Главная
Study mode:
on
1
Intro
2
Red team analytics
3
What is a heuristic?
4
Automatic vs calculated
5
Case study: Making Xerox Copies
6
Common behavioral heuristics
7
The Linda Problem
8
Your morning decisions
9
Experience and context
10
Active Directory Concepts
11
Fast lane to DA
12
Appearance
13
Physical assessments
14
Adobe
15
Browser extensions
16
Microsoft Office
17
MacOS App Store
18
Brief overview of Command and Control (C2)
19
(A few) cloud providers
20
Reproducing Google and Microsoft network traffic
21
Unique parameters
22
Potential infrastructure setup
23
Domain fronting
24
Telling a story with Microsoft
25
Blending in with real Google products
26
Domain categorization vendors
27
Being real
28
Phishing yourself
Description:
Explore the world of red team analytics and behavioral heuristics in this NorthSec 2019 conference talk by Kelly Villanueva. Dive into the concept of heuristics, distinguishing between automatic and calculated decision-making processes. Examine real-world case studies, including the "Linda Problem" and everyday morning decisions, to understand how experience and context influence our choices. Learn about Active Directory concepts and fast-track methods to Domain Admin. Discover techniques for blending in with legitimate network traffic, including reproducing Google and Microsoft patterns, utilizing domain fronting, and leveraging cloud providers. Gain insights into effective phishing strategies and the importance of maintaining authenticity in red team operations. Apply behavioral science principles to enhance your approach to adversary simulation and improve overall security posture.

Hacking Heuristics

NorthSec
Add to list
0:00 / 0:00