Defensive perspective
From the defender's perspective, I will demonstrate a few different incident response scenarios with an emphasis on properly scoping the full attack. The ideal outcome is expelling the attacker in one swift response, forcing them to come to the environment all over again from the outside (don't forget that some attackers are extremely persistent). We will also show examples of how this can go wrong, revealing the defender's hand (knowledge of the incident) and allowing the attacker to remain in the environment. Scoping an environment can not only be difficult, it can be extremely costly if external consultants are involved, especially if you don't succeed in fully evicting the attacker. When done wrong, some organizations actually run out of a security budget and can't continue to bring consultants in again for the same incident they failed to remediate the first time. That's the worst-case scenario; in the best-case scenario, the...