1、Orlando,FLOctober 69IBM TechXchange 2025Jason BerryJason BerryVeeam Software Sr.Systems EngineerAmit LambaAmit LambaIBM-IBM Cloud StorageSr.Technical Staff MemberSession 1741Smart Backup,Fast Recovery:AI-Powered Threat Detection with IBM Cloud&VeeamSmart Backup,Fast Recovery:AI-Powered Threat Detect
2、ion with IBM Cloud&VeeamData resiliency with Veeam Data resiliency with Veeam and IBM Cloudand IBM Cloud1.2.3.4.5.Art of the attackSimplified Cyber kill chainZero Trust Principles DemoQuestionsIBM TechXchange|2025 IBM Corporation40DAY DAY01DAY 05DAY 10DAY 17DAY 25DAY 30DAY 07DAY 15DAY 20DAY 28DAY 37
3、Art of the attackArt of the attackInformation is gathered on the victims people,processes and technology in playOBSERVATIONSNEAK INGain access to the victim by sending phishing emails and let them click a linkCreating a base of operations and lets make it redundant and highly availableBASE OF OPERAT
4、IONSSnooping around without being detected and compromise higher value targetsLATERAL MOVEMENT&ELEVATE ACCESS Alter routines,documentation and security systems to reduce/deny restore capabilities CRIPPLE RECOVERABILITYEncrypt victims data,wipe archives/backup/data,issue ransom demands!RANSOMDECLARED
5、BACKUPINDICATOR OF COMPROMISE(IOC)IBM TechXchange|2025 IBM CorporationSimplified Cyber Kill Chain Simplified Cyber Kill Chain Dwell timeDiscover Resources,escalate privileges,access credentials evade defenses,and exfiltrate dataImmediatelyPre-EncryptionCompromise backup System,Delete backups,snapsho
6、ts,and DR replicas,stop servicesAccessReconnaissance,then access via social engineering and exploiting known vulnerabilitiesEncryptionLate Friday night on a long holiday weekend,encryption beginsIBM TechXchange|2025 IBM CorporationZero Trust PrinciplesMinimize attack surface and blast radiusAssume b