{"id":1811,"date":"2019-06-07T17:31:16","date_gmt":"2019-06-07T15:31:16","guid":{"rendered":"https:\/\/archive.brucon.org\/2019\/?page_id=1811"},"modified":"2019-08-21T21:25:39","modified_gmt":"2019-08-21T19:25:39","slug":"detection-of-in-out-network-exfiltration-and-post-exploitation-techniques-blue-edition","status":"publish","type":"page","link":"https:\/\/archive.brucon.org\/2019\/brucon-2019-training\/detection-of-in-out-network-exfiltration-and-post-exploitation-techniques-blue-edition\/","title":{"rendered":"Detection of In &amp; Out &#8211; Network Exfiltration and Post-Exploitation Techniques &#8211; BLUE EDITION"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row][vc_column][vc_column_text]<\/p>\n<h2>Course Description<\/h2>\n<p><strong>UNFORTUNATELY THIS TRAINING HAS BEEN CANCELLED. WE APOLOGISE FOR ANY INCONVENIENCE\u00a0<\/strong><\/p>\n<p>&#8220;<em>Detection of In &amp; Out &#8211; Network Exfiltration and Post-Exploitation Techniques &#8211; BLUE EDITION<\/em>&#8221; is an advanced lab-based training created to present participants:<\/p>\n<ul>\n<li>Significance of security events correlation including context to reduce the number of false positives and better detection of adversary activities<\/li>\n<li>Advanced detection methods and techniques against exfiltration and lateral movement including event mapping, grouping and tagging<\/li>\n<li>Understand tactics and behaviours of the adversary after gaining initial access to the network (Linux\/Windows)<\/li>\n<li>Detection methods of tunnelling, hiding, pivoting and custom, simulated malicious network events<\/li>\n<li>Capabilities of many popular Open Source tools and integration with 3rd party security (IDS\/IPS\/WAF\/EDR) and analytics solutions against adversaries actions<\/li>\n<li>Verification methods and techniques for product and service providers from IT Security space \u2192 in terms of internal testing and PoC \/ PoV programs<\/li>\n<\/ul>\n<p>The main goal of the workshop is to achieve better detection of post-exploitation activities and more effective incident handling, thus allowing to reduce the number of false positives in the SOC environment. Individual detection lab cases will be launched and analyzed together in details by finding new and using existing DFIR artifacts. A modular lab-oriented form of the training allows for a later use and combination within your own SOC infrastructure, expanding and delivering complex tactics, techniques and procedures (TTP).<\/p>\n<p>Individual artifacts of &#8220;RED&#8221; actions will be linked, properly characterized, tagged and grouped taking into account the level of criticality, mapping to the MITRE ATT&amp;CK Framework and chain-linking events\/pieces of evidence that make up a given security incident.<\/p>\n<p>The workshop is filled with substantive examples \/ contextual insertions from the community world of Threat hunting, Blue \/ Red, including the source of origin.<\/p>\n<p>An integral element of the workshop is a DFIR quiz consisting of presenting real cases of suspicious activities in the form of describing artifacts offline.<\/p>\n<p>The entire training is based on a purely practical laboratory in which the student independently performs each action or related scenarios in a dedicated virtual laboratory network. This class focuses on x86 \/ x64 architecture, IPv4 \/ IPv6 networks and targets distributed Linux and Windows environments (AD 2016, 10, 7).<\/p>\n<p>In terms of IDS \/ IPS \/ Data Leakage Protection and for a better understanding of the current status of your network security position, training experience will help you understand the risks, identify dead points of your network security and undiscovered infrastructure spaces by simulating and detecting the actions of a real cyber-threat actor.<\/p>\n<p>The proposed training BLUE agenda &#8211; in the defensive edition &#8211;\u00a0 is a natural continuation of the first \u2192 offensive (RED) edition of the training. Highly technical content and only a practical approach guarantees that the use of the transferred knowledge and technologies in real production environments will be easy, smooth and repeatable.<\/p>\n<p>Make sure your network&#8217;s security really works![\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Course contents<\/h2>\n<h3>Day 1:<\/h3>\n<ul>\n<li>Introduction \u2192 PCAP Exfiltration CTF-style challenge.<\/li>\n<li>One more time \u2192 MITRE Attack Framework \u2192 detection map based on 5 examples of chained attack scenarios.<\/li>\n<li>Finding malicious artifacts using yara and ssdeep:\n<ul>\n<li>How yara works and why it could be your best friend<\/li>\n<li>Yarascan + Volatility Framework vs Linux rootkits<\/li>\n<li>Yara vs webshells<\/li>\n<\/ul>\n<\/li>\n<li>Collecting, analyzing and correlating data from different data sources using:\n<ul>\n<li>Wazuh<\/li>\n<li>Graylog<\/li>\n<li>Open vSwitch<\/li>\n<li>Auditd \/ go-audit<\/li>\n<li>eBPF<\/li>\n<li>OSquery<\/li>\n<li>Splunk \/ Elastic Stack \/ HELK<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li>The power of MISP &#8211; Threat Intelligence Platform.<\/li>\n<li>Windows Sysinternals Suite:\n<ul>\n<li>Sysmon:\n<ul>\n<li>Process execution events<\/li>\n<li>Network connection events<\/li>\n<li>Image load events<\/li>\n<li>Named pipe events<\/li>\n<li>WMI events<\/li>\n<li>PSexec events<\/li>\n<\/ul>\n<\/li>\n<li>Process Explorer<\/li>\n<li>Process Monitor<\/li>\n<li>Autoruns<\/li>\n<li>Evidence traces of file download and execution:\n<ul>\n<li>cmd.exe<\/li>\n<li>HTA<\/li>\n<li>JS<\/li>\n<li>VBS<\/li>\n<li>WSF<\/li>\n<li>JSE<\/li>\n<li>CSharp<\/li>\n<li>certutil<\/li>\n<li>Powershell<\/li>\n<li>Bitsadmin<\/li>\n<li>Shellcode injection techniques<\/li>\n<li>WebDAV \/ SMB \/ NFS share mapping<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>Day 2:<\/h3>\n<ul>\n<li>Low-level Linux security tracing and profiling for critical services:\n<ul>\n<li>eBPF<\/li>\n<li>sysdig<\/li>\n<\/ul>\n<\/li>\n<li>Detection of unusual log patterns and 0-day exploitation attempts using source code analysis of your critical network service.<\/li>\n<li>Playing with BRO IDS \/ Suricata IDS for anomaly detection \u2192 finding malicious artifacts at the network level:\n<ul>\n<li>The importance of network baseline for high-risk environments<\/li>\n<li>Virtual SPAN \/ TAP and Netflow \u2192 OpenVswitch<\/li>\n<li>Feature definition and extraction<\/li>\n<li>Bro-cut syntax<\/li>\n<li>Bro Script Index<\/li>\n<li>Client\/server Fingerprinting:\n<ul>\n<li>JA3<\/li>\n<li>HASSH<\/li>\n<\/ul>\n<\/li>\n<li>Security feature extraction per many different network protocols<\/li>\n<\/ul>\n<\/li>\n<li>Detection and traces of network exfiltration techniques \u2192 use cases:\n<ul>\n<li>ICMP<\/li>\n<li>TCP \/ UDP<\/li>\n<li>SSL \/ TLS<\/li>\n<li>DNS \/ DoH \/ DGA \/ anomalies<\/li>\n<li>HTTP \/ HTTP2 \/ QUIC<\/li>\n<li>LDAP Exfil<\/li>\n<li>Dropbox \/ Twitter \/ Gmail \/ Mozilla<\/li>\n<li>SMB bind named pipes<\/li>\n<li>Legitimate website covert channel<\/li>\n<li>Intelligent HTTP C2 Redirection<\/li>\n<li>Port knocking<\/li>\n<li>Domain fronting<\/li>\n<li>ngrok<\/li>\n<li>SSH Tunneling and pivoting<\/li>\n<li>RDP Tunneling and pivoting \/ RDP Inception<\/li>\n<li>Egress testing and common network traffic on non-standard ports<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>Day 3:<\/h3>\n<ul>\n<li>Detection and traces of post-exploitation, lateral movements \u2192 use cases:\n<ul>\n<li>AD Reconnaissance \/ AD Snapshot<\/li>\n<li>Bloodhound artifacts<\/li>\n<li>Golden