Don’t Believe the APT Hype: Incident Detection and Response That Works


Presented at GFIRST in San Antonio, TX on August 18, 2010.

In 2010, the APT suddenly made everyone’s hot list. MANDIANT has analyzed enough potentially compromised hosts over the last five years to know what works and what doesn’t. We’ll review real APT cases and the best tools, techniques and timing to counter this high-profile threat.  You’ll see (sanitized) actual incident data and history, from detection through response.

About the speakers

Michael Graven is a director at MANDIANT. Like all MANDIANT consultants, he chases network bad guys through Fortune 500 companies, governments, and financial institutions. Michael earned degrees at Northwestern University and Stanford University. He has worked on internetworks and system security since 1989, working in environments as large as AT&T and Netscape to as small as twenty-person startups. He is a native Californian and a snowboarder, but he does not surf.