CREST Videos
CREST Videos
  • 579
  • 243 788
CRESTCon Europe 2024 - Slash Incident Resolution Time: From 30 Days to 1 - Vsevolod Shabad
As CISO of Kazakhstan’s largest bank (13,000 employees, 6M+ customers), Vsevolod faced the immense challenge of streamlining cybersecurity
operations. By applying his IT background and innovative use of Kanban and Scrum frameworks, he revolutionized the SOC. The result? He slashed
incident resolution times for 90% of cyber threats from a staggering 30 days to a single day.
In this presentation, Vsevolod will unlock the strategies behind this remarkable transformation.
Переглядів: 9

Відео

CRESTCon Europe 2024 - I am a Purple Penguin - Tim Wadhwa-Brown
Переглядів 77 годин тому
ATT&CK is a game changer and where it works, it can enable both Blue and Red Teams to co-exist and work effectively together. However, what do attackers on Linux do when bitcoin miners aren’t their motivation? This talk looks at how the Linux-malware repo came to take shape and how the presenter has used it to inform both MITRE and Cisco’s view on adversarial behaviour over the last couple of y...
CRESTCon Europe 2024 - The ‘Thinking’ Analyst: Unlocking Core AnalysisSkills - Michael Lamb
Переглядів 247 годин тому
In this talk, Michael will take the audience through examples of key skills required by analysts that we don’t often think about, such as biases, types of communication, changing our way of thinking when approaching investigations of any size, reporting, analysis techniques and how to handle incoming information during investigations. The presentation will also cover factors that can degrade pe...
CRESTCon Europe 2024 - Threat Actor Negotiations
Переглядів 47 годин тому
Threat Actor Negotiations - Avoiding the Pitfalls, Navigating a Successful Resolution: Dan Saunders, Director, Incident Response, Kivu You have been hit with a ransomware attack, DDoS or an unauthorised intrusion resulting in a data breach and are being extorted by a financially motivated adversary. During this session, Dan will explore the benefits and risks associated with threat actor negoti...
CRESTCon Europe 2024 - Transforming Distributed SOCs into a Virtual Resilience Operation Centre
Переглядів 47 годин тому
Transforming Distributed SOCs into a Virtual Resilience Operation Centre: Dr George Papamargaritis, VP MSS, Obrela A global MSSP or MDR service provider usually operates distributed Security Operations Centres (SOCs) across various geographical regions, aligning with its strategic planning. Although each SOC entity may have its dedicated team, and adheres to standardised processes and procedure...
CRESTCon Europe 2024 - Insights from the SOC: Detecting Malware, Including AI Variants
Переглядів 87 годин тому
Insights from the SOC: Detecting Malware, Including AI Variants: Theofanis Dimakis, SOC Officer, Obrela and Nikolaos Tsompanidis, Threat Detection & Response Expert, Obrela As anticipated, AI presents opportunities for malicious actors to significantly reduce the need for research and development, as well as the time required for creating malware. With the integration of AI tools into our lives...
CRESTCon Europe 2024 - Mitigating Supply Chain Attacks - Touhid Shaikh & Mayank Sahu
Переглядів 87 годин тому
This presentation delves deeply into supply chain attacks and offers insightful analysis, real-world case studies and doable solutions to help organisations defend themselves against supply chain attacks as they change over time. The talk begins with a detailed analysis of supply chain attacks, revealing their subtleties and organisational consequences. Through an exploration of actual cases, p...
CRESTCon Europe 2024 - Predictive Cyber Defence - Early Warning Intelligence - Robin Dimyanoglu
Переглядів 154День тому
This workshop introduces Early Warning Intelligence (EWI), a predictive approach that orchestrates cyber defence by anticipating threats before they materialize. Incorporating structured analytical techniques, we will explore four distinct methodologies for constructing an EWI system: profile-driven, correlation-guided and hypothesisdriven research approaches and probabilistic attack trees, dra...
CRESTCon Europe 2024 - ‘Junk-gun Ransomware' - Matt Wixey,
Переглядів 18День тому
‘Junk-gun Ransomware’: Exploring a niche in the ransomware ecosystem For threat actors looking to get into ransomware, it’s often more complex (and expensive) than they perhaps first anticipated. In addition to having to share revenue under many Ransomware-as-a-Service (RaaS) models, they risk RaaS operators ripping them off and interfering in negotiations, law enforcement attention and infrast...
CRESTCon Europe 2024 - Navigating the Hacktivism Landscape - Riam Kim-McLeod
Переглядів 27День тому
Once thought to be a declining threat, hacktivism has generated significant noise since the onset of the Russia-Ukraine war. During the past two years, SecAlliance has collected daily intelligence on hacktivist activity from online sources, allowing us to offer insights into key trends and implications for future hacktivism in the conflict. SecAlliance observed a steady rise in hacktivist activ...
CRESTCon Europe 2024 - Exploring The Early Stages of Cyber Threats from AI - Beth Allen
Переглядів 39День тому
The emergence of AI-driven threats presents a significant challenge for companies worldwide. As we delve into the early stages, it becomes increasingly apparent that AI chatbots are becoming pivotal players in the cyber underground. This talk focuses on the implications and pressing concerns surrounding AI-driven threats. It is imperative to understand why these emerging threats demand our atte...
CRESTCon Europe 2024 - Avoiding an Identity Crisis - Jonathan Sword
Переглядів 7721 день тому
Multi Factor Authentication (MFA) is often seen as the solution to verifying a user’s identity. The guidance of “Enable MFA” is etched into all our brains as the defence against attacks using compromised credentials. But does MFA really defend us or are we just focusing on a single part of the challenge and ignoring the bigger picture? Maybe the questions we’re asking about verifying a user’s i...
CRESTCon Europe 2024 - API Secret Tokens Exposed - Antoine Carossio
Переглядів 1921 день тому
API Secret Tokens Exposed - Insights from Analysing One Million Domains Reveals Critical Risks of the Modern Web. Exposed API tokens present significant risks to organisations. This presentation underscores this issue by showcasing the findings of recent research, which analysed a million domains and revealed more than 18,000 API tokens and RSA keys (41% classified as highly critical). Antoine ...
CRESTCon Europe 2024 - Explore Open-Source LLMs implementations and use cases for offensive security
Переглядів 2521 день тому
This presentation aims to clarify basic foundation concepts of Machine Learning and generative Artificial Intelligence by exposing practical demonstration of tools that can be used during offensive security operations. The talk will be focused on Open Source Large Language Models (LLMs), allowing the audience to integrate (and hopefully improve and share) the presented tools into their penetrat...
CRESTCon Europe 2024 - Thrive or Dive - Tinesh Chhaya
Переглядів 621 день тому
Thrive or Dive - How supporting the wellbeing of the cyber team is critical to organisational resilience. This session provides an overview of the looming mental wellbeing crisis in the cybersecurity industry (and related industries), focusing on the emerging research conducted by Cybermindz in partnership with the University of Adelaide, South Australia. Recent results suggest cybersecurity pr...
CRESTCon Europe 2024 - Productivity or Malicious Activity - Max Corbridge & Tom Ellson
Переглядів 12621 день тому
CRESTCon Europe 2024 - Productivity or Malicious Activity - Max Corbridge & Tom Ellson
CRESTCon Europe 2024 - Fireside chat about UK CSC Professional Titles
Переглядів 2321 день тому
CRESTCon Europe 2024 - Fireside chat about UK CSC Professional Titles
CRESTCon Europe 2024 - Should You Let ChatGPT Control Your Browser - Donato Capitella
Переглядів 3321 день тому
CRESTCon Europe 2024 - Should You Let ChatGPT Control Your Browser - Donato Capitella
CRESTCon Europe 2024 - Fireside chat with CREST President, Rowland Johnson and CEO, Nick Benson
Переглядів 1521 день тому
CRESTCon Europe 2024 - Fireside chat with CREST President, Rowland Johnson and CEO, Nick Benson
CRESTCon Europe 2024 - Keynote Speech - Rt Hon Stephen McPartland
Переглядів 1421 день тому
CRESTCon Europe 2024 - Keynote Speech - Rt Hon Stephen McPartland
CREST Visits the UN
Переглядів 363 місяці тому
CREST Visits the UN
CREST exams are changing how to prepare and what you need to know - 1600 Session
Переглядів 1534 місяці тому
CREST exams are changing how to prepare and what you need to know - 1600 Session
CREST exams are changing how to prepare and what you need to know - 0800 Session
Переглядів 1664 місяці тому
CREST exams are changing how to prepare and what you need to know - 0800 Session
Emerging Cyber Security Trends in the US: Addressing Risk is the New Black
Переглядів 655 місяців тому
Emerging Cyber Security Trends in the US: Addressing Risk is the New Black
A day in the life of a Security Consultant | Wasim Khan (Secarma Ltd)
Переглядів 2698 місяців тому
A day in the life of a Security Consultant | Wasim Khan (Secarma Ltd)
Finding your path in cyber security | Bo Gan (JDS Australia)
Переглядів 1948 місяців тому
Finding your path in cyber security | Bo Gan (JDS Australia)
Interview with Lukasz Gogolkiewicz (Head of Corporate Security, SLEEK)
Переглядів 468 місяців тому
Interview with Lukasz Gogolkiewicz (Head of Corporate Security, SLEEK)
Hunting for Security Vulnerabilities | Alexandru COLȚUNEAC (Zitec)
Переглядів 919 місяців тому
Hunting for Security Vulnerabilities | Alexandru COLȚUNEAC (Zitec)
Transitioning from IT Management to Penetration Testing | Jonny Gill (Bramfitt Technology Labs)
Переглядів 1349 місяців тому
Transitioning from IT Management to Penetration Testing | Jonny Gill (Bramfitt Technology Labs)
Interview with Maleehah Lohani (Penetration Tester, Mercury ISS)
Переглядів 2159 місяців тому
Interview with Maleehah Lohani (Penetration Tester, Mercury ISS)