Ticket<\/li>\n<li>Silver Ticket<\/li>\n<li>Kerberoasting<\/li>\n<li>RPC over TCP\/IP<\/li>\n<li>DCsync \/ DCShadow<\/li>\n<li>Mimicatz agent\/server<\/li>\n<li>Pass The Hash<\/li>\n<li>SMBexec<\/li>\n<li>Invoke-WMI<\/li>\n<li>Invoke-PSexec<\/li>\n<li>PSRemoting<\/li>\n<li>RDP wrapping<\/li>\n<li>Offensive Powershell:\n<ul>\n<li>WMI multiple sessions<\/li>\n<li>Remote network relaying<\/li>\n<li>Copy VSS<\/li>\n<li>Keylogging<\/li>\n<li>LSA secrets extraction<\/li>\n<li>Sandbox \/ virtual environment detection<\/li>\n<li>UAC bypassing<\/li>\n<\/ul>\n<\/li>\n<li>Poisoning LLMNR, NBT-NS, MDNS, WPAD and WSUS<\/li>\n<li>SMB ransomware detection.<\/li>\n<li>Browser pivoting.<\/li>\n<\/ul>\n<\/li>\n<li>Detection of brute-force attacks \u2192 use cases:\n<ul>\n<li>SQL<\/li>\n<li>AD<\/li>\n<li>SSH<\/li>\n<li>Web Apps<\/li>\n<\/ul>\n<\/li>\n<li>Windows Malware Persistence Methods:\n<ul>\n<li>Service<\/li>\n<li>Winlogon registry entries<\/li>\n<li>Run \/ RunOnce<\/li>\n<li>Scheduled Tasks<\/li>\n<li>Startup Folder<\/li>\n<li>WMI<\/li>\n<li>DLL<\/li>\n<\/ul>\n<\/li>\n<li>Linux Malware Persistence Methods:\n<ul>\n<li>Service<\/li>\n<li>Startup scripts<\/li>\n<li>SSH magic password<\/li>\n<li>Port knocking \/ iptables<\/li>\n<li>Kernel modules<\/li>\n<\/ul>\n<\/li>\n<li>Describing relevant log events as generic and open signature \u2192 Sigma rules:\n<ul>\n<li>Application<\/li>\n<li>APT<\/li>\n<li>Linux<\/li>\n<li>Network<\/li>\n<li>Proxy<\/li>\n<li>Web<\/li>\n<li>Windows<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Requirements<\/h2>\n<ul>\n<li>An intermediate level of command line syntax experience using Linux and Windows<\/li>\n<li>Fundamental knowledge of TCP\/IP network protocols<\/li>\n<li>Penetration testing experience performing enumeration, exploiting, and lateral movement is beneficial, but not required<\/li>\n<li>Basic programming skills are a plus, but not essential<\/li>\n<\/ul>\n<h3>System Requirements<\/h3>\n<ul>\n<li>At least 30GB of free disk space<\/li>\n<li>At least 8GB of RAM<\/li>\n<li>Students should have the latest Virtualbox installed on their machine<\/li>\n<li>Full Admin access on your laptop<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Who should attend:<\/h2>\n<ul>\n<li>Red and Blue team members<\/li>\n<li>Security \/ Data Analytics<\/li>\n<li>CIRT \/ Incident Response Specialists<\/li>\n<li>Network Security Engineers<\/li>\n<li>SOC members and SIEM Engineers<\/li>\n<li>AI \/ Machine Learning Developers<\/li>\n<li>Chief Security Officers and IT Security Directors<\/li>\n<\/ul>\n<h3>If you are looking to:<\/h3>\n<ul>\n<li>Learn ways to improve your detection and event correlations skills across many different data sources<\/li>\n<li>Find the malicious activities and identify threats details on the network<\/li>\n<li>Prepare your SOC team for fast filtering out network noise and allow for better incident response handling<\/li>\n<li>Profile your critical OS and network segments in terms of \u2018normal vs exotic\u2019 behaviour<\/li>\n<li>Find out how DFIR \/ IR Open Source Software can support your SIEM infrastructure<\/li>\n<li>Learn current trends, techniques, and tools for network exfiltration and lateral movements<\/li>\n<li>Understand the value of DLP \/ IDS \/ IPS \/ FW \/ WAF \/ Memory Forensics against real adversary lab scenarios<\/li>\n<li>Understand values from an automated approach to simulating attackers and generating anomalies<\/li>\n<li>Identify blind spots in your network security posture<\/li>\n<\/ul>\n<p><strong>Then this training is for you!