seeing red: improving blue teams through red teamingseeing red: improving blue teams through red...

103
Seeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Upload: others

Post on 08-Jul-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Seeing Red: Improving blue

teams through red teamingDave Hull

Tanium EDR Engineering

Page 2: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

What is this?

Copyright 2015 Tanium Inc. All rights reserved.2

Page 3: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Intro

Copyright 2015 Tanium Inc. All rights reserved.3

Page 4: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Intro

Copyright 2015 Tanium Inc. All rights reserved.6

Page 5: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Intro

Copyright 2015 Tanium Inc. All rights reserved.7

Page 6: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Intro

Copyright 2015 Tanium Inc. All rights reserved.8

Page 7: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Intro

Copyright 2015 Tanium Inc. All rights reserved.9

Page 8: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Intro

Copyright 2015 Tanium Inc. All rights reserved.10

Page 9: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Intro

Copyright 2015 Tanium Inc. All rights reserved.11

Page 10: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.12

Page 11: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Copyright 2015 Tanium Inc. All rights reserved.13

Because it delivers a security incident.

Page 12: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Pen testing delivers… a nice report.

Copyright 2015 Tanium Inc. All rights reserved.14

Page 13: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Because you will play like you practice.

Copyright 2015 Tanium Inc. All rights reserved.15

Page 14: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Copyright 2015 Tanium Inc. All rights reserved.16

Page 15: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

“We run that play every day — end of every

practice,” [Phil] Booth said.

http://www.nytimes.com/2016/04/06/sports/ncaabasketball/villanova-national-championship.html?_r=0

Page 16: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Copyright 2015 Tanium Inc. All rights reserved.18

Page 17: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Because red teaming is quantifiable.

Copyright 2015 Tanium Inc. All rights reserved.19

Page 18: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Mean-time-to-compromise.

Copyright 2015 Tanium Inc. All rights reserved.20

Page 19: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Mean-time-to-detection.

Copyright 2015 Tanium Inc. All rights reserved.21

Page 20: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Why red team?

Mean-time-to-recovery.

Copyright 2015 Tanium Inc. All rights reserved.22

Page 21: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.23

Page 22: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

What is red teaming?

It is not threat modeling.

Copyright 2015 Tanium Inc. All rights reserved.24

Page 23: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

What is red teaming?

It is not vulnerability assessment.

Copyright 2015 Tanium Inc. All rights reserved.25

Page 24: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

What is red teaming?

It is not penetration testing.

Copyright 2015 Tanium Inc. All rights reserved.26

Page 25: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

What is red teaming?

Red teaming is different.

Copyright 2015 Tanium Inc. All rights reserved.27

Page 26: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

What is red teaming?

Some call it “adversary emulation.”

Copyright 2015 Tanium Inc. All rights reserved.28

Page 27: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

What is red teaming?

Some call it “a force-on-force engagement.”

Copyright 2015 Tanium Inc. All rights reserved.29

Page 28: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Red teams:

Have mission objectives.

Copyright 2015 Tanium Inc. All rights reserved.30

Page 29: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Red teams:

Have mission objectives.

Enterprise or domain admin?

Copyright 2015 Tanium Inc. All rights reserved.31

Page 30: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Red teams:

Have mission objectives.

Customer pivot.

Copyright 2015 Tanium Inc. All rights reserved.32

Page 31: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Red teams:

Have mission objectives.

IP theft.

Copyright 2015 Tanium Inc. All rights reserved.33

Page 32: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Red teams:

Have mission objectives.

Burn it all down.

Copyright 2015 Tanium Inc. All rights reserved.34

Page 33: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Red teams:

Have mission objectives.

Test incident response capabilities and procedures.

Copyright 2015 Tanium Inc. All rights reserved.35

Page 34: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Red teams:

Have mission objectives.

Test incident response capabilities and procedures

of the organization... not just the blue team.

Copyright 2015 Tanium Inc. All rights reserved.36

Page 35: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Who responds, if...

