
Episode #14
Investigating Nix Endpoints for Incident Response - Patterson Cake
How many endpoint Operating Systems are there? SPOILER alert – the answer is two! 🛝 Webcast Slides - https://www.antisyphontraining.com/wp-content/uploads/2026/04/REI-Nix-042026.pdf Join Patterson Cake, Director of Incident Response at Black Hills Infosec, as he guides through his “rapid endpoint investigations” workflow for the “other” (not Windows) Operating System…*Nix (Linux/Mac). We’ll learn how to select, acquire, and analyze Linux and Mac investigative artifacts, using Velociraptor offline collector, CatScale, and UAC scripts. Windows gets a lot of attention and rightfully so! However, Linux and Mac are part of every enterprise ecosystem and represent a critical attack surface. You need a simple, effective, repeatable plan for investigating these endpoints. Chapters (00:00) - Intro - Investigating Nix Endpoints for Incident Response - Patterson Cake (00:31) - April is the cruelest month (02:24) - AGENDA (04:21) - ENDPOINT & IDENTITY (04:59) - ENDPOINT = ? (07:11) - OS = Windows vs Linux vs Mac? (08:48) - Linux “Use Cases” (10:29) - Endpoint Investigations: Linux (12:45) - Rapid Endpoint Investigations: Linux (13:37) - THREAT-ACTOR SOP* (17:15) - ENDPOINT ATTACK SURFACE (18:58) - RAPID TRIAGE WORKFLOW (20:07) - Linux Artifacts (22:14) - COLLECT...PARSE...REDUCE/REFINE (23:22) - COLLECT ARTIFACTS (27:02) - ANALYSIS WORKFLOW (27:49) - OUTPUT REVIEW (32:40) - Other = Mac (Business Desktops 10%) (34:35) - Mac “Threat-Actor SoP” (36:37) - Mac Artifacts (40:07) - Mac UAC Execution (41:55) - Mac Artificats (again) (50:30) - ENDPOINT & IDENTITY - Mac (52:32) - Resources (53:52) - Q&A Credits Creators & Guests Patterson Cake - Guest Zach Hill - Host Ryan Poirier - Producer Chat with your fellow attendees in the BHIS Discord server: https://discord.gg/bhis in the #🔴live-chat channel 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Click here to watch a video of this episode. Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com Click here to view the episode transcript.





