Disrupting the red team – a practical guide

No ratings

Presented at ConfidenceKrakow 2018 by

Red teaming is everywhere and everybody is doing it. Most organisations are not mature enough to be able to repel red team engagements / simulated attacks. The talk will discuss methods that organisations can employ that will disrupt the red team from achieving their goals; and it doesn’t involve an expensive “magic box”! Presentation Outline:The presentation will walk through a typical red team engagement identifying key areas that an organisation / blue team can utilize to attempt to de-rail a simulated attack / red team engagement. High level areas of interest will include – the talk will dive into these areas: • removing technical debt, • knowing your infrastructure, • the desktop /EUD is the battleground and do they (the desktop) need to communicate with one another, • understanding that operational security compromises organisations and not 0days;• understanding hacker behaviors,• blocking Netsessionenum makes things really hard,• windows event IDs FTW!• Tool enhancments: redsnarf and situational awreness (Pentest Academy video here of tool: https://www.youtube.com/watch?v=JpmXl_zr8doClosing RemarksAttackers use known TTPs, understanding these is crucial to derail and disrupt a red team engagement and increase an organisations security.Attendee Takeaways:1 Red teamers will get an understanding for what works when performing red team engagements.2 Blue teamers and organisations will understand the level of maturity that is required to repel ATPs and red teamers.3 Those who wish to aspire to become red / blue teamers will have an understanding of the level of detail a typical engagement requires to be successful.