SOC Summit Talk: Needle Hunting: An Endpoint Investigation Cheat Sheet
With Patterson Cake
March 25 @ 10:00 am – 10:25 am EDT

How do you investigate – let alone understand – an endpoint operating system with more than 50 million lines of code?
Join Patterson Cake, Black Hills Infosec Director of Incident Response, for a technical session outlining a prioritized approach to endpoint investigations, focusing on where and how unauthorized access and activity impact Windows and Linux.
You’ll learn about the endpoint “attack surface,” prioritization of operating-system artifact selection, suggested workflow for artifact acquisition, and a methodology for identification of indicators of compromise.
Chat with your fellow SOC Summit attendees in the Antisyphon Discord server: https://discord.gg/antisyphon
This talk is part of the Antisyphon Training SOC Summit, a free, 6-hour, live virtual event designed to give you an honest, practical look at what it’s really like to work in a SOC.
For those who want to go further, multiple hands-on, high-quality, and affordable training courses are available March 26-April 10 to help you deepen your skills and become more effective at protecting what matters most.
Patterson Cake will be teaching his Incident Response Simplified class on April 3.
See the entire Antisyphon Training Course Catalog for affordable cybersecurity training!
About the Instructor
Patterson Cake
Bio
Patterson Cake joined the Black Hills Information Security (BHIS) pirate ship in June of 2023 as a Security Analyst focusing primarily on detection engineering and digital forensics and incident response. He chose BHIS because, to paraphrase, “doing cool stuff with cool people” and “making the world a better/safer place” is exactly how he wants to spend his professional time and energy. It also helps that he has a bit of history with a couple of awesome folks that have been with BHIS for many moons. Prior to joining the team, Patterson helped build and lead a DFIR practice for an MSSP, worked as a senior security engineer for AWS Managed Services, and spent several years in enterprise cybersecurity, often healthcare related, focusing on intermingling offensive security and incident response in technical and leadership roles. Outside of work, he enjoys spending time with his family, which often involves motorcycles, outdoor sports, movies, and music.

