzer. Web Analyzer now is, here's where we are in this complex attack chain. We are using our Web Analyzer engine. We are going to give you a lot of great information. We are going to tell you, "Okay, this domain was created at such and such time." Here it says created 22 days ago. We are going to look at some of the Base 64 encoding images. We are going to just provide a lot of different information for you as we are going through this complex attack chain. Before we look at the blurred engine, I want to kind of point out these artifacts here. Attack Analyzer, because malicious domains are often short-lived, by the time a SOC analyst actually gets a chance to really dig deep, sometimes those domains are gone. Attack Analyzer is going to store the actual information for those HTML documents so that you can recreate those and look at those even if the domain is gone. That's just something I just wanted to point out really fast for you. Let's go back here. Notice that this is blurred. This is another obfuscation method. This is another, what we called in the earlier slides, another hoop that is placed to kind of get you to kind of weed out detection, to weed out detection and evade traditional security measures. Attack Analyzer automatically goes through and clicks that for you. We provide the images for both so that you're well aware of each step of this attack chain. Now we get to this location. After Attack Analyzer clicks this to unblur it, we get to this location that pretty much leads you to two different links. One is just press the test button below to validate your Office 365 login, and then it gives you a secondary link if that's not working. You have a score of 40 here, but it all adds up. Now that we've gotten here, Attack Analyzer is able to break this down and go into the second phase of this. That is where it starts to get even deeper because if you look at this, you may have already had multiple different tools that have said, "Hey, nope, no executable. That's benign." This is just a blurry image. There's nothing there. That's benign. This is a QR code. Once you get past that, that's benign. Attack Analyzer keeps going because as a SOC analyst, we're always thinking, "What else is going on? I know there's more to this." That is where Attack Analyzer keeps pushing forward, which is very important. Now that it's unblurred that information, Attack Analyzer is able to go in and say, "Hey, this is a phishing attempt. This form collects passwords." It's going to tell you all of that. It's going to look at these images here down below, and it's going to give you the images as well, but it says, "Hey, this is a phishing attempt. This form collects passwords." We're just going to expand on this. It's going to say, "This Microsoft 0365 background image has been found and observed in other resource kits. This image match is a potential website detected for Microsoft. Non-Microsoft web page claiming to be Microsoft." This is important. It's going to go through all of this information here, and it's going to tell you so much stuff about what's actually taking place. You can always dig deeper by clicking into these. It's going to give you more information, more detail. Again, we always want to educate you as you go along. We want to always level up your skills. We want to free up your time to level up your skills. Just looking at these phases that we've went through, we've went through the first four phases, and Attack Analyzer has overcome so much that without human intervention, it's very difficult to do. Attack Analyzer is able to do that in a short amount of time, keep you rolling forward, and keep your investigation moving forward while you're doing other things to improve your security operations center, your IT department, your overall security posture for your company. Now that Attack Analyzer has been able to do that, it's able to get to this next stage where there's a zip file. This is where we get into where the traditional sandboxes and malware analysis tools operate. This is where Attack Analyzer, without Attack Analyzer, we would have never, more than likely, never have gotten to that point. Now we're going to get into the zip file that was downloaded after all of the steps had taken place. Now we're at this phase. There's a zip file. That zip file is downloaded. It says page hosted on a commonly abused domain. Again, we're providing a lot of just nuggets and Easter eggs as we go through this process for you. File downloaded. Now we have an archive that we're going to extract. We're going to talk about some of the detections and different engines in more detail after we go through this phase here. Here, it triggered some of the ClamAV rules. We utilize ClamAV with a lot of customization to it, but there are three different signatures that picked up here for that file. Now we're here at the executable. This is where the depth of things really gets to, but notice how much and how much effort it took to get to this point. Imagine going through this manually. Imagine sitting in your SOC, getting this alert, having to go through all these steps one by one where Attack Analyzer went through this in a matter of minutes for you. Now we're analyzing. We're at the big boss here, which is the executable. This is like the cream in the middle of an ice cream. We're here. Now we're using our static analysis engine. What we're going to do is we're going to look at, I'm going to go up to the top here. We're going to give you information about this, what the SHA-256 is. We're going to have a lot of different detections here, and we're going to provide you with all of this information. It's very, very informative here. Some of the important things that you'll notice too, we're going to tell you what the malware family is. We talked about that in the beginning, different ClamAV rules that were targeted. Here, here's some really important things that we point out within the sandboxing engines. Now we're in the sandboxing engines. It says that there are attempts to remove evidence of a file being downloaded from the internet. We're going to tell you what that file is. This is basically trying to pull something down, execute something, and then delete it and say, "Hey, I didn't do nothing." That's exactly what this is doing. Attack Analyzer catches that. We look at this here, creates a copy of itself. Something here is creating a copy of itself, executed a process, and injected code into it, probably while unpacking. There is a lot of information that Attack Analyzer is going through. We're just going to look at some of the depth of this just so you can see that. Sniff keystrokes. Bam. That's telling you that it's trying to see what you're doing if it's been executed on your device. It wants to watch you. Installs itself at auto run. That was detected also two different times. Very important. Here, we even go into your registries, harvest information related to emails. Look at this. We even go into your registries, and we tell you exactly what took place. If there was some sort of compromise there and you have to do some cleanup, you know exactly where to look, or you know exactly where to look just to ensure something did not happen otherwise. If someone's having a weird issue and they were able to, they went through a different method, so they bypassed Attack Analyzer. You have some different information that you can use for other investigations that may be similar. There is a lot of data here that you see that Attack Analyzer goes through, created a process from suspicious location. These were all within the confines of the Windows 7 and Windows 10 sandbox that when we get into the traditional sandboxing and malware analysis, that is where our sandboxing comes into play. That is the last step of this portion of the demo and what Attack Analyzer goes through here. Before we go over to some of the advanced features and we look a little bit deeper into the analyst engines and things like that, let me know if you guys have any questions as I prep here to transfer over. Let me check the, let me go back to the starting page. As I prep here to kind of transfer over, let's see. I'll answer a question here as well just to see, just we've got one question. Let's see. How do the majority of users submit content for analysis? Very good question. We covered a little bit of this in the slide deck, but we'll kind of revisit. We're not going to replace your email gateway. If you're using it in a sense of email, we're not going to replace your gateway, but we are going to provide next-level advanced defenses for you to be able to analyze emails that get through your email gateway. You are able to be able to submit, instead of submitting back to your email gateway, you can submit it to us. We will do that for you, whether it's through a unique domain and you build a macro for your email client, that's a possibility. Whether you're using SOAR and you're sending something directly over from Enterprise Security, that's a possibility. There are multiple ways to do it. Hopefully that answers that question. I'll mark that as read. Now what we're going to do as we go to the next portion of this demo, we are going to go ahead and look at some of the advanced features here. We're going to look at some of the detection engines. We're going to look at some of the different things that Attack Analyzer provides to you automatically to help obfuscate detections and to help avoid all the obfuscation and evasion so that it can process all of those attack chains, all the attack chains complexity without your intervention. You can also come here and submit as well manually, and you can interact with different components of it as well on your own. As you see here, you have a choose file location. You can come here and submit things manually. First, as we go through some of these things, let's look at the internet region. Attack Analyzer provides you with different residential IP addresses all throughout the world because some attacks are built to avoid corporate ranges and things of that nature because they want to go to the most vulnerable. Attack Analyzer will automatically go in and select the best possible range to perform the analysis on. If you're interacting manually, you have the ability to go in and select it yourself. Attack Analyzer, through automation, will go through and select the best possible IP ranges for you. We have a multitude of those there, as you can see. Again, just some of the advanced features that Attack Analyzer provides for you. Attack Analyzer is also, when we talk about device fencing, some attacks will know, some attacks will know that, "Hey, if this is a workstation, do not execute it because it could be for multiple reasons. It could be because the EDR on a workstation is going to be a lot stronger than your EDR AV on a mobile device. Or in this case, it wanted you to scan and take you away from traditional security methods. So Attack Analyzer will go through and select the best possible user agent here for the detection that it's analyzing without you having to do anything. But again, we're here manually. If we submitted something manually, you would have the opportunity to go through and submit that and then be able to select it yourself. Now, we looked at the attack. We looked at the password that was in the actual email. One of the questions that we often get is, "What happens if there is a malicious file, but there's no password somewhere?" Attack Analyzer uses different password lists to be able to go in and unpack different payloads. If you're interacting manually, you can also type in your payload here that you want. If you know a password, you can actually punch that in here and be able to use that to extract that information and decrypt that PDF file or whatever it is. In terms of URL engines here, this is part of when we first start this, you have your URL Reputation engines. By default, we're going to send things to Cisco Talos. Another one is Google Safe, and then there's like two or three more on top of that. You have multiple options for your URL engines to submit to. Here's right here, you'll be able to kind of go here and interact with that, whether you're going to turn it on or off. You go into Web Analyzer also, and you have multiple options here within Web Analyzer to be able to unpack what you're doing, go through things with a fine-toothed comb, be able to look at the web pages for what they are, be able to kind of bypass the CAPTCHAs, make determinations on the phishing attempts, things like that. That is what the Web Analyzer is going to do. It is very, very cool. You can interact with that. It is a very powerful tool for that. Just over here, you have the different engines, the archive extraction engines. That's our engine for extracting the archives. It does some password extraction and application that you saw previously in that demo. You saw that in live with what it did with those archives. We have the ClamAV there. What you can see here with the ClamAV is that is our antivirus service that we've baked into Attack Analyzer. We make modifications to it and customize it based on what we want to do. It's not just the plug and play like that you get, but we customize it for our environment. With your Email Analyzer, you'll see that your Email Analyzer is what actually went through and looked at the attachments, looked at images, makes determinations based on the intelligence that we provide, and then it passes that message over to your sandboxes. Here we currently work with Windows 7 and Windows 10 sandboxes. You can dynamically, we dynamically detonate these artifacts and observe the behaviors in these sandboxes. They can be executables, malicious scripts, files, etc. You have a lot of flexibility here with those two sandboxes. You have your Static Doc Analysis, detects the threats delivered via your documents. It analyzes everything for QR codes. That was important earlier. Looks at the URLs, reviews images too using OCR. That is important because we take all that information out. We look at that information, and that helps us put our overall score together of what the threat is, what the score. The higher the score, the higher the risk. Keep that in mind. What next do we have here? We have our Static File Analysis. That's our engine that reviews the malware capabilities of a file, reviews headers on the portable executables, creates hash outputs and things like that. That's Static File Analysis. Just like an engine, some things do more than others. Some things do less than others. Without each component, you're at a disadvantage because an engine needs its smallest part as well as its strongest part, which is typically the motor or the transmission. An engine needs all of that. It's the same thing here with all of the different layers that Attack Analyzer provides. We provide our YARA rules here. We talked a little bit about some like the ClamAV, but the YARA rules are actually some things that you could apply logic on top of our analysis if you're familiar with YARA. If not, there's some information on our website about the Attack Analyzer detection engines that you can go and look at. I'm going to bring that up over here for you guys. You can go here. If you're not familiar with some of this stuff, you can actually go here yourself. You can take a look at some of our detection engines, and we'll provide a lot more information on what we're using here. You can go take a look at some of the optional third-party integrations as well. When we looked at our sandboxes, we're typically going to work with Windows types of files and things like that. However, it's very important to know we can integrate with other types of sandboxes as well. Just because you do not see a Linux sandbox here does not mean that we cannot integrate with the sandbox of your choice and work with that also. Keep that in mind. When we go up here, there are a lot of different options here. Let's go back to the main page. I want to kind of, let's go back to basics, and then let's go back to the actual attack here. There are also the abilities to submit feedback here. You can go through and submit false positives. You can submit false negatives. There are a lot of ways to interact here and things that we can actually improve on. If you run into some situations where, "Hey, this was false," you can go through and interact with that as well. You can download a PDF report here of this entire attack chain that we went through so that you have a report that's a canned report that's made to order. You can sit down and discuss what's taken place, whether it's a shift handoff or whether just a meeting with the overall SOC team. You can go through all that. When we look at that, you see that all of this here was done in seven minutes total, three URLs and five files. There's more. I'm going to kind of go in. I'm going to go ahead and click this Normalized Forensics tab. We're going to look at some of the things here, the detections overall that Attack Analyzer found. We're going to tell you the MITRE ATT&CK frameworks that were used so that you can actually click and go to that page. Again, we're all about educating, helping you level up your skills, helping you get better, helping you provide more value to yourself and to your organization. You can do that by learning from these attacks, from these MITRE ATT&CK techniques here as well. We're going to go through here in the Normalized Forensics tabs. We're going to actually give you a ton of information here, which is really cool. Some of it pertains to net stats. Some of it pertains to doing Whois lookups. You get all that here when you go into Normalized Forensics under these different tabs. For example, we're going to tell you all the hosts that were involved in this attack here. We're going to provide all that for you. You get all that information. We're going to tell you all the connections that were made, what the ports, NetBIOS, port DNS. You're going to see all those different ports as well. All the different HTTPs, the different URLs that were used. We're even going to give you the Whois information for these domains here. That's one of the first things that I'm always doing as I would investigate security incidents is, "Hey, what is this domain? What is that?" We do it for you. It's all in the report. It's all right here for you to go through and look at everything one by one. Let's go within Normalized Forensics. Let's go ahead and let's go to the System tab. We talked about some of the different files and artifacts that Attack Analyzer automatically saves for you. Here's an example of that right here. Attack Analyzer is going to keep receipts for everything. Then it's going to tell you what these processes are too. We talked about the detections with different processes spinning up. You're going to see all of that information here when we go over to the system side of the Normalized Forensics. You're going to see the different registry keys that were attempted to be impacted by this attack. You're going to see all that here. You're going to see the different mutexes. You're going to see all of that information here. It is really powerful, really powerful this information we provide. Let's see here, strings and configs. These are just some of the OCR extracted strings. We're going to tell you what we extracted there. You're going to see some of the verbiage from those images that the QR code took you to. You're going to see some of those images, some of the verbiage from those images here. We provide all that for you so you have it for your reporting. We provide all of these images as well that were used to obfuscate and evade detection throughout this attack chain. Again, no URL, no executable, probably benign. I want you to think about that. No URL, no executable. What are these traditional security tools going to do? They're probably going to say it's more than likely benign. As you see here, here's the other images where it was blurred. Attack Analyzer went through and clicked that for you. It unblurred it so that it can continue its analysis. The two different URLs that respond from that. The file downloads. You're going to see the QR codes and all that, and then the different sandboxes below. Attack Analyzer, as you can see, it provides you with a wealth of information here. I'm just going to stop sharing my screen here. Attack Analyzer provides you with a wealth of information. It keeps you rolling, keeps you doing the things that make you more valuable. If you guys are like me, I love learning new things. I love improving myself. I love getting better as an engineer. One of the reasons I came to technical marketing is because I get to be the engineer that I've always been, but I get to work with people like yourself. We all have this passion of protecting our digital way of life, and Attack Analyzer helps you do that. So now what we are going to do here is what the next steps are. If you would like a personalized demo, reach out to your account team. We can make that happen. We can dive deep into things, talk about a lot of different things within Attack Analyzer, and bring any questions you have to the forefront. Now let's get into the Q&A here. We've got a bunch of questions here. Want to try to keep up, so bear with me. Let me clear my throat. All right, pardon me. I am a year-round allergy guy, so pardon me. We have a question here. In case of a zero-day attack, are you using some intelligence to analyze it? Yes. We are using some different machine learning models and different artificial intelligence methodologies to analyze things as they come in. Zero-day is always going to be challenging, but we're using some different things to try to detect what's taking place. As we piece things together, we are looking at the overall score of what's happening here. That's important to look at. That is one question. Let me go ahead and is Attack Analyzer app free or paid? How to connect it with our Splunk SIEM? Great question. I got so caught up in this that I almost forgot to show you some other cool stuff. Thank you for bringing that up. Who's that? Musa? Alsey. Thanks, buddy. I appreciate that. I got so excited about this. I forgot to show you some things. Here, we're in ES 8.0. ES 8.0 looks very cool. I wanted to show that. Here we're looking at an investigation here of a malicious PowerShell process. Not going to spend too much time here, but I do want to show you some of the interactions here within ES 8.0 and Attack Analyzer. Now let me just go over to, once this comes up, let me just click automation here. Here we're looking at some of the automation here. One of the things here that was done is Attack Analyzer ran some analysis on an actual zip file that was on a URL automatically as a part of the investigation process within Enterprise Security. Absolutely, Attack Analyzer can integrate directly. You can tie your SOAR into it. There's a lot of different custom playbooks. I've ran some things manually as well. Absolutely, Attack Analyzer brings all of this stuff into all of these cool security features into the Splunk ecosystem, and it lets you kind of automate what you're doing. Again, you don't have to play DJ David Guetta and bounce from your SIEM to your Attack Analyzer to your this, to your that. We're bringing all the data from multiple sources all into one location. We're triggering from there. We're using SOAR. We're using Attack Analyzer. You know what? Let me actually bring my screen back so I can show you what I'm talking about. Okay, got that up. Here we are in a malicious PowerShell process here within ES 8.0. Here you see Attack Analyzer has automatically executed and analyzed this zip file from a URL. Let me close that. I hate when it brings up that. Here you'll see also encoded PowerShell analysis when we talk about this. This is probably just from SOAR itself, but I'm clicking this just to point out that we're bringing in Attack Analyzer. It's integrated with the Splunk ecosystem, as you guys can see here. You get a clear understanding that now I don't have to bounce back and forth from security platforms to be able to provide the coverage that I need to and the analysis and investigation that I need to provide. I can do it all within ES 8.0 and get everything that I need right here directly from your queue to