Agenda

Sandworm intrusion set campaign targeting Centreon systems – Threat analysis and DFIR

Wed Apr 28 / 13:10 - 13:40 CEST
07. Incident response and threat analysts - from ANSSI

Incident response and threat analysts

from ANSSI

From 2017 to 2020, the intrusion set Sandworm targeted vulnerable Centreon monitoring systems. It resulted in the breach of several French entities, mostly IT services providers. The intrusion set used the P.A.S. webshell as well as dedicated Linux malware « Exaramel ». The presentation will focus on how incident response was led and will present some hypothesis about the intrusion set.