Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Introduction Atomic Red Team Framework

Introduction Atomic Red Team Framework

Presented at null Dubai Meet 22 December 2017 Monthly

Pralhad Chaskar

December 22, 2017
Tweet

More Decks by Pralhad Chaskar

Other Decks in Technology

Transcript

  1. Sysmon • System Monitor (Sysmon) is a Windows system service

    and device driver which provides detailed information about process creations, network connections, and changes to file creation time. • By collecting the events you can identify malicious or anomalous activity and understand how intruders and malware operate on your network. • Note that Sysmon does not provide analysis of the events it generates, nor does it attempt to protect or hide itself from attackers. Reference : - https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
  2. CALDERA (again by ….MITRE team) It is an automated adversary

    emulation system that performs post- compromise adversarial behavior within enterprise networks. It generates plans during operation using a planning system and a pre- configured adversary model based on the Adversarial Tactics, Techniques & Common Knowledge (ATT&CK™) project. Reference : - https://github.com/mitre/caldera https://www.blackhat.com/docs/eu-17/materials/eu-17-Miller-CALDERA-Automating-Adversary-Emulation.pdf
  3. Takeaways • Visibility of endpoints in Infrastructure • Analayze logs

    (powershell, cmd, etc) • Test framework against own infrastructure before attacker own’s you • Maturity of blue team is important • All teams (Red, Blue, Purple, etc) should work together