Posts

Operation “Mr. Wilson”

Image
We’ve been hired by Bank of Widget to ‘attack’ their C level team to determine their security posture via social engineering. Our Target: Mr. Wade Wilson. Wade is CEO of Bank of Widgets in Chicago. Our Goal : Gain access to Mr. Wilson’s work / personal computer(s) Let's begin... KILL CHAIN The kill chain is a military term “kill chain” is a phase-based model to describe the stages of an attack. OSINT (Reconnaissance Phase) What is OSINT anyway? According to Wikipedia “Open-source intelligence (OSINT) is data collected from publicly available sources to be used in an intelligence context. In the intelligence community, the term “open” refers to overt, publicly available sources (as opposed to covert or clandestine source” This article is aimed at showing you just how easy it is to collect information on a target and set up a well-crafted attack. Most of the tools I will be using today come installed standard on Kali Linux. You can download Kali here — https://www.kali.org/ We wi...

Basic Malware Lab

Image
Basic Malware Lab So, you’d like to start analyzing some malware without destroying your own environment? This guide will help you get started with a basic Malware lab.  Environment  The first challenge is isolating your “Malware network traffic” as to not infect your personal machine or even worse launching some SMB Crypto Malware that encrypts ALL THE THINGS! That will be a bad day for you — I promise. So, to solve this issue we will be using VMs running on an isolated network and then creating some fake traffic for the malware to play with. I am going to suggest you start with VirtualBox — I might catch some slack for that — but a few things it’s free and most importantly it allows for snapshots and did I mentions it’s free. KVM is another good choice.  This article assumes a few things. One you have some basic VM experience and two you a little Linux and Windows experience also. Ubuntu Linux Virtual Machine (If you’re looking to get rolling as fast a...

Threat Intelligence with Anomali STAXX

Image
If you follow me on Twitter then you probably already know I am an Anomali STAXX fanboy. Laying around in a Turkey induced food coma - I thought I would do a quick write up on STAXX. So what exactly is STAXX anyway? STAXX is a quick and very easy way to get multiple threat intelligence feeds via STIX and TAXII pushes pushed into one platform.  Some key features are a very easy On-Prem install, free feeds from Anomali LIMO (or bring your own), A very powerful search UI and access to STAXX advanced investigation features. This post will not touch on the installation of STAXX (it's pretty much importing a VM and you're good to go)  Below is the opening page Dashboard. This is a quick glance at 7 days of intelligence pushes. You can filter down by various indicators such as phish_url, apt_url, mal_md5, scan_ip etc. Our SOC team has given us a site that has been lighting the SIEM up with alerts and has asked the Intel team to do a little more research on it. hxxp://ji...

GIAC GMON SEC511

Image
I seem to get WAY overstressed when it comes to testing for certifications. I sat yesterday for the GIAC GMON SEC511 certification and happy to report  I passed!    A very special thank you to my company for sponsoring me. I'd also like to thank Seth Misenar and Eric Conrad for putting together an amazing course. Cannot forget my wife and daughter for being patient with me.   Blue will always be cool! Thanks for helping me "Secure all the Things" So what is GMON anyway? GIAC Continuous Monitoring Certification (GMON) View Professionals Description Preventing all intrusions is impossible, but early detection is a must for the security of your enterprise. The proper use of Defensible Security Architecture, Network Security Monitoring (NSM)/Continuous Diagnostics and Mitigation (CDM)/ Continuous Security Monitoring will support the hindrance of intrusions and allow for early detection of anomalous activity. The topic areas for each exam part follow: Acco...

Detroit Security Conferences

Image
Really excited to be volunteering again this year for Converge and Bsides Detroit.  Below is a little information about these amazing conferences. There are still tickets left!!! May 11-13, 2017 Detroit, MI https://www.convergeconference.org/ Converge Conference is the premier information security and technology gathering. Taking place in the heart of the domestic auto industry, a prominent manufacturing hub and one of America’s great tech cities, Converge Conference spotlights information security for two informative and idea-sharing days. It’s a venue for professionals to come together from diverse technological backgrounds and discuss issues that every organization faces. From technicians to developers to various C-level executives, the goal of Converge is to promote the discussion of security throughout your organization. Together, we can ensure that security stays top-of-mind and meets the needs of the businesses. Lots of amazing sponsors to thank also. Make sure t...

EnFuse Conference

Image
                                                                                                                                                               Excited for another conference!  EnFuse! Pretty geeked for this conference as I have been slowly transitioning to focus more and more on the DFIR side of the world.   I will post a post-con blog once I am back.   Enfuse is a three-day security and digital investigations conference where specialists, executives, and experts break new ground for the year ahead. It's a global event. It's a community. It's wher...

SANS Experience

My SANS experience. I was told SANS training was very good.  I honestly think that’s an understatement.  I was lucky enough to have one of the 504-course author as my instructor – John Strand.  John is the owner of Black Hills Security one of the top Pen testing and security companies in the world.  His passion for Information Security and teaching left me truly inspired to be in this industry.  The SANS@Night courses allowed me to meet several of the other SANS instructors who share his passion for both teaching and information security.   Day 1 Preparation, Identification, Containment, Eradication,  Recovery  Securing our infrastructure is not an easy task.  We have to balance business needs against security risk. With new vulnerabilities releases daily there is always the potential for an intrusion.  The first part of day 1 we looked at a step by step incident handling model. This was model was created by the most experienced inc...