
Canary (Tokens) in the Code Mine with Casey Smith
<p>Thinkst Canary, Cyber Security Researcher Casey Smith joins Nic Fillingham on this week's episode of The BlueHat Podcast. Nic and Casey discuss his background in security, his experience presenting at Blue Hat, and his session on building a Canary token to monitor Windows process execution. The Canary token project is an open-source initiative that creates artifacts on a network to alert defenders when an attacker interacts with them. The tokens can take various forms, such as documents, cloud credentials, QR codes, or executables, providing an early warning system for potential breaches. They also cover the importance of failure in the research process and the evolution of the canary token project to adapt to new attack techniques.&nbsp;</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>In This Episode You Will Learn</strong>:&nbsp;&nbsp;&nbsp;&nbsp;</p><p>&nbsp;</p><ul><li>The need for defenders to explore new features in the Windows operating system&nbsp;</li><li>Challenges of keeping ahead of more sophisticated adversaries&nbsp;</li><li>The use of legitimate binaries for malicious activities&nbsp;</li></ul><p>&nbsp;</p><p>&nbsp;</p><p><strong>Some Questions We Ask:</strong>&nbsp;&nbsp;&nbsp;&nbsp;</p><p>&nbsp;</p><ul><li>How do you balance curiosity-driven research with practical security concerns?&nbsp;</li><li>What challenges do you see in the current state of endpoint security?&nbsp;</li><li>How do you navigate working with customers and using what you learn for research?&nbsp;</li></ul><p>&nbsp;</p><br><p><strong>Resources:</strong>&nbsp;&nbsp;</p><p><a href="https://www.linkedin.com/in/casey-smith-066702282/" rel="noopener noreferrer" target="_blank">View Casey Smith on LinkedIn</a>&nbsp;</p><p><a href="https://www.linkedin.com/in/wendyzenone/" rel="noopener noreferrer" target="_blank">View Wendy Zenone on LinkedIn</a>&nbsp;</p><p><a href="https://www.linkedin.com/in/nicfill/" rel="noopener noreferrer" target="_blank">View Nic Fillingham on LinkedIn</a>&nbsp;</p><p>&nbsp;</p><p><strong>Related Microsoft Podcasts:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</strong>&nbsp;&nbsp;&nbsp;&nbsp;</p><ul><li><a href="https://afternooncybertea.com/" rel="noopener noreferrer" target="_blank">Afternoon Cyber Tea with Ann Johnson</a>&nbsp;</li><li><a href="https://thecyberwire.com/podcasts/uncovering-hidden-risks" rel="noopener noreferrer" target="_blank">Uncovering Hidden Risks</a>&nbsp;&nbsp;&nbsp;&nbsp;</li><li><a href="https://thecyberwire.com/podcasts/microsoft-threat-intelligence" rel="noopener noreferrer" target="_blank">The Microsoft Threat Intelligence Podcast&nbsp;</a>&nbsp;</li></ul><p>&nbsp;</p><p>&nbsp;</p><p>Discover and follow other Microsoft podcasts at<a href="https://news.microsoft.com/podcasts/" rel="noopener noreferrer" target="_blank"> microsoft.com/podcasts</a>&nbsp;&nbsp;</p><br /><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>
The BlueHat Podcast · Microsoft
Audio is streamed directly from the publisher (traffic.megaphone.fm) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.
Show Notes
Thinkst Canary, Cyber Security Researcher Casey Smith joins Nic Fillingham on this week's episode of The BlueHat Podcast. Nic and Casey discuss his background in security, his experience presenting at Blue Hat, and his session on building a Canary token to monitor Windows process execution. The Canary token project is an open-source initiative that creates artifacts on a network to alert defenders when an attacker interacts with them. The tokens can take various forms, such as documents, cloud credentials, QR codes, or executables, providing an early warning system for potential breaches. They also cover the importance of failure in the research process and the evolution of the canary token project to adapt to new attack techniques.
In This Episode You Will Learn:
- The need for defenders to explore new features in the Windows operating system
- Challenges of keeping ahead of more sophisticated adversaries
- The use of legitimate binaries for malicious activities
Some Questions We Ask:
- How do you balance curiosity-driven research with practical security concerns?
- What challenges do you see in the current state of endpoint security?
- How do you navigate working with customers and using what you learn for research?
Resources:
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
- Afternoon Cyber Tea with Ann Johnson
- Uncovering Hidden Risks
- The Microsoft Threat Intelligence Podcast
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Hosted on Acast. See acast.com/privacy for more information.