КОМЕНТАРІ

  • @amyharris380
    @amyharris380 15 днів тому

    Where can I find your 'reasons to not have Life 360"...

  • @chrisns9712
    @chrisns9712 Місяць тому

    RIP Fred. Thanks for everything.

  • @saravananm9783
    @saravananm9783 2 місяці тому

    Hi sir ,thanks for your valuable information ❤. I'm don't have any either working experience and certification. I learn cyber security and red team by all free resources more then 3 years. Doing project regarding to red team , blogs , documenting our own red team lap setups and process of red team by our own red team exercise lap. If I done these all can i land on a RED TEAM. I'm also intrested in joining your RED TEAM for that what are the qualifications should I have?

  • @UGDFDhrshC
    @UGDFDhrshC 2 місяці тому

    where i find the aggressor.dll file???

  • @user-8ng1ize
    @user-8ng1ize 5 місяців тому

    Actually, it would be best to avoid humans and such things in any objective test, except when they take the role of the tester. Because we are subjects. “Objective” and empirical science confines the subjective to the disposition of the experimenter.

  • @user-8ng1ize
    @user-8ng1ize 5 місяців тому

    39:31 “it’s not a subjective test, it’s an objective test” *proceeds to define a test completely relying on individual subjectivity* An objective test would be, for example, taking someone’s pulse, or using some other scientific instrument which does not retrieve a result from the human mind but rather derives the result of the test from directly applying it to its object. Another objective test would be to burn something by which you test its flammability.

  • @carol-lo
    @carol-lo 5 місяців тому

    RIP

  • @maccajohn3670
    @maccajohn3670 5 місяців тому

    Fred Piper - #Respect.

  • @johnmartin6161
    @johnmartin6161 6 місяців тому

    RIP

  • @charlesalexander9847
    @charlesalexander9847 6 місяців тому

    My former professor

  • @real_djvirus
    @real_djvirus 7 місяців тому

    Alhamdulillah 🙌🏻🙌🏻

  • @adityazalte9932
    @adityazalte9932 8 місяців тому

    One Day I'll Also become the Best Security Architect.

  • @darrenburris7369
    @darrenburris7369 8 місяців тому

    That’s my cousin ❤❤❤❤❤❤❤❤❤❤❤❤❤ yeahhhhhhhhhh😊

  • @Nomaankhan00020
    @Nomaankhan00020 8 місяців тому

    Well done 👍...wk❤🎉

  • @Gazala12
    @Gazala12 8 місяців тому

    Mashaallah ❤ 😍

  • @NomanKhan-kj7nu
    @NomanKhan-kj7nu 8 місяців тому

    Well done wazeer sahab👍🏻

  • @aqilmohdazam9343
    @aqilmohdazam9343 9 місяців тому

    2 yrs late, but cool video

  • @robinsk8591
    @robinsk8591 10 місяців тому

    All the very best Davis❤

  • @smingry
    @smingry 10 місяців тому

    All the best Davis ❤

  • @mohammedshine2372
    @mohammedshine2372 10 місяців тому

    This guy is exceptionally skilled in the field of RFID security. I am fortunate to have the opportunity to work with him at the ASRG Kerala AutoSec Village, where he was as a speaker. Best regards, Davis.

