Ian Ahl
Ian Ahl, SVP of Permiso’s P0 Labs
- Mandiant 10’ish Years
- Advanced Practices Lead
- Incident Response
- @TekDefense
- USMC
Session
06-18
09:50
20min
LUCR-3: Cloud Clepto & SaaS-y Scattered Spider Shenanigans
Ian Ahl
The on premise tactics of LUCR-3 (Scattered Spider) are well known. In this talk I will walk through the less known TTPs of LUCR-3 in cloud, identity, and SaaS environments. From Initial Access through mission completion, no step will be left untraced. Detection ideas, hunting approaches, and a large collection of rules will be shared!
A Long Train of Abuses and Usurpations
Breakout 2