A Post Incident Case Study for SMB Response Teams | Amanda Berlin @WildWestHackinFest
A Post Incident Case Study for SMB Response Teams | Amanda Berlin  @WildWestHackinFest
Uploaded January 2025 | Updated September 2026, 2 weeks ago
πŸ”— Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences β€” wildwesthackinfest.com
πŸ”— Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com

This presentation will delve into a real-world cybersecurity incident involving a masked application attack on an SMB environment. Using an anonymized incident narrative, we'll walk through the response process from the perspective of a small to medium-sized business team. The presentation will highlight the importance of early detection, the challenges of identifying sophisticated threats, and the critical role of proper incident response procedures.

We'll examine the attack timeline, from the initial malware download disguised as legitimate software to the attacker's lateral movement and attempts at data exfiltration. Key focus areas will include the significance of user awareness, the value of multi-layered security controls, and the effectiveness of SIEM and endpoint detection solutions in identifying suspicious activities.

The presentation will also cover practical lessons learned, including the importance of least privilege principles, robust password policies, and regular security testing. We'll discuss how SMBs can improve their security posture by implementing these lessons and leveraging available tools and best practices.
By analyzing this incident, attendees will gain valuable insights into real-world attack techniques, effective response strategies, and proactive measures to enhance their organization's cybersecurity resilience. The session will conclude with actionable takeaways for SMBs to better prepare for and respond to similar threats in their own environments.

///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe

///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections

///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response

///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com

///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training

///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) β€” Wild West Hackin' Fest: wildwesthackinfest.com
A Post Incident Case Study for SMB Response Teams | Amanda BerlinHacks Hackers Hate  Built In Bins to Bunk BaddiesMind Over Malware: Harnessing Psychology to Fortify Cybersecurity  | Jenn FerrerasWeb Application Authorization: Taming the Perfect Storm | Tim TomesWorkshop: Automating Attacks | Alex Martirosyan | WWHF 2023Tool Shed Demo: ELROND | Ben Smith | WWHF 2023Large Language Models: Disinformation and the Future of Work | Heather  Lawrence | WWHF 2023Unintentional Hackers: Students as the Weakest (and Wildest) Link | Jacob ThompsonThe Hackening: Lessons Learned Compromising MSPs! | Matt Lee, Jason SlagleTrust Me, Im a Shortcut: New LNK Abuse Methods | Wietze BeukemaLost Underground | Ray and Mike Felch | WWHF 2023Tow Away Zone –The Dark Side of Domain Parking | Cameron Cartier
Wild West Hackin Fest |

A Post Incident Case Study for SMB Response Teams | Amanda Berlin

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER