OSInt, Shoe Laces And Bubble Gum: How To Use OSInt With Limited Time And Budget To Better Understand How Attackers See Your Organization

No ratings

Presented at BSidesVancouver 2019 by

Jamie McMurray, Security Operations Manager for Kobalt will discuss and demonstrate how to use open source intelligence tools to gather combined insight using subdomain enumeration, port scan and service discovery, web screenshots, and typo-squatting domain enumeration.Limited effort, no budget OSInt that will help you:Quickly find actionable intelligenceKeep track of changes in available OSInt data, enumeration of internet-facing assets and exposing potential shadow ITGain a better sense of combined OSInt and what it tells an attacker, for example:Cloud Infrastructure Providers (IP ASN)Email Hosting Providers (MX Record)SAAS Services (SPF, subdomains, screencapture)“Hidden” subdomains exposed via CT Logs and other sourceTypo-squatting domainsOpen ports and servicesScreen capture of existing domains and known subdomains revealing visual clues about servicesWebpage external dependancies which could be used in an attack