Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Signal The ATT&CK

Paul Bottomley
November 13, 2018

Signal The ATT&CK

Security orchestration and automation and its use in enhancing an Endpoint Detection and Response (EDR) capability built around Tanium.

Paul Bottomley

November 13, 2018
Tweet

Other Decks in Research

Transcript

  1. PwC PwC Signal The ATT&CK EDR Architecture GitHub Docker NiFi

    Elastic Clusters Pull master branch master branch dev branch Tanium Server 1 Tanium Server 2 Tanium Server n Slack API calls Caldera Attacker Simulation Alerting Orchestration JIRA Ticketing
  2. PwC PwC Signal The ATT&CK Recon Weaponize Deliver Exploit Install

    C2 Actions Anatomy of a Cyber Attack Cyber kill chain methodology Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Execution Collection Exfiltration Network Forensics Network Forensics Target an organization or industry Craft malicious payload Payload sent to Target Compromise System Installation of malware/post exploitation tools Command and Control Ultimate goals achieved Host Forensics
  3. PwC Signal The ATT&CK Host A Discovery Enumerate Computers Enumerate

    Windows/DNS Enumerate Administrators Initial Access Malicious Excel Macro Spear phishing Persis tence Create HKLM Run Key Execution Download Netcat via Powershell Launch Netcat via Advpack.dll Listen for commands in shell Host B Initial Access Remote execution of RAT Discovery Enumerate Computers Enumerate Windows/DNS Enumerate Administrators etc. Dump passwords with Mimikatz
  4. PwC PwC Signal The ATT&CK Future • Machine learning –

    signals per endpoint, comparisons across estate • Automatic Tanium Signal suppression from the platform • Real-time lookup and correlation with other data sources: • Network: Iceberg, SonarShock • Endpoint: Tanium, Winlogbeat, Auditbeat
  5. 19 Signal The ATT&CK Paul Bottomley, paul.m.bottomley [ AT ]

    pwc.com / @fromCharCode Aniket Bhardwaj, bhardwaj.aniket [ AT ] pwc.com / @anittude Chris Donovan, chris.donovan [ AT ] pwc.com / @Fmtscanf