In order to fulfill a growing need for IOC search campaigns, CERT-Solucom released CERTitude, an open-source IOC network scanning tool. Indeed, more and more companies are being requested by national cyber-security agencies to perform "IOC search" on their Information System. Moreover, during incident response missions, there is a frequent need for CERT-Solucom analysts to find the scope of compromise. However, most solutions on the market use previously deployed agent and/or send IOC on the IS network: the attacker becomes aware of the search method. CERTitude is an agentless tool with the ability to "hide" itself from the attacker with the use of encryption protocols. Despite a lot of conditions from OS compatibility to performance impacts, various Windows' IOC can be processed by CERTitude such as registry data, files, processes, services, prefetch data, network connections… We will be pleased to share with you the challenges faced and solutions that we've adopted. At last, but not least, a demo of CERTitude will be performed and the new development roadmap revealed.
Matthieu GARIN is manager within Solucom's Security & Risk Management Practice. For the last 10 years, he has been leading security transformation projects for
Solucom's clients. He is in charge of the cybersecurity activities, and more particularly of the CERT-Solucom's strategy : guidelines definition, new tools development,
business development...
Vincent NGUYEN is the technical leader of CERT-Solucom. He is in charge of the CERT-Solucom's technical projects and, in incident response cases, is leader of analysis teams. More particularly, he is in charge of the development of the CERTitude tool which is presented during the talk.