How many endpoint Operating Systems are there?
 
SPOILER alert – the answer is two!

🛝 Webcast Slides - 
https://www.antisyphontraining.com/wp-content/uploads/2026/04/REI-Nix-042026.pdf
 
Join Patterson Cake, Director of Incident Response at Black Hills Infosec, as he guides through his “rapid endpoint investigations” workflow for the “other” (not Windows) Operating System…*Nix (Linux/Mac).
 
We’ll learn how to select, acquire, and analyze Linux and Mac investigative artifacts, using Velociraptor offline collector, CatScale, and UAC scripts.
 
Windows gets a lot of attention and rightfully so!
 
However, Linux and Mac are part of every enterprise ecosystem and represent a critical attack surface. You need a simple, effective, repeatable plan for investigating these endpoints.

Chapters

  • (00:00) - Intro - Investigating Nix Endpoints for Incident Response - Patterson Cake
  • (00:31) - April is the cruelest month
  • (02:24) - AGENDA
  • (04:21) - ENDPOINT & IDENTITY
  • (04:59) - ENDPOINT = ?
  • (07:11) - OS = Windows vs Linux vs Mac?
  • (08:48) - Linux “Use Cases”
  • (10:29) - Endpoint Investigations: Linux
  • (12:45) - Rapid Endpoint Investigations: Linux
  • (13:37) - THREAT-ACTOR SOP*
  • (17:15) - ENDPOINT ATTACK SURFACE
  • (18:58) - RAPID TRIAGE WORKFLOW
  • (20:07) - Linux Artifacts
  • (22:14) - COLLECT...PARSE...REDUCE/REFINE
  • (23:22) - COLLECT ARTIFACTS
  • (27:02) - ANALYSIS WORKFLOW
  • (27:49) - OUTPUT REVIEW
  • (32:40) - Other = Mac (Business Desktops 10%)
  • (34:35) - Mac “Threat-Actor SoP”
  • (36:37) - Mac Artifacts
  • (40:07) - Mac UAC Execution
  • (41:55) - Mac Artificats (again)
  • (50:30) - ENDPOINT & IDENTITY - Mac
  • (52:32) - Resources
  • (53:52) - Q&A


Credits
Creators & Guests


Chat with your fellow attendees in the BHIS Discord server:
https://discord.gg/bhis
in the #🔴live-chat channel

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com

Click here to watch a video of this episode.

Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

Click here to view the episode transcript.

Podden och tillhörande omslagsbild på den här sidan tillhör Antisyphon Training. Innehållet i podden är skapat av Antisyphon Training och inte av, eller tillsammans med, Poddtoppen.