
Even though investigation leads may perceive intrusions as ranging from straightforward to complex, your stakeholders may not be able to conceptualize findings and impact quite the same way. One tool we have found to consistently communicate the scope of attacker activity is an attack path diagram. If you are new to creating diagrams, they can seem intimidating to develop. Through years of creating attack path diagrams, we have developed processes to visualize our current knowledge of an investigation for our intended audience. This session will discuss how we plan attack diagrams, considerations to match the audience's level of technical understanding, and tools we have used so you can develop your first or next diagrams.
SANS DFIR Summit 2023
Speakers:
David Pany, Manager, Mandiant
Brad Slaybaugh, Incident Response Lead, Mandiant
View upcoming Summits: