[APAC] Dissecting How Follina Tricks Word Into Running Arbitrary Code

Logo
Presented by

Brian Coulson, Dan Kaiser, and Randy Franklin Smith

About this talk

In this webinar, you’ll see how Follina works starting with an innocently looking Word “document” that has no macros. Thankfully this particular zero-day is patched. We will also discuss strategic methods for dealing with the risk of Office documents and all the other highly functional content users open and process every day. As just one example of the defense scenarios we will explore is the highly effective method of analyzing parent-child processes. But there’s plenty of other detection controls to consider. Threat researchers Brian Coulson and Dan Kaiser, from LogRhythm, will be joining me and they will take us through the detection mitigations they have developed for Follina and we’ll discuss how to extend them to as yet undiscovered attacks.
Related topics:

More from this channel

Upcoming talks (1)
On-demand talks (257)
Subscribers (76946)
LogRhythm helps security teams stop breaches by turning disconnected data and signals into trustworthy insights. From connecting the dots across diverse log and threat intelligence sources to using sophisticated machine learning that spots suspicious anomalies in network traffic and user behavior, LogRhythm accurately pinpoints cyberthreats and empowers professionals to respond with speed and efficiency. With cloud-native and self-hosted deployment flexibility, out-of-the-box integrations, and advisory services, LogRhythm makes it easy to realize value quickly and adapt to an ever-evolving threat landscape. Together, LogRhythm and our customers confidently monitor, detect, investigate, and respond to cyberattacks. Learn more at logrhythm.com