Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

ARTHIR - ATT&CK Remote Threat Hunting Incident Response Windows Tool

BasisTech via YouTube

Overview

Explore the capabilities of ARTHIR, a modular framework for remote threat hunting and incident response, in this conference talk from OSDFCon 2021. Learn how to leverage PowerShell and Windows Remote Management to perform compromise assessments, configuration, containment, and other security activities across multiple target systems. Discover how ARTHIR improves upon the Kansa tool, offering enhanced functionality for remotely executing binaries and retrieving output. Understand the framework's integration with the MITRE ATT&CK Matrix, allowing users to map modules to specific tactics and techniques. Gain insights into the open-source nature of ARTHIR, including its GitHub repository, SLACK community, and opportunities for contribution. Explore the included modules, such as original Kansa and LOG-MD free edition components, and learn how to create custom modules. Presented by Michael Gough, a malware archaeologist and incident responder, this talk provides valuable information for blue team defenders and security professionals seeking to enhance their remote threat hunting capabilities.

Syllabus

ARTHIR: ATT&CK Remote Threat Hunting Incident Response Windows Tool by Michael Gough [OSDFCon 2021]

Taught by

BasisTech

Reviews

Start your review of ARTHIR - ATT&CK Remote Threat Hunting Incident Response Windows Tool

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.