Ghosts in the SIEM: Poking the Bear

No ratings

Presented at saintcon 2017 by

Red teams share a common goal: they present scenarios that challenge the *status quo* in order to improve postures and processes. In InfoSec, red-teaming consists of simulated network attacks aimed to uncover and resolve weaknesses in a network's defenses, with a primary goal of eluding detection. While a major outcome of these simulations is remediation of software and infrastructure weaknesses, equally important is improving the tools and processes that allow the attacks to go unnoticed. Confronted by a sea of security products, how can you verify your tool of choice is providing the information you need to defend your assets? In this talk I discuss the notion of red-teaming an enterprise SIEM solution by "hacking to get caught", generating suspicious artifacts on monitored endpoints with the intention of being detected. I'll release a modular framework that automates these simulations without burning precious tools. Nukes will be fired, will you detect them?!