We've all done it: upload a webshell, get code execution and move on. But what if your target is being monitored ?
In our latest blog post, we tackle webshell tradecraft in monitored networks including disk activity, process context, and HTTP patterns.
https://t.co/X4Ob3khaUP
SSH access to a system ?
🎯 Red teamers: Avoid interactive sessions to prevent entries in the `last` log. Run commands with `notty` by appending your cmd to the SSH command.
🛡️ Defenders: Monitor unexpected origin IP's in the `last` log and modifications to `/var/log/wtmp`
SNMP enum in legacy/OT networks:
🎯 Red teamers: use specific MIB's that contain useful info such as `HOST-RESOURCES-MIB::hrSWRunParameters` instead of cycling the entire MIB range with snmpwalk
🛡️Defenders: Flag snmpwalk packets starting with 0x30 and containing 0xA1 or 0xA5
Just published a breakdown of 3 easy red team mistakes SOC or threat hunters spot instantly.
Noisy recon, weird process chains, offensive infra misconfigurations, ... (+TraceHunt shots 👀)
If you’re in red/blue teaming or threat hunting, Check it out👇
https://t.co/zalIWgVymc
If you’ve ever done an engagement and thought “wow, that command was loud,” this one’s for you.
I wrote about the OPSEC gap in current offensive trainings and how we’re tackling it with TraceHunt.
If you want your ops to be cleaner than your `/tmp/`:
https://t.co/KvmRKt0W2D
@bpauwels@intidc Initial entry is quasi altijd een succes als tijd geen limiterende factor is voor de aanvaller. Snelheid van detectie en isolatie/damage control van threats zijn de zaken die het verschil maken in dit soort scenario’s
I’m so grateful to be invited to the #1337up0822 LHE hosted by @intigriti and @TheParanoids. I’ve met a lot of new faces and had a blast throughout the entire event. Cherry on top was today’s visit to the BelgianGP F1 race 🏎 Congrats to the winners and see you next time ✌️