HS Detecting Initial Access Malware Before It’s Too Late

HS Detecting Initial Access Malware Before It’s Too Late

Source: YouTube · SANS Digital Forensics and Incident Response · published Jun 26, 2025 · 29:05

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

[BLUF] This presentation details initial access vectors like Luma Stealer, Gozi, and GootLoader, explaining how threat hunting and specific detection strategies for browser-based attacks can mitigate ransomware risks. 0:03-0:13

Key Takeaways:
• Kirin Sadwani introduces the topic, highlighting the critical role of threat hunting in reducing dwell time and detecting threats before traditional alerts trigger. 0:15-0:33
• Initial access malware often uses browser-based vectors like fake updates or SEO poisoning; notably, the "Click Fix" technique tricks users into running malicious PowerShell via the Windows Run dialog. 0:25-0:45
• Luma Stealer operates as Malware-as-a-Service, stealing credentials to sell to ransomware groups like Akira, though recent disruptions have impacted its prevalence. 1:45-2:05
• Gozi (fake update) uses JavaScript to steal credentials, while GootLoader employs SEO poisoning to distribute malicious payloads via compromised search results. 2:45-3:05
• Detection requires monitoring Run MRU registry keys for suspicious commands and identifying unusual WScript or PowerShell executions linked to browser processes. 2:15-2:35

[Closing statement] By understanding these initial access vectors and employing proactive threat hunting, organizations can significantly reduce their risk of successful ransomware attacks. 0:03-0:13

Sources:

  • 0:03 Introduction to initial access malware and detection importance.
  • 0:15 Speaker introduction and agenda overview.
  • [0:25](https://www.youtub

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

We are going to talk on the initial access malares. How we can detect those uh what are the impact and how uh how early we can detect this. My name is Kirin Sadwani and let's start this. I'll start with the quick introduction of myself. I'm currently working at uh as a cyber threat hunter at Inspa Enterprise which is an MSSP. We have a wide range of customers from healthcare sector, manufacturing, FMCG, fintech and whatnot. Previously I worked with for scout and PWC as well. I do sometime write blogs on medium been previously speaker at science blue team summit and in 2023. So uh before uh going to the agenda and uh discussing the initial access m I want to start with uh a story basically a scenario uh recent example maybe so where uh think about a user from a manufacturing midsize manufac…