ENGLISH

Adversarial Tradecraft in Cybersecurity(2021)[Borges][9781801076203]

Book information

ISBN
9781801076203
Language
english
Format
PDF
Filesize
2 MB (2549504 bytes)
Pages
\247
Time added
2021-06-16 21:46:41

Description

Cover Copyright Contributors Table of Contents Preface Chapter 1: Theory on Adversarial Operations and Principles of Computer Conflict Adversarial theory CIAAAN Game theory Principles of computer conflict Offense versus defense Principle of deception Principle of physical access Principle of humanity Principle of economy Principle of planning Principle of innovation Principle of time Summary References Chapter 2: Preparing for Battle Essential considerations Communications Long-term planning Expertise Operational planning Defensive perspective Signal collection Data management Analysis tooling Defensive KPIs Offensive perspective Scanning and exploitation Payload development Auxiliary tooling Offensive KPIs Summary References Chapter 3: Invisible is Best (Operating in Memory) Gaining the advantage Offensive perspective Process injection In-memory operations Defensive perspective Detecting process injection Preparing for attacker techniques The invisible defense Summary References Chapter 4: Blending In Offensive perspective Persistence options LOLbins DLL search order hijacking Executable file infection Covert command and control channels ICMP C2 DNS C2 Domain fronting Combining offensive techniques Defensive perspective C2 detection ICMP C2 detection DNS C2 detection Persistence detection Detecting DLL search order hijacking Detecting backdoored executables Honey tricks Honey tokens Honeypots Summary References Chapter 5: Active Manipulation Offensive perspective Clearing logs Hybrid approach Rootkits Defensive perspective Data integrity and verification Detecting rootkits Manipulating attackers Keeping attackers distracted Tricking attackers Summary References Chapter 6: Real-Time Conflict Offensive perspective Situational awareness Understanding the system Clear the Bash history Abusing Docker Gleaning operational information Keylogging Screenshot spy Getting passwords Searching files for secrets Backdooring password utilities Pivoting SSH agent hijacking SSH ControlMaster hijacking RDP hijacking Hijacking other administrative controls Defensive perspective Exploring users, processes, and connections Root cause analysis Killing malicious processes Killing connections and banning IPs Network quarantine Rotating credentials Restricting permissions Chattr revisited chroot Using namespaces Controlling users Shut it down Hacking back Hunting attacker infrastructure Exploiting attacker tools Summary References Chapter 7: The Research Advantage Gaming the game Offensive perspective The world of memory corruption Targeting research and prep Target exploitation Creative pivoting Defensive perspective Tool exploitation Threat modeling Operating system and application research Log and analyze your own data Attribution Summary References Chapter 8: Clearing the Field Offensive perspective Exfiltration Protocol tunneling Steganography Anonymity networks Ending the operation Program security versus operational security Taking down infrastructure Rotating offensive tools Retiring and replacing techniques Defensive perspective Responding to an intrusion The big flip The remediation effort A post-mortem after the incident Forward looking Publish results Summary References Packt Page Other Books You May Enjoy Index

Similar books