from the cyber trenches - cyber security experts ... · © mandiant, a fireeye company. all rights...

43
1 © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL FROM THE CYBER TRENCHES LESSONS LEARNED FROM INVESTIGATING TARGETED ATTACKS Director Security Consulting Services BeNeLux & Nordics [email protected] +31 6 24 255 472 Jeroen Herlaar

Upload: others

Post on 11-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

1© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

FROM THE CYBER TRENCHES

LESSONS LEARNED FROM INVESTIGATING TARGETED ATTACKS

Director Security Consulting Services BeNeLux & Nordics

[email protected]

+31 6 24 255 472

Jeroen Herlaar

Page 2: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

2© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

ABOUT MANDIANT

FOUNDED

2004EMPLOYEES

2500+

COUNTRIES

40+FIREEYE

2014

RESPOND ASSESS TRANSFORM

Page 3: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

3© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

ABOUT MANDIANT

RESPOND

ASSESS

TRANSFORM

AM I VULNERABLE?

AM I COMPROMISED?

AM I PREPARED?

I AM BREACHED!

AM I PREPARED?

- INCIDENT RESPONSE -

- INCIDENT RESPONSE RETAINER -

- COMPROMISE ASSESSMENT -

- VULNERABILITY ASSESSMENT -

- RESPONSE READINESS ASSESSMENT -

- SECURITY PROGRAM ASSESSMENT -

- CYBER DEFENSE CENTER DEVELOPMENT -

Page 4: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

4© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

ABOUT MANDIANT

Page 5: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

5© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

2014 NUMBERS

229 ~17.144 467.234>2M13

Page 6: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

6© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

BREACH INVESTIGATIONS

Page 7: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

7© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHAT HAPPENED?

PICTURE THIS

75.000

Page 8: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

8© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

INITIAL

COMPROMISE

WHAT HAPPENED?

CREDENTIAL

HARVESTING

LATERAL

MOVEMENT

DATA

EXFILTRATION

1001010101

1101010010

1011110100

1101001010

REMOTE

ACCESS

Page 9: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

9© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHAT HAPPENED?

205

67

100

3.5M

Page 10: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

10© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHAT HAPPENED?

2982

Page 11: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

11© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

Attacker has domain administrator privileges

Attacker has hashes or cracked passwords for all domain accounts

Attacker has additional stolen credentials

Attacker can freely move:

VPN to Servers

VPN to workstations

Host-to-Host

Partner networks may be compromise

ASSUMPTION: UNFETTERED ACCESS

Page 12: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

12© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

INITIAL

COMPROMISE

WHAT HAPPENED?

CREDENTIAL

HARVESTING

LATERAL

MOVEMENT

DATA

EXFILTRATION

1001010101

1101010010

1011110100

1101001010

REMOTE

ACCESS

Page 13: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

13© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

Page 14: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

14© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

INITIAL

COMPROMISE

WHAT HAPPENED?

CREDENTIAL

HARVESTINGLATERAL

MOVEMENT

DATA

EXFILTRATION

1001010101

1101010010

1011110100

1101001010

REMOTE

ACCESS

Unauthorized

Use of Valid

Accounts

Known &

Unknown

Malware

Command &

Control

Activity

Suspicious

Network

Traffic

Files

Accessed by

Attackers

Valid Programs

Used for Evil

Purposes

Trace

Evidence &

Partial Files

EVIDENCE OF COMPROMISE

Page 15: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

15© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

INITIAL

COMPROMISE

WHAT HAPPENED?

CREDENTIAL

HARVESTINGLATERAL

MOVEMENT

DATA

EXFILTRATION

1001010101

1101010010

1011110100

1101001010

REMOTE

ACCESS

Unauthorized

Use of Valid

Accounts

Known &

Unknown

Malware

Command &

Control

Activity

Suspicious

Network

Traffic

Files

Accessed by

Attackers

Valid Programs

Used for Evil

Purposes

Trace

Evidence &

Partial Files

EVIDENCE OF COMPROMISE

Page 16: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

16© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHAT HAPPENED?

DEEPDIVE SCALE SPEED

✓ ✓ ✓

Page 17: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

17© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHAT DID WE SEE IN 2014?

YEAR 2014 IN REVIEW

TAKE AWAYS

SO WHAT DO WE DO

Page 18: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

18© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

YEAR 2014 IN REVIEW

17%BUSINESS &

PROFESSIONAL

SERVICES

14%RETAIL

7%GOVERNMENT &

INTERNATIONAL

ORGANIZATIONS

6%HEALTHCARE

TAKEN FROM M-TRENDS 2015 REPORT

8%MEDIA &

ENTERTAINMENT

Page 19: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

19© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

YEAR 2014 IN REVIEW

Page 20: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

20© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

YEAR 2014 IN REVIEW

China“PLA Unit 61398”

Russia“APT 28, Russians

are back”

Iran

Syria“Behind the Syrian

Conflict’s Digital

Frontlines”

North Korea

Page 21: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

21© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

China“PLA Unit 61398”

Russia“APT 28, Russians

are back”

Iran

Syria“Behind the Syrian

Conflict’s Digital

Frontlines”

USA

UK

North Korea

YEAR 2014 IN REVIEW

Page 22: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

22© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

YEAR 2014 IN REVIEW

Page 23: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

24© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

ATTACK VECTORS: APT 28 EXAMPLE

Page 24: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

25© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

ATTACK VECTORS: APT 30 EXAMPLE

Page 25: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

26© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

ATTACK VECTORS: MOBILE EXAMPLE

Page 26: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

27© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

2014 TAKE AWAYS

Page 27: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

28© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

2014 TAKE AWAYS

IF YOUR NETWORK CAN BE

COMPROMISED, IT WILL BE

COMPROMISED

Page 28: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

29© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

THERE EXIST FEW RISKS OR

REPERCUSSIONS FOR THE

ATTACKERS

2014 TAKE AWAYS

Page 29: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

30© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

CYBER SPACE IS AN

ASYMETRICAL THEATRE

2014 TAKE AWAYS

Page 30: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

31© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

ATTRIBUTION AND THREAT

INTELLIGENCE MORE IMPORTANT

2014 TAKE AWAYS

Page 31: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

32© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

CYBERCRIME TRADECRAFT

IMPROVED DRASTICALLY

2014 TAKE AWAYS

Page 32: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

33© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

DISCLOSURE MORE PROBABLE

2014 TAKE AWAYS

Page 33: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

34© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

SECURITY POVERTY LINE EXISTS

2014 TAKE AWAYS

Page 34: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

35© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

REDEFINE THE WIN

Page 35: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

36© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

REDEFINE THE WIN

ELIMINATE THE CONSEQUENCES OF CYBER ATTACKS

Page 36: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

37© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

- RISK APETITE -

Page 37: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

38© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

REDEFINE THE WIN

Page 38: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

39© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

REDEFINE THE WIN

TURN SECURITY INCIDENT INTO A 10 MINUTE PROBLEM

Page 39: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

40© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHAT CAN WE EXPECT NEXT?

Page 40: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

41© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHAT CAN WE EXPECT NEXT?

More destructive attacks?

Attribution will be more important

Counter forensics will improve

Attacks will align with conflicts

More threat actors will emerge

More government involvement

A return to standards for non-regulated

industries

More reliance on the cloud

More active defense (Hunting)

Page 41: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

42© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

Q&A

“QUESTIONS NOW ALLOWED, ANSWERS NOT GUARANTEED”

Page 42: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

43© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

WHERE TO CALL IN CASE OF INCIDENT?

INTERNATIONAL: + 1 703 996 3012

[email protected]

Page 43: FROM THE CYBER TRENCHES - Cyber Security Experts ... · © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL 2 ABOUT MANDIANT FOUNDED 2004 EMPLOYEES 2500+ COUNTRIES 40+

44© Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL © Mandiant, a FireEye Company. All rights reserved. CONFIDENTIAL

THE

END