MacOS host monitoring - the open source way

DerbyCon 7.0 - Legacy

Presented by: Michael George
Date: Saturday September 23, 2017
Time: 17:30 - 17:55
Location: Stable Talks

MacOS host monitoring - the open source way, I will talk about a example piece of malware(Handbrake/Proton) and how you can use open source tooling detection tooling to do detection and light forensics. Since I will be talking about the handbrake malware, I will also be sharing some of the TTPs the malware used if you want to find this activity in your fleet.

Michael George

Dropbox - Security Engineer. I work on the Incident Response team at Dropbox. I primarily work on host-based detection systems.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats