TH-2020 Rastrea2r: Collecting & Hunting for IOCs with Gusto and Style

Presented at Texas Cyber Summit 2019, Oct. 12, 2019, 2:15 p.m. (60 minutes)

Rastrea2r: Collecting & Hunting for IOCs with Gusto and Style Rastrea2r (pronounced "rastreador" - hunter- in Spanish) is a multi-platform open source tool that allows incident responders and SOC analysts to triage suspect systems and hunt for Indicators of Compromise (IOCs) across thousands of endpoints in minutes. To parse and collect artifacts of interest from remote systems (including memory dumps), rastrea2r can execute sysinternal, system commands and other 3rd party tools across multiples endpoints, saving the output to a centralized share for automated or manual analysis. By using a client/server RESTful API, rastrea2r can also hunt for IOCs on disk and memory across multiple systems using YARA rules. As a command line tool, rastrea2r can easily integrate with AV consoles and SOAR tools, allowing incident responders and SOC analysts to collect forensics evidence and hunt for IOCs without the need for an additional agent, with 'gusto' and style! Source Code: <https://github.com/rastrea2r/rastrea2r> Presentation: <https://github.com/rastrea2r/rastrea2r/blob/master/presentations/BH%20Arsenal%20rastrea2r%202018.pdf>

Presenters:

  • Sudheendra Bhat - McAfee LLC
    Sudheendra (Sudhi) Bhat is an Information Security Professional, currently holds the role of Cloud Security Architect in Security Operations Group at McAfee. Sudhi has been developing software for the last 12+ years and has worked for a variety of Software Corporations ranging from small startups to Fortune 100’s. It was while working at Intel 6 years back, Sudhi got exposed to the analyzing Security vulnerabilities which influenced him to pursue Security as a Career Interest. Sudhi Bhat has a Bachelor's Degree in Computer Science from MSRIT, Bangalore (India) and Masters Degree in Computer Science from George Mason University, Virginia and holds various Software and Security Certifications, the most recent one being GIAC GWEB (Analyst # 641). Sudhi Bhat is passionate about OpenSource projects and currently maintains and contributes to the projects under rastrea2r organization in GitHub. Sudhi’s current research areas include Forensic Data Collection, Web Services Security and Automotive Security. Apart from Software and Security, Sudhi loves traveling and outdoor photography.

Links: