Pi$$ing Off an APT

No ratings

Presented at BSidesBristol 2019 by

Red teaming is everywhere and everybody is doing it. Most organisations are not mature enough to be able to repel red team engagements / simulated attacks. The talk will discuss methods that organisations can employ that will disrupt the red team from achieving their goals; and it doesn’t involve an expensive “magic box”! The presentation will walk through a typical red team engagement identifying key areas that an organisation / blue team can utilize to attempt to de-rail a simulated attack / red team engagement. The talk will dive into; The Mitre ATT&CK Framework, removing technical debt, knowing your infrastructure, the desktop /EUD is the battleground and do they (the desktop) need to communicate with one another, understanding that operational security compromises organisations and not 0days; understanding hacker behaviors and windows event IDs FTW!