http://www.sans.org/event/dfir-summit-2013
AGENDA PDF DOWNLOAD
Tuesday, July 9, 2013 | ||
Time | Room 1 | Room 2 |
7:00am - 8:00am | Registration | Networking Breakfast Presented By | |
8:00am - 8:10am | Welcome and Introduction to the 2013 Digital Forensics and Incident Response Summit
| |
8:10am - 9:10am | Digital Forensics and Incident Response Summit - Keynote Address - TBA | |
| 9:10am —9:20am | Networking Break | |
| 9:20am-10:20am | Title: File system journaling forensics theory, procedures and analysis impacts
| Title: Mining for Evil
|
| 10:20am - 10:40am | Networking Break | |
| 10:40am — 11:40am | Title: The "Trusted" Insider Theft of Intellectual Property and Trade Secrets
| Title: Volatile IOCs for Fast Incident Response
|
| 11:40am-12:40pm | Lunch & Learn Presented By | |
| 12:40pm —1:40 pm | Title: Johnny AppCompatCache: the Ring of Malware
| Title — iOS Device Forensics on a Budget
|
| 1:40pm — 2:40pm | Title: (Mostly) Open Source DFIR — A Toolkit for End-to-End Investigations
| Title: Offence informs Defense, or does it?
|
| 2:40pm — 3:00pm | Networking Break | |
| 3:00pm-4:00pm | Title: Open Source Threat Intelligence
| Title: Cyber Nightmares: Red October & Shamoon
|
| 4:00pm-5:00pm | Title: Automating Malware Analysis with Cuckoo Sandbox
| Title: "My name is Hunter, Ponmocup Hunter"
|
| 5:00pm—6:00pm | Title: Hunting Attackers with Network Audit Trails
| Panel Title: Women in DFIR PanelPanelists:
|
Wednesday, July 10, 2013 | ||
| 7:00am-8:00am | Networking Breakfast Presented By | |
| Time | Room 1 | Room 2 |
| 8:00am-8:30am | Title: Forensic 4Cast Awards
| |
| 8:30am-9:30am | Title: Autopsy 3: Extensible Open Source Forensics
| Title: Timeline Analysis by Categories
|
| 9:30am- 10:30am | Title: Detecting data loss from cloud synchronization applications
| Title: A Day in the Life of a Cyber Tool Developer
|
| 10:30am - 10:50am | Networking Break | |
| 10:50am - 11:50pm | Title: Proactive Defense
| Title:The 7 Sins of Malware Analysis
|
| 12:00pm-1:00pm | Lunch & Learn Presented By | |
| 1:00-2:00pm |
| Title: Facilitating Fluffy Forensics(a.k.a. Considerations for Cloud Forensics)
|
| 2:00pm—3:00pm | Title:Timeline creation and review, GUI style!
| Title: Building, Maturing, and Rocking a Security Operations Center
|
| 3:00pm—4:00pm | Title: ICS, SCADA, and Non-Traditional Incident Response
| Title: Restoring Credential Integrity after an Enterprise Intrusion
|
| 4:00pm-4:20pm | Networking Break | |
| 4:20pm-5:30pm | DFIR SANS360 In one hour, 10-12 Digital Forensics and Incident Response experts will discuss the coolest forensic technique, plugin, too, command line, or script they used in the last year that really changed the outcome of a case they were working. If you have never been to a lightning talk it is an eye opening experience. Each speaker has 360 seconds (6 minutes) to deliver their message. This format allows SANS to present 10-12 experts within one hour, instead of the standard one presenter per hour. The compressed format gives you a clear and condensed message eliminating the fluff. If the topic isn't engaging, a new topic is just 6 minutes away. Don't be a script kiddie - Kyle Maxwell, Verizon Hunting and Sniper Forensics - Jason Lawrence Incident Readiness - Top 10 Keys to a Successful Forensic Investigation - J Jewitt Social Media Forensics - Brian Lockrey Finding Evil Everywhere: Combining host-based and network indicators - Alex Bond Chasing Malware, Not Rainbows - Frank McClain Raising Hacker Kids - Joseph Shaw TBA - Hal Pomeranz A Decade of Trends in Large-Scale Financial Cyber Breaches - Ryan Vela Reconstructing Reconnaissance - Mike Sconzo Advanced Procurement Triage - Michael Ahrendt | |
| 5:30pm-5:40pm | Summary & Closing Remarks Rob Lee & Alissa Torres— Summit Chairs Digital Forensics and Incident Response Summit | |
Please note: The DFIR SUMMIT agenda is subject to change at any time.


Post a Comment
* Indicates a required field.