@reprise_99 some first ones (that could have ruined some of my RT projects in an early phase) could be
- Bloodhound detection using decoy AD objects
- Webshell detection in DMZ using audit/sysmon
- ADCS exploitation using a honeypot template
@reprise_99 I'd probably make sure the hundreds of built-in rules work, and only then implement additional use-cases.
I'd focus on use-cases helping to catch attackers early instead of detecting events like DC access which only tell you that your are f***ed already.
Cool finding from my colleague @cj_berlin detailed here: https://t.co/zzDlXDxXZv. PS remoting and SSH ignores "Deny Logon restrictions". So if you enable SSHd on a Domain Controller, every domain user can log in... and, for example, perform a #RemotePotato0 attack 😲
@Tom11880@n3ll41 Lieber @Tom11880, mein Kommentar richtete sich nicht nur an Nella, sondern genauso an Leser, die den Code ausführen und denken, dass sie sicher sind. Aber Nächstes mal versuche ich mich noch klarer auszudrücken. Danke, super wertvoller Kommentar ❤️
@n3ll41 Du könntest das umbauen und als Service laufen lassen, der alle Connections speichert und 1x / Stunde gegen VT testet.
Oder doch einfach deinen Client in nen SIEM onboarden und dort die IPs gegen VT testen
@n3ll41 Die meiste Malware stellt keine permanenten Verbindungen her, sondern betreibt "beaconing" über HTTP. d.h. es gibt nur einen HTTP request alle paar Minuten/Stunden/Tage. Das ist schwierig zu finden hiermit weil man nur alle TCP Verbindungen in einem Moment anschaut...
@rad9800 from my experience there is much less value in EDRs on linux as there is on windows and if you want to save some money I'd recommend a SIEM and making the default alerts based on auditd work
but CSF and MDE are sort of ok if you really want an EDR
I recently implemented 7 public UAC bypasses as BOFs and integrated them into a Havoc module and Sliver extensions. Requests to add more bypass methods are also welcome! https://t.co/Szg0ygwEg8
@n3ll41@Venitroll Ich finde die Aussage auch missverständlich. Ich denke bei einem keylogger an ein Stück Software das es geschafft hat aus der Appsandbox auszubrechen und global, sprich in allen Apps, die Tastatureingaben abzugreifen. Ist das hier der Fall?