In brief

What to do when the corporate network is already down and the usual security tool consoles and telemetry are gone. The analysis is built on a single end-to-end case: a leaked online store database containing the personal email address of a contractor's employee → access to his email and cloud → open-source reconnaissance → entry into the customer through a jump host under the guise of contract work → persistence, exfiltration of databases, the discovery of an unencrypted backup of a personal phone on the workstation of an IT guy → destruction of backups and of core switch configurations → encryption and extortion over a messenger. Then the practical part: when to isolate a node and when you must not; what to collect as volatile data and in what order; how to connect to switches with a console cable and why the first command should be the shell history. The section on persistent data had begun — and that is where the recording breaks off.

Key points

Tools, artifacts, technologies

The procedural frame appears in the last section: the copy of persistent data must be verifiable — with the source, the extraction method, the tool and its version, the storage location, the time of the operation and the checksums all recorded. The organizational part of the case is about responsibility for contractors: remote access granted to a "contractor" without control became the entry point, and the unencrypted backup of a personal phone on a workstation turned into leverage against the employee personally, including a threat to his reputation. It is separately stressed that none of the collected data may be written to the drive of the node under examination.

Questions from the audience

There are no questions in the recording: the stream breaks off mid-sentence in the section on persistent data, so the end of the talk and any discussion did not make it into the recording.

The speaker's position

A methodical talk by a practitioner, built not around tools but around decisions: the main message is not to act by the template of "isolate everything" or "collect everything", but to assess each time the node's connection to the incident, the ongoing damage and the technical risks. The limitations are stated consistently: isolation destroys volatile data, careless collection brings down an unstable machine, a viewing command on a switch still changes the state of the device. The tone is emphatically cautious, with qualifiers like "at least I wouldn't do it" and "this question is rather philosophical". The practical part is tied to the materials behind the QR code — neither the scripts nor the lists of commands are shown in full in the recording itself.

Quotes