Dave and Keith are joined by Principal Security Researcher Phil Hagen to peel back the layers of STORM-2603, a suspected China-based threat actor group and how it leverages legitimate tools to lead to tunneling malicious traffic and ransomware deployment.
Phil discusses how adversaries’ use of DFIR-focused tools can complicate detection opportunities and how organizations can mitigate risks through auditing and blocklists.
View the video