Copyright 2015 Tanium Inc. All rights reserved.37

Page 36: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Who responds, if Brian Krebs is your IDS?

Not just the IR team.

Not just the security team.

Copyright 2015 Tanium Inc. All rights reserved.38

Page 37: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.39

Page 38: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Lesson learned

Outliers may be leads.

Copyright 2015 Tanium Inc. All rights reserved.40

Page 39: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Outliers may be leads.

Copyright 2015 Tanium Inc. All rights reserved.41

Page 40: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Outliers may be leads.

Copyright 2015 Tanium Inc. All rights reserved.42

Page 41: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Do you even monoculture?

Copyright 2015 Tanium Inc. All rights reserved.43

Page 42: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Dan Geer:

Copyright 2015 Tanium Inc. All rights reserved.44

• "Internet security is quite possibly the most

intellectually challenging profession on the planet... for

two reasons... complexity... and rate of change [are] your

enemy.

Page 43: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Loathsome long tails...

Copyright 2015 Tanium Inc. All rights reserved.45

Page 44: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

“... ever present everywhere...”

Copyright 2015 Tanium Inc. All rights reserved.46

Page 45: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Build systems that automate

data collection, analysis and remediation.

Copyright 2015 Tanium Inc. All rights reserved.47

Page 46: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Blue’s Prime Directive: Remediation

Copyright 2015 Tanium Inc. All rights reserved.48

Page 47: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Remediation, like security, is a process not a product.

Copyright 2015 Tanium Inc. All rights reserved.49

Page 48: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Investigate. Remediate. Repeat.

Copyright 2015 Tanium Inc. All rights reserved.50

Page 49: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.51

Page 50: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Who should be red teaming?

Any organization that may have a security incident.

Copyright 2015 Tanium Inc. All rights reserved.52

Page 51: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Who should be red teaming?

Any organization with something worth protecting.

Copyright 2015 Tanium Inc. All rights reserved.53

Page 52: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Who should be red teaming, practically speaking?

Organizations meeting the previous criteria and having:

Some monitoring.

Some defenses.

Some IR capabilities.

Copyright 2015 Tanium Inc. All rights reserved.54

Page 53: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Who should be red teaming?

Probably an internal team, but not just the security team.

Copyright 2015 Tanium Inc. All rights reserved.55

Page 54: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Lesson learned

Documentation is wrong.

Code comments are wrong.

Assumptions are wrong.

Copyright 2015 Tanium Inc. All rights reserved.56

Page 55: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.57

Page 56: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

When should you red team?

Two, maybe three times a year.

Copyright 2015 Tanium Inc. All rights reserved.58

Page 57: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.60

Page 58: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Practicalities

Have Rules of Engagement.

Copyright 2015 Tanium Inc. All rights reserved.61

Page 59: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Get approval from management and legal.

Copyright 2015 Tanium Inc. All rights reserved.62

Page 60: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Copyright 2015 Tanium Inc. All rights reserved.63

Page 61: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

No accessing or tampering with customer data.

Copyright 2015 Tanium Inc. All rights reserved.64

Page 62: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

No accessing or tampering with real customer data.

Copyright 2015 Tanium Inc. All rights reserved.65

Page 63: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

No outages.

Copyright 2015 Tanium Inc. All rights reserved.66

Page 64: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

No weakening of existing

controls.

Copyright 2015 Tanium Inc. All rights reserved.67

Page 65: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Give the red team access.

Copyright 2015 Tanium Inc. All rights reserved.68

Page 66: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Give the red team source code.

Copyright 2015 Tanium Inc. All rights reserved.69

Page 67: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Give the red team architecture diagrams.

Copyright 2015 Tanium Inc. All rights reserved.70

Page 68: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Keep the blue team in the dark.

Copyright 2015 Tanium Inc. All rights reserved.71

Page 69: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement – Don’t let blue do this

Copyright 2015 Tanium Inc. All rights reserved.72

Page 70: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Real incidents trump red team incidents.

Copyright 2015 Tanium Inc. All rights reserved.73

Page 71: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Red incidents are core hours only.