your actual create an investigation. If it's configured to detonate automatically, you're going to have all these automated containment here that have taken place here by ES automation the way it's configured in my environment. You'll have all that automatically. Great question there. Let's see here. We've got a lot of awesome questions here. Hopefully, I can keep up with you guys. We've got some really smart folks here. Thanks for joining again. How often will you change on your end when it is a false positive? Great question. We have our threat research team. We're always looking at ways to improve. We're always trying to move the needle and get better. I mean, I think that's with all of us. All of us that are in IT, we're always trying to improve somehow, bring more value. The same goes with Attack Analyzer. We're going to always investigate false positives, false negatives. We're always going to investigate those things. At the same time, we're always improving how we detect things, how we analyze things. It's not just a static thing on our side. It's a continuous evolution of improvement that not only with Attack Analyzer, but with Splunk and Cisco as well. We're always trying to get better. Next question here. Is Attack Analyzer a separate product cost from Splunk or included with all Splunk purchases? Good question. Attack Analyzer is a separate product. Let's kind of clear that there. It is a second product. However, the different, let's go back to the advanced tab, that when we talked about those different URL engines and things like that, like Talos, those things, that's included automatically. Your URL Reputation searches and the things that come here, that's included with Attack Analyzer. Attack Analyzer is a separate product. All right, next question. I wanted to ask who would have access to report emails to Attack Analyzer? If a user would have access, would there be a button? Great question. That would be determined by your team. Again, one of the methods, if you're using it for email augmentation, is Attack Analyzer will have its own email domain and its own email that can be submitted that way. Email can be forwarded, or maybe someone on your team can create a macro that ties in directly to your email client. That way, it could be more customized with a button, so on and so forth. That is determined by you guys and how you guys want to do it, whether you want people to forward something to your SOC team or if you want them to be able to forward it directly to Attack Analyzer. It's all your choice. Let's see here. Do we have anything else? Okay. Let's see. We've got a few more questions here, and we'll close this out here. A lot of great interaction here. Really appreciate you guys for all showing up here. Very important. I'm going to pass that one because I answered it in the demo. But you know what? I'll answer it again. How does Attack Analyzer deal with password-protected files when the email doesn't include a password? Attack Analyzer uses multiple password lists that it goes through and extracts and tries different passwords if the email doesn't contain a password. Of course, if the email contains a password, we're just going to extract that password. We're going to store it as we go through that complex attack chain, and then we're going to use it later. We've got a few more. Hopefully, we can knock a few more questions out. It's almost time to go. I know you guys are busy as well. Appreciate your time. What happens? Okay. Yeah, if you have an email gateway, we talked about that. We're not going to take away your email gateway. We're going to augment that. How do sandboxes avoid detection? That's a great question. We use a custom image to help avoid detection. We try to remove all instances of anything that says we're a VM. We try to remove that from that. We also do things inside of our sandboxes that would mimic real human behavior. Like, hey, maybe there's processes that need to be open so that when a file is executed, because malicious content will look and say, "Hey, there are no processes being opened on this file. This is a sandbox." We try to do things on top of kind of removing any remnants of this being a VM. We try to do things that make it look like this is just a regular person, different executables running to symbolize different documents, things of that nature. There are multiple ways of that. We have one more question here before we bounce. What type of files are supported by Attack Analyzer? In our default deployment, we typically look at Windows environments. However, as I mentioned during the demo, we will integrate with the sandbox of your choice so we can kind of look at different Linux binaries and things like that. If you have a sandbox that you want to use for those, we can integrate with those. We are very flexible. We can work in your environment. If you have some questions and want to get some interaction going, please reach out to the team. That concludes this demo. I really enjoyed the time that you guys all spent. Man, I'd love to spend. If I had another hour, I can sit here and talk this stuff with you guys all day. Hopefully, I'll see some of you guys at RSA. Reach out to me on LinkedIn. We can continue the discussion as well. I can help put you in touch with some resources within our company so you guys can move to the next step of learning about Attack Analyzer if you don't already have an account team. Hey, I like collaborating and networking with like-minded individuals and folks. Hey, don't feel shy to reach out to me on LinkedIn, and we can connect there. That concludes this demo. I'm very grateful for your time. This has been fun being able to show you all of the functionality that Attack Analyzer provides, being able to jump through these hoops for you, being able to free your time up to do the things that improve you, which in turn not only make you happy, but make your organizations happy because you become more effective. Thanks for joining me today, people. It's been fun. Again, reach out to me on LinkedIn and have a fantastic day. Thanks.
Loading workspace