<\/strong>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Trainer Biography<\/h2>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column width=&#8221;5\/6&#8243;][vc_column_text]<strong>Leszek Mi\u015b<\/strong> is the Founder of Defensive Security, Principal Trainer and Security Researcher with over 15 years of experience in Cyber Security and Open Source Security Solutions market. He went through the full path of the infosec carrier positions: from OSS researcher, Linux administrator and system developer, Solution Engineer, DevOps and CI, through penetration tester and security consultant delivering hardening services and training for the biggest players in the European market, to become finally an IT Security Architect \/ SOC Security Analyst with deep non-vendor focus on Network Security attack and detection. He\u2019s got deep knowledge about finding blind spots and security gaps in corporate environments. Perfectly understands technology and business values from delivering structured, automated adversary simulation platform.<\/p>\n<p>Recognized speaker and trainer: BruCON, Black Hat USA, OWASP Appsec USA, FloCon USA, Hack In The Box DBX\/AMS\/Singapore, Nanosec Asia, Confidence PL, PLNOG, Open Source Day PL, Red Hat Roadshow. Member of OWASP Poland Chapter.<\/p>\n<p>Author of many IT Security training:<\/p>\n<ul>\n<li>Open Source Defensive Security \u2192 The Trinity of Tactics for Defenders<\/li>\n<li>In &amp; Out \u2192 Network Data Exfiltration Techniques [RED EDITION]<\/li>\n<li>In &amp; Out \u2192 Detection of Network Data Exfiltration Techniques [BLUE EDITION]<\/li>\n<li>System Internals \u2013 Network, OS and Memory Forensics<\/li>\n<li>SELinux \u2192 Development &amp; Administration of Mandatory Access Control Policy<\/li>\n<li>Advanced RHEL\/CentOS Defensive Security &amp; Hardening<\/li>\n<li>ModSecurity \u2192 Development and Management of Web Application Firewall rules<\/li>\n<li>FreeIPA \u2192 Identity Management for Linux Domain Environments &amp; Trusts<\/li>\n<\/ul>\n<p>Holds many certifications: OSCP, RHCA, RHCSS, Splunk Certified Architect.<\/p>\n<p>His areas of interest include network \u201cfeatures\u201d extraction, OS internals and forensics. Constantly tries to figure out what the AI\/ML Network Security vendors try to sell. In free time he likes to break into \u201cIoT world\u201d just for fun.<\/p>\n<p>Still learning hard every single day.[\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/6&#8243;][vc_single_image image=&#8221;600&#8243;][\/vc_column][\/vc_row][vc_row][vc_column][vc_empty_space][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text] Course Description UNFORTUNATELY THIS TRAINING HAS BEEN CANCELLED. WE APOLOGISE FOR ANY INCONVENIENCE\u00a0 &#8220;Detection of In &amp; Out &#8211; Network Exfiltration and Post-Exploitation Techniques &#8211; BLUE EDITION&#8221; is an advanced lab-based training created to present participants: Significance of security events correlation including context to reduce the number of false positives and better detection of adversary activities Advanced detection methods and techniques against exfiltration and lateral movement including event mapping, grouping and tagging Understand tactics&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":75,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1811","page","type-page","status-publish"],"_links":{"self":[{"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/pages\/1811","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/comments?post=1811"}],"version-history":[{"count":11,"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/pages\/1811\/revisions"}],"predecessor-version":[{"id":1989,"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/pages\/1811\/revisions\/1989"}],"up":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/pages\/75"}],"wp:attachment":[{"href":"https:\/\/archive.brucon.org\/2019\/wp-json\/wp\/v2\/media?parent=1811"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}