Copyright 2015 Tanium Inc. All rights reserved.74

Page 72: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Red incidents are core hours only,

plus a little.

Copyright 2015 Tanium Inc. All rights reserved.75

Page 73: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Cross team collaboration.

Copyright 2015 Tanium Inc. All rights reserved.76

Page 74: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Establish a situation room.

Copyright 2015 Tanium Inc. All rights reserved.77

Page 75: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Designate incident and investigative leads.

Copyright 2015 Tanium Inc. All rights reserved.78

Page 76: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Rules of engagement

Delegate and PM.

Copyright 2015 Tanium Inc. All rights reserved.79

Page 77: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Situation normal...

Investigate.

Copyright 2015 Tanium Inc. All rights reserved.80

Page 78: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Situation normal, practice how you want to play

Document.

Copyright 2015 Tanium Inc. All rights reserved.81

Page 79: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Situation normal, practice how you want to play

Report.

Copyright 2015 Tanium Inc. All rights reserved.82

Page 80: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Situation normal, practice how you want to play

Copyright 2015 Tanium Inc. All rights reserved.83

Page 81: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Situation normal, practice how you want to play

Plan for remediation.

Copyright 2015 Tanium Inc. All rights reserved.84

Page 82: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Situation normal, practice how you want to play

Execute remediation.

Copyright 2015 Tanium Inc. All rights reserved.85

Page 83: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Situation normal, practice how you want to play

Post remediation monitoring.

Copyright 2015 Tanium Inc. All rights reserved.86

Page 84: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Take aways

Postmortems.

Copyright 2015 Tanium Inc. All rights reserved.87

Page 85: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: Who?

Stakeholders, blue team, red team.

Copyright 2015 Tanium Inc. All rights reserved.88

Page 86: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: What?

No blame games.

Copyright 2015 Tanium Inc. All rights reserved.89

Page 87: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: What?

But hold yourself accountable.

Copyright 2015 Tanium Inc. All rights reserved.90

Page 88: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: Story time.

Blue team goes first.

Copyright 2015 Tanium Inc. All rights reserved.91

Page 89: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: Tell all.

Copyright 2015 Tanium Inc. All rights reserved.92

Page 90: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: The facts.

Red team goes second.

Copyright 2015 Tanium Inc. All rights reserved.93

Page 91: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: Mind the gap.

Blue Red

Copyright 2015 Tanium Inc. All rights reserved.94

Goal: close gap over time

Page 92: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Postmortem: Takeaways.

All teams get bugs, feature requests.

Copyright 2015 Tanium Inc. All rights reserved.95

Page 93: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.96

Page 94: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Lesson learned

Just-In-Time admin (JIT).

Copyright 2015 Tanium Inc. All rights reserved.98

Page 95: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Lesson learned

Dedicated admin workstations.

Copyright 2015 Tanium Inc. All rights reserved.101

Page 96: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Lesson learned

Zero human generated passwords.

Copyright 2015 Tanium Inc. All rights reserved.102

Page 97: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Lesson learned

2FA everywhere.

Copyright 2015 Tanium Inc. All rights reserved.103

Page 98: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Lesson learned

Don’t trust. Verify.

Copyright 2015 Tanium Inc. All rights reserved.104

Page 99: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Agenda

• Teaser

• Why red teaming

• What is red teaming

• Highlights and lessons learned

• Who should be red teaming

• When

• Practicalities of red teaming

• Conclusion

Copyright 2015 Tanium Inc. All rights reserved.105

Page 100: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Conclusion

Red teaming is hard.

Copyright 2015 Tanium Inc. All rights reserved.106

Page 101: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Conclusion

Real incidents may be harder.

Copyright 2015 Tanium Inc. All rights reserved.107

Page 102: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Conclusion

Practice how you want to play.

Copyright 2015 Tanium Inc. All rights reserved.108

Page 103: Seeing Red: Improving blue teams through red teamingSeeing Red: Improving blue teams through red teaming Dave Hull Tanium EDR Engineering

Thank you!

[email protected]