Upping the APT hunting game: learn the best YARA practices from Kaspersky

Presented by

Costin Raiu, Director Global Research & Analysis Team (GReAT)

About this talk

Have you ever wondered how Kaspersky discovered some of the world’s most famous APT attacks? Now, the answer is within your reach. Costin Raiu, director of Kaspersky’s Global Research and Analysis Team (GReAT), will be sharing best practices on the use of YARA, an essential tool for APT hunters that can assist with the discovery of new malware samples, exploits and zero-days, speed up incident response, and increase your defenses by deploying custom rules inside your organization. If you ever wanted to master YARA and achieve a new level of knowledge in APT detection, mitigation and response, now is your chance. This brief webinar is based on Kaspersky’s exclusive training on YARA rules, which has already helped improve the APT detection strategies of many cybersecurity teams from leading businesses across the world. During the webinar, you will learn how to write test and improve effective YARA rules. You will also get a glimpse of some of our internal tools and learn how to maximize your knowledge for building effective APT detection strategies with YARA. This practical webinar is useful for security researchers and incident response personnel, malware analysts, security engineers, network security analysts, APT researchers and IT security staff. The content is suitable for both beginners and seasoned YARA users. During this webinar, you will learn about: •YARA syntax •Tips & tricks for creating fast and effective rules •Using YARA-generators •Testing YARA rules for false positives •Hunting new undetected samples •Using external modules within YARA for effective hunting •Anomaly search •Real-life examples Don’t miss this opportunity to learn about APT threat detection from Kaspersky’s Global Research and Analysis Team. Attendees’ requirements: Technical level: medium Prerequisites: knowledge of basic programming languages Software to install: YARA 3.11.0 or newer (if any) Learn more about Kaspersky cybersecurity trainings: https://kas.pr/6m8r

Related topics:

More from this channel

Upcoming talks (1)
On-demand talks (198)
Subscribers (43222)
On this channel, Kaspersky experts share their knowledge and key insights into high-fidelity threat hunting and intelligence, incident management, malware analysis, reverse engineering, security solutions, and several other vital aspects of the cyberworld. To keep you up to date, the experts also provide detailed webinars and workshops on how Kaspersky security solutions and services can halt and prevent a vast range of malicious attacks conducted by cybercriminals. Kaspersky is a global cybersecurity and digital privacy company that has been providing protection for 25 years, with over 400 million users from more than 200 countries. Kaspersky experts' mission is to help you find the perfect weapon to protect against any cyberthreat, carried out by even the most sophisticated cybercriminals. Kaspersky researchers are top-notch cybersecurity and protection technology experts, who regularly take part in leading information security events worldwide as best-in-class speakers. Kaspersky’s deep threat intelligence and security expertise is constantly being transformed into innovative security solutions and services that protect businesses, critical infrastructure, governments and consumers around the globe. Subscribe and learn more about the latest cybersecurity discoveries on the threat landscape and how to defend against them. Contact us at https://www.kaspersky.com/about/contact