Devil is in the details

No ratings

Presented at NoHat2019 2019 by

How cybercriminals and State-sponsored hackers failed their opsec We like to think that most digital investigations took advantage of sophisticated technologies and analysis methods. But many of them actually started from something much more trivial: an opsec fail. From the suspect accused to have breached Capital One to many drug vendors or marketplace administrators, from APT28 to hacktivists and leakers, the difference between a good or a bad opsec is just one mistake. Usually, more than one. The human factor often exploited by attackers is the same that might compromise them. An undisciplined past, the need of opsec persistence, money flows, the rush to get results and group dynamics are some of the most common vulnerabilities.