Early Detection through Deception

No ratings

Presented at BsidesCleveland 2019 by

A discussion on utilizing deceptive principals in enterprise environments with a goal towards tricking adversaries into giving away their presence as early in an engagement as possible. The talk will cover placing deception both in the DMZ and on internal networks and pairing them together to help control an engagement starting from OSINT all the way to lateral movement from a compromised system. I will discuss how to use common attack tools and techniques against the attacker, using their tradecraft as a key part to an enterprise's detection capabilities.All tools and techniques shown are free, open source tools and have been utilized in at least one large enterprise environment with great success.