  • @elizabethv8416
    @elizabethv8416 10 місяців тому

    Hearty congratulations.wish you more and more improvement in this subject.

  • @akhil19901990
    @akhil19901990 10 місяців тому

    Nice Session

  • @mohammedshine2372
    @mohammedshine2372 10 місяців тому

    Nice talk

  • @smingry
    @smingry 10 місяців тому

    Congratulations Davis

  • @jerrintvinayan3420
    @jerrintvinayan3420 10 місяців тому

    Nice Session Davis.

  • @GregVlahos-y6l
    @GregVlahos-y6l 11 місяців тому

    Great story and update on DFIR from Emre, the Founder and CEO of Binalyze

  • @bonsaiben8755
    @bonsaiben8755 Рік тому

    CREST’s CRTIA syllabus & notes for candidates says - we will get 2 long form questions, but here in the video it says 1 long form. Which one is correct?

  • @monroe8594
    @monroe8594 Рік тому

    Promo sm

  • @Pri_ag
    @Pri_ag Рік тому

    Brilliant!

  • @AnnieNelson-wo6bm
    @AnnieNelson-wo6bm Рік тому

    Please help. I'm ready to strangle someone. Why is this happening on my phone im no hatter or Dev or coder or pen tester..

  • @FalcoGer
    @FalcoGer Рік тому

    My car's sensors are limited to engine performance, the fuel gauge, the speedometer and if the doors are closed or not and an accelerometer to trigger the air bags when there is some unplanned, rapid disassembly happening. And the only thing that my car has that connects to anything is my retrofitted bluetooth capable radio. No radars, no lidars, no air monitors, no light sensors, no cameras, no rain detectors, no tire pressure caps, no GPS receiver, no broadband modem, no cruise control. The thing about all that junk is that it's nice to have, but at the same time it drives complexity and cost and is a maintenance liability. Any one of those complex systems can fail and very few of them actually are for the improvement of the core functionality of a car or the safety. They're mostly convenience features. Imagine having to park your car yourself instead of pressing the auto park button. But at least I don't have to pay $5000 to replace and realign the radar park assist sensors if they failed to detect that narrow pole that was just between them when I hit the autopark button only only have to pay for a can of paint if I screw up myself, which hasn't happened yet. My car is also started with a turn key, that physically connects the spark plugs to the power supply. So when I want to stop the car, I only need to turn the key. There were cases where cars would use software with a start button to start the engine, and then you basically have no emergency stop button to stop the car in case you had a runaway engine because it was all in software and fly by wire. You couldn't switch to neutral, because that would be dangerous and then you are in for the ride of your life until you either crash or run out of gas. And that has happened. All systems that rely on software only and are safety critical should be designed to have a physical backup switch in case the software fails. And emergency stop buttons should also be failsafe and completely unreliant on software. "There is an infrastructure by honda", and there is half of your problem. They decide that your car is no longer supported, you're out of luck. They decide to track you and sell all that data to who knows who, they can do that. They decide that you should not be allowed to unlock your car anymore? Well, tough luck getting your car to open because it's depending on their services. It's ridiculous that you don't even own your phone and computer anymore, but now they do that same stuff with your car? The security of the car shouldn't depend on the user's device and some crappy attempts to prevent it from running in a testing environment, it should depend on the car and only on the car. If I were to somehow decide that I do want a car that is accessible from the internet, then the only way I would ever allow that is if I am in control of access control and own the whole chain of trust myself. That is a public-private key pair that I generate is required and no backdoor access other than me unlocking my car with a physical key and pressing some hard buttons to reset everything.

  • @user-gb9gl4rp4w
    @user-gb9gl4rp4w Рік тому

    Well presented..

    • @FalcoGer
      @FalcoGer Рік тому

      The accent is hard to decipher at times.

  • @smrubelmedia
    @smrubelmedia Рік тому

    Your video is very beautiful. I like it a lot. I have been trying to talk to you for a long time. I am waiting for your response. Please give me a chance to talk to you📞💗👌

  • @EdgarUProductions
    @EdgarUProductions Рік тому

    Fantastic talk, thanks so much for uploading.

