Перейти к содержимому

From Code to Coverage: A Detection Engineer's Journey Through the LDAP Wilderness - Andrew Schwartz

BSides Belfast

0:00 / 0:00

From Code to Coverage: A Detection Engineer's Journey Through the LDAP Wilderness - Andrew Schwartz

43 просмотра · 9 дн. назад
BSides Belfast
861 подписчик
43 просмотра · 9 дн. назад
Active Directory reconnaissance tools like BloodHound, Impacket, and SOAPHound are the attacker's first move in enterprise compromises, yet detecting their LDAP queries remains one of the hardest problems in security operations. This talk chronicles a six month journey from writing my first broken Sigma rule to building a complete, evasion resistant LDAP detection stack. You'll learn why traditional signature based detection fails spectacularly, how to think like both an attacker and a parser, and how mathematical approaches can outsmart evasion techniques. We'll cover OID transformations that break your rules, whitespace variations that mock your regex, hidden LDAP parameters that bypass your detections, and ultimately, statistical methods that make evasion mathematically impossible. This isn't theory. Every technique is battle tested in production environments with working Sigma rules, real attack logs, and actual false positive rates. Leave with detection rules you can deploy Monday morning.