
Hunting SMB Shares with Data, Graphs, Charts, and LLMs | SO-CON 2025
Source: YouTube · SpecterOps · published May 8, 2025 · 48:34
Scott Sutherland introduces a session focused on hunting SMB shares using modern data analysis techniques like graphs, charts, and LLMs to identify and detect threats 0:05-0:08.
Key Takeaways:
• The presentation centers on exploiting and defending SMB shares, framing the legacy protocol as a nostalgic but highly relevant attack vector reminiscent of 1999 0:06-0:11.
• Sutherland, an established figure in the infosec community best known for creating PowerUpSQL, currently serves as a VP of Research at Net Spy 0:18-0:37.
• His team's core mission involves developing new services and products dedicated to both breaking into systems and detecting malicious actors attempting to do the same 0:42-0:46.
This introduction sets the stage for applying advanced data visualization and AI tools to a classic security vulnerability.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Music] Yeah, we're going to be talking about hunting SMB shares with data, graphs, charts, and LLMs. Um, you heard that right, SMB shares like it's 1999 again. So hopefully, uh, we have some nostalgic fun as we go through. For those of you who haven't met me before, uh, my name is Scott Sutherland. Um, and I go by Nobine, typically on GitHub and Twitter and the like. Um, I've done a lot of open source stuff in the past. Um, the thing I'm probably most known for is PowerUps SQL, which is a little dusty these days, but was still a fun project. Um, these days I'm one of the VPs of research at Net Spy, and so we focus on, you know, building new services, new products, um, trying to find new and exciting ways to break things and detect people breaking things. One of the places I've spent a lot…