Red Teaming MacOS Environments

No ratings

Presented at Texas Cyber Summit 2019 by

This talk is focused on red teaming techniques and tools against MacOS hosts in enterprise environments. Below is the outline of topics that will be discussed:-Intro-Agenda-A Look at MacOS Enterprise Deployments (Common technologies, Remote management, Local admin rights, Misconfigurations)-Phishing techniques (Payload types, Credential harvesting techniques)-Gatekeeper (What is it?, How does it work?, Ways around it/limitations)-Post Exploitation Methods and Examples-Common patterns/detection techniques (Parent-child processes, Command line arguments, Network connections)-Migrating to API Calls (How?, Why This is Harder to Detect, Examples)-Defensive Recommendations (Host-based, Network-based)-Q&A