  • @cynthiamitchell5748
    @cynthiamitchell5748 Рік тому

    Great insight. I am attempting to transition into CTI. It has been very exhausing.

  • @errickhepworth4515
    @errickhepworth4515 Рік тому

    I love this dude!! You need SMZeus!

  • @adnanhameed-hg1mn
    @adnanhameed-hg1mn Рік тому

    ❤😂❤

  • @CestPablo
    @CestPablo Рік тому

    Great vid!

  • @thevaper4753
    @thevaper4753 Рік тому

    I got malware all over my hair 😂😂😂

  • @greysky1786
    @greysky1786 Рік тому

    Thank you very much for this video!

  • @greysky1786
    @greysky1786 Рік тому

    Thank you very much!

  • @tnour2511
    @tnour2511 Рік тому

    Hey Matt, thanks for sharing your knowledge and wisdom! As you mentioned, there is a large skills gap across the industry. Do you think companies should open more positions to junior staff? If skilled and experienced employees are retained, won’t that create more specialised staff that become even more employable, while those that are trying to break into the industry are not given the opportunity because of the focus on training current staff? I say this because I have a BSc in Information Security, I’m proficient in Python, I'm active on TryHackMe and HackTheBox, and I’ve obtained my Crest CPSA, but I’ve had absolutely no luck in finding any role in the industry since graduating in August 2021. Many graduate jobs are not fair in their hiring process; they use a "one-fit" psychometric test or tests, and as there are thousands of applicants, it is extremely difficult. I’m trying to obtain additional certifications, but these certifications are really expensive (not very accessible for low-income individuals starting their careers). And for many entry-level or junior roles I’ve come across, companies require professional work experience (I’ve seen a few companies require 2-3 years of work experience!). This is extremely frustrating, especially when I think it would be the perfect role. Many of my peers that I studied with are also in the same vicious cycle. Anyway, I digress. This was meant to be a question but also turned out to be part rant! Thanks for the advice. I will be watching the Crest Careers webinar tomorrow (1st December) for further support.

  • @AM-mv6ro
    @AM-mv6ro Рік тому

    Matt is not 100% correct. You can’t reduce the skills shortage by training and retaining staff. You need to start hiring more junior staff and then train them. It took me 7 months to find an entry level role; I must’ve sent about 250 application and since working at my company, there is still not enough done to hire juniors. My workload has tripled since starting and the people at the top and HR, do not care! I’m on the way to obtaining my CRT and once I get that I’m out!

    • @megamatman
      @megamatman Рік тому

      Hey, I don't disagree with you. The next generation and people that want to retrain and enter the industry are the future and we must do more to support them. What I'm trying to get across is that organisations can not replace the need for mid-level and senior-level+ employees by *just* bringing in juniors. Who is going to provide the training and lend expertise to help people to grow? The data shows that experienced people are leaving the industry in record numbers. That often leads to a situation where juniors are left to pick up responsibilities that they arent ready for yet. I'm sorry to hear about your experience! Well done though for getting that role and powering on through. The role as you've described it doesn't sound very sustainable. That's one of my key rallying calls - lets work to make our roles at all levels sustainable.

  • @simplified_101
    @simplified_101 Рік тому

    So much related. ❤️❤️❤️❤️ for all the presenters. It needs a lot to come up. Hats off

  • @Hannahshibu
    @Hannahshibu Рік тому

    Really benefited from this - thanks CREST!

  • @HimmatSingh1005
    @HimmatSingh1005 2 роки тому

    How do I reach out to you guys? I need some details regarding the CPSA & CRT certification. I am from INDIA. I need to understand how I can achieve these certifications. Please reply as soon as possible as it is urgent.

  • @thefunkygibbon
    @thefunkygibbon 2 роки тому

    Bloody love Zaza 🙂

  • @RaveyDavey
    @RaveyDavey 2 роки тому

    The ICSI training for the CPSA is AWFUL IMO. Nothing more than poorly worded slides that could have been stuck in a PDF, with some little quizzes. Costs hundreds.

    • @myoaye6225
      @myoaye6225 Рік тому

      Does it really helpful to pass CPSA ?

  • @benpturner1050
    @benpturner1050 2 роки тому

    legend!