62
Company Confidential Powered by Activated Charcoal Making Sense of Endpoint Data

Activated Charcoal - Making Sense of Endpoint Data

Embed Size (px)

Citation preview

Page 1: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Powered by

Activated CharcoalMaking Sense of Endpoint Data

Page 2: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Greg Foss

Head of Global Security Operations

OSCP, GAWN, GPEN, GWAPT, GCIH, CEH, Cyber APT

Page 3: Activated Charcoal - Making Sense of Endpoint Data

The Endpoint is the new Perimeter

Page 4: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

The easiest path into any network…

Page 5: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Social Engineering

Nothing like a little pretext to get people to click on your links…

Page 6: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

• Phishing• 91% of ‘advanced’ attacks began with a phishing email

or similar social engineering tactics.• http://www.infosecurity-magazine.com/view/29562/91-of-

apt-attacks-start-with-a-spearphishing-email/

• 2014 Metrics• Average cost per breach => $3.5 million• 15% Higher than the previous year

• http://www.ponemon.org/blog/ponemon-institute-releases-2014-cost-of-data-breach-global-analysis

Page 7: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Drive By Downloads, Malvertizing, and Watering Hole Attacks

Image Source: https://blog.kaspersky.com/what-is-malvertising/5928/

Page 8: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 9: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 10: Activated Charcoal - Making Sense of Endpoint Data

Training is Critical to Success

Page 11: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Key Focus Areas:

• Employees

Image Source: http://www.cloudpro.co.uk/hr/5803/gov-offers-hr-workers-free-cyber-security-training

Page 12: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

End User Tips - Phishing

Page 13: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

All You Need is +

Page 14: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Shortened URLTracking

Page 15: Activated Charcoal - Making Sense of Endpoint Data

Testing and Validation

Page 16: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Rogue Wi-Fi Network – Threat Simulation

Page 17: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

USB Drop – Training Exercise : Case Study

Page 18: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Building a Believable Campaign

Use realistic files with somewhat realistic data

Staged approach to track file access and exploitation

Page 19: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Profit

Send an email when the Macro is run…

Use a bogus email (unlike I did here) – I know, I know. Bad OpSec.

Page 20: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Tools\calculator.exe

Page 21: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

“Nobody’s going to an an exe from some random USB” - Greg

Yep… They ran it...

Page 22: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Now we have our foothold…

Fortunately they didn’t run this as an admin

Page 23: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 24: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Key Focus Areas:

• Employees

• IT Staff

• Roles and Responsibilities

• Incident Response Duties

• Configuration Monitoring

• Malware Removal

• Security Infrastructure

Page 25: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Key Focus Areas:

• Employees

• IT Staff

• Security Staff

• Table Top and Red vs Blue Exercises

• Threat Simulation Leads to Process Improvement

• Announced vs Unannounced Simulations or Penetration Testing

Page 26: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Purple Team FTW!

• Employees

• IT Staff

• Security Staff

• Table Top and Red vs Blue Exercises

• Threat Simulation Leads to Process Improvement

• Announced vs Unannounced Simulations or Penetration Testing

Page 27: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Key Focus Areas:

• Employees

• IT Staff

• Security Staff

• Leadership

Page 28: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Key Focus Areas:

• Employees

• IT Staff

• Security Staff

• Leadership

• Processes and Procedures

Page 29: Activated Charcoal - Making Sense of Endpoint Data

Continuous Monitoring and Detection

Page 30: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Automating OSINT and Response

Domain Tools

Passive Total

VirusTotal

Cisco AMP ThreatGRID

Netflow / IDS

Firewalls

Proxy / DNS

Endpoint

SIEM

API Integration SecOps Infrastructure

Page 31: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 32: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Malware Beaconing

Page 33: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 34: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Malware Beaconing

Page 35: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Correlate Network / Log Activity with Endpoint Data

Page 36: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Macro Phishing Attacks

• Common

• Bypasses Most AV

• Heavily Obfuscated

• Newer attacks

targeting Office 365

Page 37: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Macro Attack Detection

Page 38: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Full Command Line Details

Page 39: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Full Command Line Details

Page 40: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Be Careful – Don’t Jump To Conclusions…

Page 41: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Be Careful – Don’t Jump To Conclusions…

Page 42: Activated Charcoal - Making Sense of Endpoint Data

Centralized Logging and Event Management

Page 43: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 44: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Threat Feed Configuration

Page 45: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Full Event Alerting

Page 46: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Syslog Only

Page 47: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Watchlist Configuration

Page 48: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Carbon Black Event Forwarder

LogRhythm => Use LEEF Format

https://github.com/carbonblack/cb-event-forwarder

Page 49: Activated Charcoal - Making Sense of Endpoint Data

Dashboards and Investigations

Page 50: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 51: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 52: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Long Tail Analysis

Strange activity can bubble to the surface when viewing the whole picture

Page 53: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 54: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Page 55: Activated Charcoal - Making Sense of Endpoint Data

Taking it a Step Further…

Page 56: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Additional Integration

Alarming

Trigger on Specific Watch List Hits

Page 57: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Additional Integration

Alarming

Admin Tracking

Page 58: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Additional Integration

Alarming

Admin Tracking

Reporting

Page 59: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Additional Integration

Alarming

Admin Tracking

Reporting

Automation

Perform Actions Based on Alarms Observed

Page 60: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

LogRhythmChallenge . com

Booth #600 #logrhythmchallenge

Page 61: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Mini Network Monitor

Booth #600

Page 62: Activated Charcoal - Making Sense of Endpoint Data

Company Confidential

Thank You!

QUESTIONS?

Greg Foss

Greg . Foss [at] LogRhythm . com

@heinzarelli