Episode 7 - Defending Against Scattered Spider: Understanding Their Tactics, Techniques, and Procedures

Episode 7 - Defending Against Scattered Spider: Understanding Their Tactics, Techniques, and Procedures

Send a text

In todays episode of TLP - Traffic Light Protocol, Clint Marsden talks about Defending Against Scattered Spider: Understanding Their Tactics, Techniques, and Procedures.

Key Takeaways

Understanding Scattered Spider: Scattered Spider, also known as Roasted Octopus or Octo Tempest, utilizes various legitimate tools for malicious purposes.

Common Tools and Techniques: They employ tools for reconnaissance (PingCastle, ADRecon), credential dumping (Mimikatz, Lazagne), Remote access (Screen Connect, Team Viewer), and VPN (Tailscale).

Social Engineering Tactics: Their methods include impersonation, MFA fatigue (MFA bombing), and SIM swapping to gain access.

Persistence Mechanisms: They maintain access through methods like automatic account linking and adding additional MFA tokens

Defense Strategies: Implement strong identity verification, monitor for unusual activity, and educate users social engineering & smishing

Quotes

"By understanding their tactics, techniques, and procedures, or TTPs, you can better defend your network and improve its security posture."
"There's a lot of push on recognizing phishing emails and hovering over links and verifying the sender, but not enough focus on social engineering training for staff"

Action Points

Review Service Desk Processes: Ensure robust identity verification to prevent social engineering.
Monitor for Unusual Activity: Regularly audit and set up automated alerts for suspicious MFA changes or logins.
Educate Users: Conduct training on recognizing phishing and social engineering techniques.
Test Tools in a Lab: Use the mentioned tools to simulate attacks and improve defensive measures by analyzing security logs and infrastructure.

Mentioned Resources

Remote monitoring and management or RMM tools

Fleetdeck.io
Level.io
Ngrok Mitre Ref: [S0508]
Screenconnect
Splashtop
Teamviewer
Pulseway
Tactical RMM

Reconnaissance:

PingCastle - https://www.pingcastle.com/
ADRecon - https://github.com/sense-of-security/ADRecon
Advanced IP Scanner - https://www.advanced-ip-scanner.com/
Govmomi - https://github.com/vmware/govmomi

Cred dumpers:

Mimikatz - https://github.com/ParrotSec/mimikatz
Hekatomb - https://github.com/ProcessusT/HEKATOMB
Lazagne - https://github.com/AlessandroZ/LaZagne
gosecretsdump - https://github.com/C-Sto/gosecretsdump
smbpasswd.py - (as part of Impacket) - https://github.com/fortra/impacket/blob/master/examples/smbpasswd.py
LinPEAS - https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS
ADFSDump - https://github.com/mandiant/ADFSDump

VPN:

Tailscale - Provides virtual private networks (VPNs) to secure network communications








Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(25)

Episode 24: Voice AI Under Attack: Hackers Exploit AI Call Agents | Traffic Light Protocol Podcast

Episode 24: Voice AI Under Attack: Hackers Exploit AI Call Agents | Traffic Light Protocol Podcast

Send a textVoice AI is moving fast — but so are the attackers.In this episode of the Traffic Light Protocol Podcast, Clint and Myles break down how scammers are exploiting Voice AI platforms with the ...

16 Sep 202554min

Episode 23:AI Voice Agent Security: Voice AI Under Siege: SIP Spoofing, Cost Drain, and How to Fight Back

Episode 23:AI Voice Agent Security: Voice AI Under Siege: SIP Spoofing, Cost Drain, and How to Fight Back

Send a textIn this episode of Traffic Light Protocol, we kick off our AI series with a hard look at how voice AI agents are being targeted; and how fast small businesses and startups can rack up serio...

5 Sep 202533min

Episode 22:AI Chat Forensics: How to Find, Investigate, and Analyse Evidence from ChatGPT, Claude & Gemini

Episode 22:AI Chat Forensics: How to Find, Investigate, and Analyse Evidence from ChatGPT, Claude & Gemini

Send a textUnlock the secrets behind digital forensic investigations into AI chat platforms like ChatGPT, Claude, and Google's Gemini in this insightful episode. Learn the precise methods for discover...

22 Jun 202540min

Episode 21: How IRCO is Changing DFIR: The AI Copilot for Real-Time Cyber Investigations

Episode 21: How IRCO is Changing DFIR: The AI Copilot for Real-Time Cyber Investigations

Send a textLink to IRCO- Incident Response Copilot on Chat  GPThttps://chatgpt.com/g/g-68033ce1b26481919b26df0737241bac-irco-incident-response-co-pilotIn this episode of TLP: The Digital Forensics Pod...

10 Jun 202515min

Episode 20:What Makes an Elite Incident Response Team: Mindset, Mastery, and Real-World DFIR Lessons

Episode 20:What Makes an Elite Incident Response Team: Mindset, Mastery, and Real-World DFIR Lessons

Send a textDrawing inspiration from observing military special forces and over five years of hands-on DFIR experience, Clint explores the mindset, habits, and tactical processes that set top-performin...

4 Jun 202538min

Episode 19: AI Data Poisoning: How Bad Actors Corrupt Machine Learning Systems for Under $60

Episode 19: AI Data Poisoning: How Bad Actors Corrupt Machine Learning Systems for Under $60

Send a textClint Marsden breaks down a critical cybersecurity report from intelligence agencies including the CSA, NSA, and FBI about the growing threat of AI data poisoning. Learn how malicious actor...

26 Mai 202526min

Audiobook - Mastering Sysmon. Deploying, Configuring, and Tuning in 10 easy steps

Audiobook - Mastering Sysmon. Deploying, Configuring, and Tuning in 10 easy steps

Send a textThis episode features the complete narration of my ebook: Mastering Sysmon – Deploying, Configuring, and Tuning in 10 Easy Steps, providing a step-by-step guide to getting Sysmon up and run...

28 Feb 202543min

Episode 17 - Building a CTF

Episode 17 - Building a CTF

Send a textSo You Want to Build Your Own DFIR CTF? Ever wanted to build your own Digital Forensics and Incident Response (DFIR) Capture the Flag (CTF) challenge but weren’t sure where to start? In thi...

27 Feb 202528min

Populært innen Teknologi

teknisk-sett
lydartikler-fra-aftenposten
energi-og-klima
rss-ki-praten
elektropodden
hans-petter-og-co
smart-forklart
rss-alt-som-gar-pa-strom
rss-snakk-om-sikkerhet
fornybaren
shifter
rss-ai-forklart
tomprat-med-gunnar-tjomlid
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
teknologi-og-mennesker
pedagogisk-intelligens
nasjonal-sikkerhetsmyndighet-nsm
rss-alt-vi-kan
rss-ki-til-kaffen
plattformpodden