Automated Control Validation with Tommyknocker : Jeremy Banker :

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • number6
    404 Image not found
    • Apr 2019
    • 2172

    #1

    Automated Control Validation with Tommyknocker : Jeremy Banker :

    Title: Automated Control Validation with Tommyknocker
    Presenter: Jeremy Banker
    Co-Presenter:
    Location: W303
    Day,Time: Fri Aug 9 , 2PM - 3:45PM
    Audience: Offense, Defense, Purple Team, SecOps, Audit/Policy
    Project: https://github.com/loredous/tommyknocker

    Abstract:
    Tommyknocker is an open source project designed to facilitate automation of continuous security control validation, bringing some of the processes developers have been using for years for regressing testing, to the security world. It allows users to easily create test scenarios using docker images and standard scripts to perform one or more test actions, followed by the ability to easily check common tooling (SIEM, IDS, Log aggregators) for any expected alerts or log entries. Using Tommyknocker, security organizations can add test cases each time a new security control is created, so that any time a change is made in the environment, the continued functioning of existing controls can be validated. Many times, security organizations will only test controls when they are first implemented, and potentially a few times a year for audit purposes. With Tommyknocker, controls can be tested multiple times per day, ensuring that alerts are raised as soon as possible when a control ceases to function correctly, or is compromised by a threat actor.

    Bios:
    * Presenter:
    Jeremy is an accomplished software developer and lifelong hacker with a combined 10 years of experience in software development and cybersecurity. After working his way up from customer support, and earning a Master's degree in Information Security, Jeremy helped found the Security Product Engineering, Automation and Research group at VMware. Having spoken at both Blackhat Arsenal and Def Con Demolabs on his open source projects, he continues to be passionate about sharing new tools and technologies with the community. In his spare time, Jeremy enjoys gardening, camping, and tinkering with all manner of technology.
    * Co-Presenter:
    Starts
    August 9, 2024 14:00
    Ends
    August 9, 2024 15:45
    Location
    W303
    Last edited by number6; June 25, 2024, 15:59.
Working...