CATCH ME IF YOU CAN —
SEEING THE RED
THROUGH THE BLUE
Owen Shearing & Will Hunt, in.security
This workshop will help improve both red and blue skillsets through a series of live hacks, where you as an attendee will have to identify malicious activities on a series of targets.
The trainer (Red Team) will perform a series of attacks on the hosts within the in.security LAB, running commands, tools and utilising techniques used in the field. You (the Blue Team) will then need to use the in-LAB ELK stack to identify the malicious activities and raise the alarm! This will up-skill both attackers in understanding the various attack flows that can compromise their cover and defenders in understanding how to detect them.
“The best defence is a good offence” applies as much in cyber as it does in sport. Understanding the attack flow is important in consolidating knowledge, so you’ll get to see every attack the trainer carries out before you’re set off to hunt down the evidence. This heightened mindset will then up your game in the field to better detect the traces, logs and data that can give an attacker away.
WHAT TO EXPECT IN THE INTENSIVE 120-MINUTE WORKSHOP
LAB & SCENARIO INTRODUCTION
Connectivity and network overview
Auditing Windows, Linux and network devices
Intro to the ELK stack, Sysmon, logging, alerting and monitoring
* Port/vulnerability scans
* Brute-force attacks
* Identify targeted hosts and the associated services
* Identify compromised user accounts
* Sending emails with malicious content
* Landing a shell!
* Catching a Phish!
* Credential theft (identifying Mimikatz, Kerberoasting, LSASS attacks)
* Lateral movement and pivoting within the enterprise
* Identifying credential attacks
* Identifying compromised hosts
* Using Out of Band (OOB) channels
* Exfiltrating data
* Identifying suspicious connections
* Raising the alarm!
THIS WORKSHOP IS SUITED TO A VARIETY OF STUDENTS, INCLUDING
Blue/Red team members
IT support, administrative & network personnel
TECHNICAL / HARDWARE / SOFTWARE REQUIREMENTS
Students will need to bring a laptop with a web browser installed