Phishing & OOB Exfiltration Through Purple Tinted Glasses

No ratings

Presented at InfoSecurityEurope 2019 by

The proliferation of client-side attacks continues to grow, as attackers are increasingly aware their chances of success are increased if they can get the victim to open for the door them.Using our enterprise simulated training lab, we will setup and execute a phishing campaign that bypasses AV and results in a foothold on a target network. We’ll then switch hats and use an ELK stack to identify logs and IOCs. The session will then move onto data exfiltration, where DNS and ICMP out-of-band channels will be established. Finally, we’ll jump back into blue and show where logging can help identify the above exfiltration methods, providing an overall perspective of both attack and defence.Learning Outcomes:Knowledge of phishing setup and executionTweaking payloads to bypass defensive protectionsSetup and execution of out-of-band channel data exfiltration over DNS and ICMPIntroduction to ELK stack functionalityMonitoring/logging of compromise and data exfiltration