Black Hat USA 2018 - No Royal Road … Notes on Dangerous Game @HackersOnBoard
Black Hat USA 2018 - No Royal Road … Notes on Dangerous Game  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 5 days ago
Attribution fatigue is real. We are 20 years past Moonlight Maze, 15 years past Titan Rain, and a decade past the formation of NATO's Cooperative Cyber Defence Centre in Estonia. These recent ten years have seen the public dumping of stolen nation-state toolchains, a worm renaissance, and increasingly adventurous forays by states far beyond the limits of espionage, into active operations. Small wonder we’re tired… but what have we learned about technical and contextual analysis as nation-state threats roll into their third decade? What are we missing? Does any of this even matter?

Network defenders and threat intelligence analysts tend to be sharply divided on this question of nation-state threat attribution. Reasonable network defenders may decide ‘How?’ is all that matters (observables || GTFO); reasonable threat intel analysts may feel similarly about ‘Who?’ (APT1 || GTFO). This talk addresses each of these reasonable extremes, and further advocates for the neglected value of ‘Why?’ in surfacing adversary requirements, targeting, and constraints. We will look at how nation-states have used malware as a form of geopolitical signalling, the myth of vendor neutrality in the nation-state threat ecosystem, and opportunistic distortion of technical analysis.

Words and PE headers are hard, nation-states are weird, but more perfect nation-state threat analysis is possible within – and beyond – the binary.
Black Hat USA 2018 - No Royal Road … Notes on Dangerous GameBlack Hat USA 2018 - Deep Neural Networks for Hackers Methods, Applications, and Open Source ToolsKeynote Optimistic Dissatisfaction with the Status QuoBlack Hat USA 2018 - New Norms and Policies in Cyber-DiplomacyDEF CON 27 - Daniel Romero - Why You Should Fear Your mundane Office EquipmentProtecting the Protector, Hardening Machine Learning Defenses Against Adversarial AttacksDEF CON 27 - Infiltrating Corporate Intranet Like NSA _Pre-auth RCE on Leading SSL VPNsDEF CON 27 - Dirk-jan Mollema - Im In Your Cloud Pwning Your Azure EnvironmentBlack Hat USA 2018 - Real Eyes, Realize, Real Lies Beating Deception TechnologiesDEF CON 27 - Roger Dingledine - The Tor Censorship Arms Race The Next ChapterDEF CON 27 - Truman Kain - Surveillance Detection Scout Your Lookout on AutopilotDEF CON 27 - Jmaxxz - Your Car is My Car
HackersOnBoard |

Black Hat USA 2018 - No Royal Road … Notes on Dangerous Game

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER