[00:01.910 --> 00:02.850] Great, thank you. [00:06.970 --> 00:07.370] Thanks. [00:07.610 --> 00:11.070] Yeah, so the WikiLeaks thing was quite interesting. [00:12.170 --> 00:14.770] So a little bit about me and some of the guys. [00:15.450 --> 00:18.150] To start off with, I'm the team leader for Proactive Risk. [00:18.350 --> 00:19.890] We're a red team type company. [00:20.450 --> 00:23.510] I'm also sitting on the board of directors for the OWASP Foundation. [00:23.850 --> 00:30.630] So one of the things that was mentioned with WikiLeaks, which I completely support, is the ability to write open software and to evangelize around the world. [00:30.730 --> 00:33.190] The software that we use actually does affect everyone's life. [00:33.590 --> 00:39.290] For those who don't know, OWASP is the Open Web Application Security Project. [00:39.750 --> 00:45.950] We have 21,000 members, about 160 chapters worldwide, and 118 different projects. [00:45.950 --> 00:50.930] Everything from testing guides, how to break stuff, to how to do secure development, etc. [00:51.190 --> 00:52.950] So definitely something worth looking at. [00:53.770 --> 00:57.570] Here in New York City, I head up the team with the chapter. [00:58.050 --> 00:59.290] Many of the members of the team are here. [00:59.530 --> 01:03.310] I'd like to quickly introduce Blake Cornell, Tom Ryan, Kwai, and Vlad. [01:04.610 --> 01:06.630] Those members are of the OWASP team. [01:07.450 --> 01:11.390] And there's a lot of information here. [01:11.510 --> 01:14.950] So obviously, I come out of the Marine Corps, DOD, and I've been working in the space for quite some time. [01:15.690 --> 01:19.650] With four kids, it sounds like I'm raising pirates and ninjas these days. [01:20.490 --> 01:23.410] Basically, what I have is I have a three-year-old and a five-year-old that are pirates. [01:23.410 --> 01:27.850] And the rest that you don't see on the screen are ninjas, because they don't want to be a part of these talks, which is quite funny. [01:28.950 --> 01:37.450] So the talk outline is going to focus on a couple things that have been getting a lot of publicity, kind of the concept of what is a red team, how does it work. [01:37.550 --> 01:48.790] And we're going to speak a little bit about red team, the components of the definitions, the various ways that these things come together, when red teaming is actually appropriate within an organization, adversarial remodeling. [01:49.470 --> 01:50.650] Wow, those are bright lights. [01:51.310 --> 01:52.870] And also thinking like the bad guy. [01:52.990 --> 01:54.170] So we're going to go through some scenarios. [01:54.170 --> 01:56.090] There's going to be a lot of conversation. [01:56.090 --> 01:57.630] It's going to happen between pieces of the talk. [01:57.770 --> 01:58.570] It's pretty interactive. [01:59.270 --> 02:04.510] There was also 250 handouts that were supposed to arrive that are not here, even though they were an hour late. [02:04.710 --> 02:06.790] So that's unfortunate, but we'll push through that. [02:07.070 --> 02:09.590] And again, we're going to go through some attack exercises as well. [02:10.010 --> 02:13.650] So, red teaming as defined by the U.S. [02:13.730 --> 02:18.230] Army, potentially the folks that were involved in the prior video. [02:18.390 --> 02:18.690] We'll go there. [02:19.290 --> 02:32.710] Certainly a structured process to look at the context of an operational environment to basically determine if, in fact, credible threat could potentially cause damage or harm to the environment, right? [02:32.890 --> 02:42.590] So the concept of looking at an organization or a government sort of component there of determining, could this facility or system be compromised in the event of an attack by our adversary? [02:42.590 --> 02:47.810] If so, potentially OPSEC awareness would fall into this category where you have a defender and an attacker. [02:47.910 --> 02:49.750] The attacker kind of would think from the attacker side. [02:49.890 --> 02:51.430] The defender thinks from the defender side. [02:51.890 --> 02:53.870] And kind of a tabletop exercise would start. [02:56.090 --> 02:59.710] SANS defines it a little bit differently for some that know who SANS is. [03:00.190 --> 03:02.890] SANS is kind of more focused on the network side. [03:02.950 --> 03:05.150] So we're going to spend a little bit of time in that area as well. [03:05.150 --> 03:12.350] But the SANS definition is definitely focused more on what you're used to with the pen-testing or the network sort of side of things. [03:12.790 --> 03:16.590] The one I like the best is actually red teaming defined as the following. [03:17.710 --> 03:22.510] Authorized, keyword, authorized, adversarial based assessment services for defensive purposes. [03:22.730 --> 03:25.870] That's kind of the concept of what a red team is used for. [03:27.290 --> 03:36.070] Critical infrastructure is kind of the focal point for me, but certainly the focal point for these services that have been provided for many, many years. [03:36.790 --> 03:43.990] Looking at the organizations across the board here, these are about 18 areas of critical infrastructure that are deemed important to society. [03:44.330 --> 03:48.250] Those being financial services, food, gas, power, electric, etc. [03:48.650 --> 03:53.510] These are all areas that, you know, any one of them could substantially impact our social-economical conditions here. [03:53.890 --> 03:56.210] And certainly our people of water, gas, etc. [03:56.410 --> 03:58.390] So these are what's considered critical infrastructure. [03:58.850 --> 04:03.690] Joe that sells baskets online might be an important Joe, but doesn't fall into that particular category. [04:06.170 --> 04:09.750] Red team engagements typically have stakeholders, as any other project does. [04:10.230 --> 04:15.770] These projects could be various individuals, but it typically involves a lot of individuals within an organization. [04:16.130 --> 04:31.070] So whether you're the owner of the organization, you're the head of the organization's focal point of ensuring that logistics happen to provide value to society, developers, designers, maintainers, etc. [04:31.070 --> 04:37.570] There's many different people that are typically a part of the involvement of the organization that does testing. [04:38.990 --> 04:41.070] So, security to the non-security professional. [04:42.670 --> 04:45.550] Historically these things have been happening for many, many years, right? [04:45.730 --> 04:48.270] So they constantly get reviewed and updated. [04:48.450 --> 04:54.910] But things like, you know, DMZs, stamps, signatures, illusion, these things are not new in any stretch of the imagination. [04:54.910 --> 04:59.130] But today, being 2010, they continue to evolve. [04:59.550 --> 05:03.810] The Trojan horse, you know, being one of the ones that everyone knows that the big horse pushed it to the castle. [05:04.210 --> 05:08.710] These type of concepts are constantly being reinvented within our own space here. [05:08.810 --> 05:16.850] Because what we are trying to do as a technology space community is trying to drive these things a bit forward from both maybe the attacker as well as the builder. [05:16.850 --> 05:18.870] So you have the builder-breaker sort of philosophy here. [05:19.850 --> 05:21.930] So, again, red teaming defined. [05:22.470 --> 05:24.270] Authorized, adversarial-based assessments. [05:24.510 --> 05:27.450] Activities performed for defensive purposes will be used for this particular talk. [05:27.970 --> 05:29.010] Keyword there being authorized. [05:29.530 --> 05:33.290] The person or the entity with legal control of the facility or systems to be assessed. [05:33.730 --> 05:39.050] These are the individuals that typically can invoke these sort of assessments or reviews. [05:39.610 --> 05:41.750] It is adversarial-based, alright? [05:41.950 --> 05:45.250] So it's not... we'll get into that in a second. [05:45.250 --> 05:56.350] The red team activities are typically guided by one or more adversaries with the knowledge across a team that has various skills, achievements, and resources relative to the culture that we're trying to assess or test. [05:56.910 --> 05:57.150] Okay? [05:57.610 --> 06:00.490] So this is actually a fairly important slide. [06:01.090 --> 06:06.270] This slide kind of illustrates the different types of red team slash red team activities. [06:07.290 --> 06:11.630] Some of you may be more familiar with a... we'll get that in a second. [06:11.630 --> 06:17.890] But design assurance in itself has red team folks that are typically assigned to the design of a system. [06:18.490 --> 06:24.790] This is not going to be any sort of a fancy kick in the door, social engineer, trick somebody with a phishing attack sort of a conversation. [06:25.090 --> 06:29.590] It's going to be diligent individuals that are in potentially design assurance phase. [06:29.730 --> 06:36.990] They're going to look at an organization's new widget and determine if that power system is going to stand up to normal threats and normal attacks. [06:37.610 --> 06:46.590] Looking at red team gaming, again, this could be more of exercises where that looking across the table and determining, in fact, kind of role playing, if you will. [06:47.730 --> 06:53.810] Benchmarking sort of teams that look against systems to measure their process or progress compared to others in a similar class. [06:55.190 --> 06:56.270] Operational teams, right? [06:56.750 --> 07:02.590] Analytical and then the ones that are started there is the penetration testing teams, which is we're going to kind of spend a little time in that particular area. [07:02.590 --> 07:06.850] So, when is red teaming appropriate? [07:08.250 --> 07:11.710] It's not appropriate for simple systems, right? [07:11.730 --> 07:13.710] It's not appropriate for a simple system. [07:13.990 --> 07:19.190] Here's an environment that's Joe's basket weaving and let's determine how vulnerable it may be. [07:19.390 --> 07:25.510] But it is certainly appropriate for complex systems that are intertwined that are tied potentially to critical infrastructure. [07:26.750 --> 07:28.870] Systems with unknown consequences, right? [07:28.870 --> 07:29.790] Those are appropriate. [07:30.070 --> 07:35.730] Where that process control systems that can result in human life, death, those are fairly important. [07:35.970 --> 07:43.590] So, these are systems that you might want to have teams of individuals that are focused in particular areas, test systems because the outcome could be life, right? [07:43.670 --> 07:44.430] It could be human life. [07:44.570 --> 07:46.650] So, there's a balance there. [07:47.050 --> 07:59.150] One of the phrases I've always said at certain engagements is I sit down and I tell the customer, I say, so, if this testing activity goes sideways, what potentially is the worst case outcome? [07:59.950 --> 08:05.650] And they're like, well, you know, we'll have a financial disruption in our business, cause, you know, stock price to change, et cetera. [08:05.790 --> 08:07.030] And I say, okay, well, back up. [08:07.450 --> 08:09.110] Is anyone potentially going to die? [08:09.250 --> 08:11.390] Is there any sort of, you know, impact to human life? [08:11.610 --> 08:14.150] And their answer is like, no, no, no, just it's like a financial thing. [08:14.150 --> 08:14.910] I'm like, oh, okay. [08:15.150 --> 08:16.110] Well, let's go get some coffee. [08:16.230 --> 08:22.290] And when we come back, we'll talk about your, you know, your financial law system because that obviously falls into the category of fairly important. [08:22.310 --> 08:26.910] But at the end of the day, all activities should be looked upon with human life being fairly important, I would think. [08:29.510 --> 08:41.030] If you're not ready for an extreme answer, organizations typically don't contract full-scope services to a third party, unless they're ready to have a real reality check as to potentially is there any kinks in the armor, right? [08:41.230 --> 08:45.810] The concept there is being that if you're going to look full-scope, you're going to look at things that are going to be potentially in different areas. [08:45.990 --> 08:53.310] You're going to look at areas that might be, you know, physical, electronic, you know, tying into wireless, network, social engineering, people, humans, et cetera. [08:53.670 --> 08:54.830] The scope gets very, very wide. [08:55.810 --> 08:58.870] So not all adversaries are certainly equal in their capabilities. [08:59.150 --> 09:04.650] And what's really, really important with most organizations is determining potentially what their threat is. [09:04.650 --> 09:10.570] So if the organization is concerned, potentially, I'll use a couple to throw it out there. [09:10.930 --> 09:21.190] If the organization is potentially concerned with, let's say, Greenpeace as potentially being a problem in their world because, let's say, they do experiments on animals, as an example. [09:21.470 --> 09:26.110] Well, that would obviously be an adversary with certain capabilities and funding, et cetera. [09:26.110 --> 09:34.450] And this organization to the right potentially would have impact if that organization was to want to publicize or conduct a smear campaign against them. [09:34.570 --> 09:38.650] So looking in the public sector, that might take sense. [09:39.150 --> 09:58.010] Whether if we're looking at power or gas here in the city, if we're looking at, you know, critical infrastructure systems, electricity, right, blackouts here in New York, et cetera, those potential systems could be classified that are going to be looked upon as potentially adversaries that are going to spend an awful lot of time to determine if they can have command and control over particular [09:58.010 --> 09:58.510] environments. [09:58.790 --> 10:02.250] So it's completely different based on the scope of the project. [10:02.430 --> 10:05.030] And the good part about it, I guess, is each one is quite different. [10:07.110 --> 10:15.390] Disgruntled employees, administrators, insiders, et cetera, these are always, of course, the most difficult people to guard against because they have legitimate access, right? [10:15.390 --> 10:16.190] They're in the systems. [10:16.310 --> 10:17.650] They have access to certain controls. [10:17.890 --> 10:19.510] They know where the skeletons are hidden, et cetera. [10:20.030 --> 10:30.790] And in many cases, whether they quote-unquote put back doors in themselves or they simply leave things open because they really haven't spent the time to close them, at the end of the day, these individuals become fairly important. [10:31.350 --> 10:39.130] So with that, the motivation in the attacker types typically align into three different buckets. [10:39.950 --> 10:41.110] And this is actually interesting. [10:41.650 --> 10:48.790] I had worked for an organization that used these sort of terms to speak about a particular area of their business. [10:49.050 --> 11:02.110] I look at it more as a very true statement that you have the random opportunistic adversary, the individual that's going to look to make a quick buck, going to go out there and try to find a quick system to take advantage of. [11:02.190 --> 11:03.250] It could be any organization. [11:03.430 --> 11:05.170] Maybe they want, you know, PII data, et cetera. [11:05.170 --> 11:08.370] And they're going to go out there and attempt that any way they possibly can. [11:09.350 --> 11:12.130] But kind of random, regardless of who the organization is. [11:12.630 --> 11:14.730] You may also then have individuals that are more targeted. [11:14.870 --> 11:20.010] A team of people or several people that want to focus on potentially an organization that they're going to go after today. [11:20.310 --> 11:26.410] A credit union, a small business, an organization that might have the goods that they want, the treasure that they're looking to find. [11:26.410 --> 11:28.530] And then lastly, the fully targeted adversary. [11:28.970 --> 11:31.210] The fully targeted adversary could be the people that are on stage. [11:31.690 --> 11:37.350] The fully targeted team is going to be individuals that have various expertise in various different areas that can assemble for one purpose. [11:37.670 --> 11:40.870] To put together a whiteboard conversation of exactly how do we break this? [11:40.970 --> 11:41.570] How do we steal this? [11:41.630 --> 11:42.470] How do we take this down? [11:42.750 --> 11:47.390] And at the end of the day, it's probably going to be quite successful because most organizations have never been punched in the face. [11:47.570 --> 11:49.310] They don't understand what it means to take a punch. [11:49.310 --> 11:55.630] The conversation of saying, you know, are we secure in many different areas needs to be tested and determined. [11:56.650 --> 11:58.970] So, thinking like the bad guy. [11:59.490 --> 12:06.250] So, of course, what vulnerabilities are the most important to the adversary largely depends on the objectives, right? [12:06.370 --> 12:11.890] So, if you're looking for treasure information, you know, goal, that might be one particular component. [12:12.050 --> 12:13.110] Maybe it's intellectual property. [12:13.250 --> 12:18.970] Maybe it's the cure for cancer that, you know, there's rumors that we've cured cancer but we're not going to do it because of the money that's tied to the industry. [12:18.970 --> 12:23.590] There's all sorts of interesting conspiracy theories as we have at HOPE every year or every two years. [12:24.890 --> 12:34.730] There's currently, you know, red teaming is kind of a dark art but at the same time, it's becoming a little more formalized with more individuals involved in the process. [12:35.730 --> 12:40.050] Experience really comes from analyzing the details of attacks prior, right? [12:40.170 --> 12:48.010] Systems that have been broken into, compromise that have happened, military operations that have happened successfully, such as taking down command and control systems, radar stations, etc. [12:48.150 --> 12:50.010] before attacks are made. [12:50.650 --> 13:00.770] So, lending yourself to these different experiences, you can quickly apply to civilian sort of organizations because it's very important to understand what the capabilities of the target you're attacking. [13:01.390 --> 13:14.150] So, red teamers, you know, certainly must use extreme exercise and prudence and also restraint in most cases because at the end of the day, I kind of call there's typically three different types of red teams, right? [13:14.250 --> 13:17.970] The first type of red team is the person you call on the phone and say, hey, can you hack into our network? [13:17.990 --> 13:20.550] And they say, sure, it'll cost you a lot of money, you'll be happy to do it, right? [13:20.870 --> 13:22.490] Kind of once a year sort of type of thing. [13:23.050 --> 13:28.990] Then you're going to have another set of individuals that might say, yeah, we're going to go ahead and use a commercial tool or a process, etc. [13:29.150 --> 13:41.010] We're going to be very infinite in scope and we're going to look at an environment, let's say public-facing systems, and come up with a result and say, based on the commercial review of what we've done in the manual validation, yeah, you're good to go. [13:41.090 --> 13:41.870] You're totally secure. [13:42.370 --> 13:49.550] But then you have the other group of folks that are kind of more involved in the conversation of, well, any way possible, let's bring it down. [13:49.890 --> 13:55.950] So, for some in the room, I think you should know some of these people on here because they work with us all the time. [14:00.760 --> 14:06.640] The lead team of high-tech thieves who have infiltrated some of the most secure locations in the world. [14:06.720 --> 14:12.200] They were able to grab all of our clients' information, their social security numbers, their bank account information. [14:14.000 --> 14:15.780] Experts in corporate espionage. [14:15.940 --> 14:17.420] Are you able to see the numbers? [14:17.800 --> 14:19.360] And masters of deception. [14:19.580 --> 14:21.240] The guy that's coming down to work on your computer today. [14:21.600 --> 14:22.920] But they are not criminals. [14:23.180 --> 14:25.520] They are paid professionals. [14:25.520 --> 14:26.360] We've got to do it. [14:27.160 --> 14:30.420] Hired to put million-dollar security systems to the test. [14:30.540 --> 14:31.100] We took it out. [14:31.200 --> 14:31.560] It's off. [14:31.660 --> 14:33.140] We always do run the risk of getting gone. [14:33.300 --> 14:34.900] I could break my neck right here and die. [14:35.100 --> 14:38.440] If I was to break into this particular facility, I would not steal one car. [14:38.540 --> 14:39.800] I would steal every single one. [14:45.030 --> 14:46.110] So, quick show of hands. [14:46.330 --> 14:47.170] It's kind of dark in here. [14:47.610 --> 14:48.310] Quick show of hands. [14:48.370 --> 14:51.210] How many folks here are familiar with Chris Nickerson, guys from Tiger Team? [14:52.070 --> 14:52.430] Excellent. [14:52.430 --> 15:02.390] So, having individuals in our circle of community, if you will, that are making it very well known and kind of getting into the space. [15:03.170 --> 15:08.390] It's a very good thing for the industry because organizations have a false sense of security. [15:08.710 --> 15:13.270] At the same time, there should be always concern relative to what I call double agents and exit strategies. [15:13.750 --> 15:20.210] The concept there is that these individuals, the teams that perform such functions, typically have access to very, very sensitive data, right? [15:20.330 --> 15:22.830] Very sensitive information from various attack vectors. [15:23.090 --> 15:27.690] At the end of the day, I've actually had an interesting conversation with a colleague. [15:27.890 --> 15:32.390] We sat there transferring money through the Federal Reserve System and I was like, $5? [15:32.810 --> 15:34.610] Let's add some more zeros and call helicopters. [15:34.890 --> 15:39.430] Like, it was very interesting on exactly what could happen during some of these assessments. [15:39.430 --> 15:46.090] So, the concept is that it's always important that you don't end up being the bad guy at the end of the conversation. [15:47.970 --> 16:01.470] Whether it be, you know, taking down systems or breaking into organizations and accessing systems from their involvement, you know, the methodology tied back to typical red teaming is kind of straightforward, right? [16:01.590 --> 16:04.870] So, we're trying to illustrate some of that and put some information to it. [16:04.930 --> 16:06.570] Then we're going to go through some exercises with the lights on. [16:07.510 --> 16:10.230] The first thing about the methodology is kind of the planning, right? [16:10.350 --> 16:12.190] So, the conversation of what are we trying to understand? [16:12.350 --> 16:16.930] What analysis are we trying to accomplish on behalf of the question? [16:17.030 --> 16:18.430] What is the question we're trying to solve? [16:19.070 --> 16:19.850] Intellectual property? [16:20.350 --> 16:21.710] What's our nightmare consequences? [16:22.070 --> 16:23.770] What is our problem that we're trying to determine? [16:24.290 --> 16:26.350] Are there proper constraints or boundaries around? [16:26.870 --> 16:28.690] Very important to kind of put that into the scope. [16:29.710 --> 16:32.990] The data collection component is fairly important as well. [16:33.530 --> 16:36.230] Relative to the systems, designs, etc. [16:36.450 --> 16:42.210] Because again, depending on what type of red team activity you're performing, in many cases it could be, I guess we'll call it open book review, right? [16:42.270 --> 16:49.510] Where you're working with the organization to bring in the subject matter experts that are experts in a particular field, looking at systems and being able to distinguish that. [16:51.110 --> 16:55.270] Characterization is being able to derive the target opportunities relative to the organization. [16:55.390 --> 16:57.790] What does the business really do in the commercial space? [16:57.990 --> 16:59.110] What's their real business, right? [16:59.110 --> 17:00.410] It's not their mail server, right? [17:00.490 --> 17:02.830] It may not be their file server, potentially. [17:03.290 --> 17:05.990] But at the end of the day, what exactly does the organization do? [17:06.070 --> 17:06.830] How are they categorized? [17:07.330 --> 17:15.630] The analysis part of it is really, really important as well because the vulnerabilities that are potentially found within an organization, these could be human, these could be technical, etc. [17:16.150 --> 17:20.350] Putting them together, kind of painting the picture for an organization is really, really important. [17:21.130 --> 17:25.950] What serious vulnerabilities must be successful to be exploited to achieve goals? [17:25.950 --> 17:28.930] Again, some of these actually can't be actually replicated. [17:30.270 --> 17:42.710] Sometimes table exercises are enough to say that if this scenario did take place, if these three things that we can visually show you were able to be accomplished, step four and five could lead to human death. [17:43.350 --> 17:46.010] Those situations are quite interesting because it shows a bit more. [17:46.590 --> 17:48.170] So, if we can turn the lights on real quick. [17:48.310 --> 17:49.650] We've got a few exercises to run through. [17:52.700 --> 18:00.180] Okay, so in the first scenario here, what I'd like to try and accomplish is kind of show a couple of things. [18:00.280 --> 18:00.980] We'll get to that later. [18:01.420 --> 18:05.840] But in the first scenario here, I'd like to take a look at the slide and read through this. [18:05.900 --> 18:08.260] And I'm actually wanting people to shout out the answers, right? [18:08.600 --> 18:11.280] So, as an electrician, in front of you is a light. [18:11.580 --> 18:12.320] Here we have lights. [18:12.780 --> 18:15.280] Hanging from the ceiling and behind you is a light switch on the wall. [18:15.820 --> 18:17.180] The light is currently on. [18:17.180 --> 18:18.260] So, shout out. [18:18.420 --> 18:19.740] And we'll try to write them down here. [18:20.180 --> 18:21.860] The five ways to turn off the light. [18:22.060 --> 18:22.620] Break the bulb. [18:23.300 --> 18:23.960] Break the bulb. [18:26.140 --> 18:27.000] Unscrew the bulb. [18:27.820 --> 18:29.400] Unscrew the bulb or blow out the bulb. [18:29.600 --> 18:29.640] Okay. [18:32.180 --> 18:33.080] So, cut the electricity. [18:33.520 --> 18:35.020] Ask someone to turn it off for you. [18:35.460 --> 18:36.220] That's a really good one. [18:36.240 --> 18:37.540] Ask somebody else to turn it off for you. [18:39.520 --> 18:40.040] Good one. [18:41.060 --> 18:42.140] Let's go on to the next one. [18:42.640 --> 18:44.640] Five components of a functioning light. [18:45.340 --> 18:45.660] One. [18:45.660 --> 18:45.860] Two elements. [18:46.360 --> 18:46.680] One. [18:47.320 --> 18:47.640] Power. [18:47.940 --> 18:48.180] Less. [18:48.560 --> 18:48.880] Vacuum. [18:50.240 --> 18:51.040] I'll go with that one. [18:52.460 --> 18:52.960] And current. [18:53.120 --> 18:53.440] Five, right? [18:53.580 --> 18:55.640] So, again, there's usually ten of these. [18:55.760 --> 18:58.340] I'm trying to go quickly because there's a lot of stuff to dive into. [18:58.980 --> 19:00.500] Five ways to tell if the light is off. [19:00.500 --> 19:02.180] Again, based on the premise of you're in the building. [19:02.380 --> 19:03.240] You're in the room. [19:03.380 --> 19:04.200] So, how do you tell if the light's off? [19:04.600 --> 19:04.920] HC. [19:05.560 --> 19:05.860] Okay. [19:06.600 --> 19:06.920] Two. [19:07.220 --> 19:07.460] Three. [19:08.120 --> 19:09.460] And whatever it is will eat you. [19:09.560 --> 19:09.960] The groove. [19:10.100 --> 19:10.480] The groove. [19:12.200 --> 19:12.520] Excellent. [19:13.420 --> 19:14.460] This one could be fun. [19:14.460 --> 19:17.420] Five ways to prevent someone from being able to turn off the light. [19:17.560 --> 19:17.940] Shoot them. [19:18.320 --> 19:18.700] Punch them. [19:21.020 --> 19:21.880] Put up a sign. [19:22.240 --> 19:22.420] Okay. [19:25.380 --> 19:27.640] Don't you know there actually is no light? [19:27.860 --> 19:28.100] Aw. [19:29.100 --> 19:31.200] I want to jump ahead to scenario five. [19:31.420 --> 19:33.520] And, again, these are referenced from ISOCON from Peter Herzog. [19:33.620 --> 19:37.900] He did a series called Jack, which is really, really interesting in this red team exercise component. [19:38.380 --> 19:39.900] So, now, let's change gears a bit. [19:40.400 --> 19:41.160] You're a soldier. [19:41.520 --> 19:41.720] All right. [19:41.820 --> 19:43.880] You're a soldier in full field gear during war. [19:44.340 --> 19:44.600] Okay. [19:44.740 --> 19:46.580] So, let's go back to maybe our video. [19:47.160 --> 19:49.840] You're stationed at the only bridge or potential crossing, right? [19:50.000 --> 19:53.220] And, give us five ways to prepare for the enemy coming. [19:53.640 --> 19:54.540] Dig in. [19:54.620 --> 19:54.860] One. [19:55.140 --> 19:55.780] Dig in. [19:56.080 --> 19:56.160] Two. [19:57.620 --> 19:58.760] I'm just looking for a clear answer. [19:58.880 --> 19:59.520] I'm not giving for a right. [19:59.520 --> 19:59.980] Mind the bridge. [20:00.120 --> 20:00.720] Mind the bridge. [20:00.860 --> 20:00.980] Two. [20:01.700 --> 20:02.260] Air strike. [20:02.440 --> 20:02.580] Three. [20:02.860 --> 20:04.600] More intelligence. [20:04.600 --> 20:04.880] Okay. [20:05.000 --> 20:05.660] We'll take that as four. [20:05.880 --> 20:07.720] Change the road sides away from the bridge. [20:08.460 --> 20:08.920] That's one. [20:08.980 --> 20:09.400] That one's cool. [20:09.500 --> 20:11.020] Change the road sides away from the bridge. [20:11.120 --> 20:11.640] That might work. [20:11.820 --> 20:12.580] It depends who they are. [20:13.860 --> 20:14.120] Five. [20:15.020 --> 20:15.580] That's awesome. [20:15.860 --> 20:17.960] Five ways to prevent the enemy from cross... [20:17.960 --> 20:18.440] Oh, we did that one. [20:18.500 --> 20:18.620] Sorry. [20:18.780 --> 20:21.680] Five ways to discern the friendly bridge users from the enemy. [20:22.000 --> 20:22.080] Right? [20:23.120 --> 20:23.880] Which way they're going? [20:24.140 --> 20:25.280] Ask them identify themselves. [20:25.400 --> 20:25.760] Guidons. [20:26.420 --> 20:26.780] Guidons. [20:27.200 --> 20:28.220] Challenge response, right? [20:28.400 --> 20:29.700] So, there's a couple different areas there, too. [20:30.400 --> 20:33.620] And, five problems the enemy could cause if they crossed the bridge. [20:33.620 --> 20:34.360] You did. [20:34.860 --> 20:35.180] One. [20:35.880 --> 20:36.240] Literally. [20:36.680 --> 20:36.780] Yeah. [20:39.680 --> 20:40.040] Two. [20:40.820 --> 20:41.180] Excellent. [20:41.780 --> 20:42.780] So, let's go to the last... [20:42.780 --> 20:44.060] The second to last one here. [20:44.160 --> 20:46.040] So, this one's kind of near and dear to some people's hearts. [20:46.580 --> 20:48.300] You're a computer help desk person, right? [20:48.380 --> 20:53.300] You work the telephone at the help desk for a large corporation dedicated to assisting its employees with support questions. [20:53.480 --> 20:55.100] Because they are always so simple. [20:55.760 --> 20:56.480] Are there any employees? [20:56.860 --> 20:57.400] There you go. [20:57.500 --> 20:58.040] So, first question. [20:58.140 --> 20:59.820] Five questions you may ask to diagnose the problem. [20:59.820 --> 21:00.820] Start off with... [21:02.480 --> 21:03.880] Is it plugged in? [21:04.020 --> 21:04.820] Is it plugged in? [21:04.860 --> 21:05.600] Is it plugged in? [21:05.640 --> 21:06.180] Is it plugged in? [21:06.380 --> 21:06.940] Is it plugged in? [21:07.080 --> 21:07.240] Excellent. [21:07.480 --> 21:08.100] How did you break it? [21:08.420 --> 21:10.020] How did you break it? [21:10.080 --> 21:10.520] Good question. [21:11.980 --> 21:13.040] How did you try to fix it? [21:13.100 --> 21:13.320] Excellent. [21:14.180 --> 21:14.600] Exactly. [21:14.880 --> 21:15.280] Same question. [21:16.520 --> 21:19.540] Five resources you might use to help solve the problem. [21:24.460 --> 21:26.660] Two, three... RTFM. [21:26.780 --> 21:27.120] Love that one. [21:29.540 --> 21:30.600] Last time we logged in. [21:30.740 --> 21:31.100] Good, good. [21:35.080 --> 21:38.600] Five concerns the caller may have with following your advice. [21:41.040 --> 21:42.060] Fix it for me. [21:47.540 --> 21:50.560] And what are the five ways we can assure better service? [21:57.590 --> 21:59.150] Our support employees. [22:01.130 --> 22:01.990] Here's the last one. [22:02.150 --> 22:02.870] This one's actually fun. [22:03.470 --> 22:04.510] So you're a diamond thief. [22:04.850 --> 22:06.170] You currently work at night, right? [22:06.270 --> 22:07.090] That's like your space. [22:07.530 --> 22:10.170] So what are five ways to choose the best diamond store to rob? [22:10.750 --> 22:11.510] Go to Sparks. [22:12.270 --> 22:13.410] Intelligence observation. [22:14.170 --> 22:17.450] Intelligence observation, that's the last scenario, so intelligence observation, good one. [22:17.830 --> 22:19.070] Friends in the diamond district. [22:19.330 --> 22:19.890] Say that again? [22:20.210 --> 22:22.110] Friends in the diamond district. [22:22.350 --> 22:22.810] Excellent one. [22:24.650 --> 22:25.530] Easy escape. [22:25.890 --> 22:27.070] Easy escape, etc. [22:28.670 --> 22:30.090] There you go, pretend to be a big buyer. [22:31.670 --> 22:35.190] Five security mechanisms which you may have to avoid in your job. [22:35.530 --> 22:35.810] Cameras. [22:35.950 --> 22:36.790] Facial recognition. [22:36.950 --> 22:37.730] Josh is here in the front. [22:38.310 --> 22:38.650] Alarms. [22:40.370 --> 22:40.810] Dogs. [22:41.030 --> 22:41.410] Guards. [22:41.950 --> 22:42.390] Police. [22:43.690 --> 22:44.290] Important, right? [22:47.170 --> 22:50.850] Five ways to increase the amount of money you can make from each job. [22:51.370 --> 22:52.410] Remember, you work alone. [22:52.810 --> 22:53.350] Don't get caught. [22:57.750 --> 22:58.950] Friends of the Diamond District. [22:59.070 --> 22:59.730] Love to reuse. [23:01.290 --> 23:01.910] Don't get caught. [23:02.110 --> 23:02.670] Don't get caught. [23:02.950 --> 23:04.150] Rob on a Friday night. [23:04.410 --> 23:05.250] Rob on a Friday night. [23:05.430 --> 23:07.210] Burn down the store so they don't know they're gone. [23:08.190 --> 23:09.270] There's an interesting idea. [23:10.050 --> 23:11.750] First one I've heard on this scenario. [23:13.190 --> 23:14.350] Diamonds don't melt, right? [23:18.090 --> 23:22.370] So the concept of these scenarios, folks, is really straightforward, right? [23:22.510 --> 23:25.990] Because enterprise complexity has gotten out of hand, right? [23:25.990 --> 23:31.050] So we all know that over the last 10, 15 years that have all been into space, some of us are kind of the same age. [23:31.370 --> 23:33.810] At the end of the day, you know, technology gets more and more entrenched. [23:34.030 --> 23:36.890] There's more and more bang-whiz sort of solutions for problems. [23:37.390 --> 23:38.950] And there's more technologies, right? [23:39.050 --> 23:41.150] So there's more things being deployed and layers, etc., etc. [23:41.250 --> 23:44.750] But at the end of the day, things come down to kind of one way in, right? [23:45.090 --> 23:51.170] So looking through the scenario components is very important, because if you whiteboard a scenario like this, the question is, okay, where are we going to start? [23:51.730 --> 23:52.630] And what is our goal? [23:52.790 --> 23:53.730] What's our treasure, right? [23:53.810 --> 24:01.210] So the red teams typically have to focus on this particular hard problem, which is what is our treasure, what is our goal, where do we have to be stealthy, etc., etc., etc. [24:01.210 --> 24:05.090] So these conversations typically are real relative to enterprise complexity. [24:05.830 --> 24:09.070] What it really comes down to is an organizational threat model, right? [24:09.210 --> 24:12.630] So from an organizational perspective, what is the actual perceived threat? [24:12.790 --> 24:18.910] It's not, you know, hey, it's going to be some kid who lives in his basement hacking a website, because now I own the house, and I have a big basement. [24:19.050 --> 24:25.010] But the point of it is, is that it's looking to determine exactly what threat agents potentially exist in your environment, right? [24:25.090 --> 24:29.610] Because you might be that electrician or that plumber, or you might be the computer help desk guy. [24:29.610 --> 24:33.470] And there's many different ways to kind of use those scenarios as a thinking exercise, right? [24:33.570 --> 24:36.990] So it's not always about technology, as no tech hacking can prove. [24:37.250 --> 24:41.470] You need the right expertise, as needed, to accomplish the goals, right? [24:41.530 --> 24:48.890] So the people in the room can attest to that, that there's an ethics issue, quite frankly, in the red team world, because if you're not working on the red team, you're usually working on the black team. [24:49.910 --> 24:59.410] So working with the attack vectors, the weaknesses, and the controls that potentially might be in place is really important, because, of course, being able to detect that something's actually happened is fairly interesting as well. [24:59.610 --> 25:02.390] So defensive, offensive, both of these things make a lot of sense. [25:02.910 --> 25:07.590] But having, you know, good threat models is probably the most important piece of advice that we're going to get out of today's conversation. [25:08.950 --> 25:13.290] Testing terminology, I think, is important, because there's kind of a lot of things thrown around out there. [25:14.110 --> 25:24.890] I kind of illustrated both cost and time, but looking at things like vulnerability scanning, security testing, et cetera, like that, you have to look at kind of the cost value effect of what you're trying to accomplish. [25:24.890 --> 25:34.050] In many cases, it's perfectly acceptable to look at if a system potentially is vulnerable to known problems, known systems, signature type testing, determine, am I misconfigured, et cetera, like that. [25:34.250 --> 25:35.790] In other cases, it's not, right? [25:35.850 --> 25:40.090] It's completely not, because the data means nothing, quite frankly, unless it's actually used against the organization. [25:40.250 --> 25:41.790] Again, intellectual property, theft, et cetera. [25:42.310 --> 25:54.290] So you have various scenarios that typically pop up, and many times we find ourselves, I think, getting into vacuums, or organizations getting into vacuums about, oh, well, you know, we've got to be patching the system, because sometimes it doesn't really make a difference, [25:54.430 --> 25:54.550] right? [25:54.630 --> 25:55.950] So what is your core business? [25:56.070 --> 25:56.910] What exactly do you do? [25:57.030 --> 25:58.770] Where can you be really hurt or kicked in the balls? [25:59.090 --> 26:01.110] That's the conversation we usually try to get to. [26:01.650 --> 26:06.990] So, again, based on the, again, the demographic in the room, you know, look at the timeline, right? [26:07.330 --> 26:22.730] So sophistication of attacker kind of versus intruder knowledge, you know, there's a lot of different things that take place, but, you know, nowadays, you know, how many people can quickly download, you know, W3AF, or can grab Metasploit, or can get, you know, [26:23.010 --> 26:24.950] access to commercial-supported tools. [26:25.530 --> 26:32.750] But chaining these effects to an organization is really, really important, because, again, it's not difficult, in most cases, to compromise a system, right? [26:32.830 --> 26:37.290] Because if it does have a known floor, known system, it will be discovered, will be utilized against such system. [26:37.470 --> 26:40.530] What's more important is the chain of effects that affect that organization. [26:41.090 --> 26:50.330] So, backing into another exercise that we're going to get to in a second, is looking at kind of evaluating an organization as it pertains to a couple things. [26:51.390 --> 26:52.870] The first thing is visibility, right? [26:53.170 --> 27:04.330] So, what can be seen, again, we're looking at kind of footprinting an organization, right, or going through this process, which many of you go through every day, you just don't know it, because you might be working for that company. [27:04.790 --> 27:09.590] But at the end of the day, it's kind of what can be seen as a presence, as a public-facing presence for the organization. [27:10.230 --> 27:13.990] You know, again, simple things, network world, you know, open or filtered ports, et cetera. [27:13.990 --> 27:16.150] These things are fairly important. [27:16.390 --> 27:18.710] You know, what's your architecture, what applications are you using? [27:19.130 --> 27:26.270] There's a lot of information relative to your organization that you've decided to plug it into this great big network and kind of face publicly. [27:26.690 --> 27:36.230] In addition to that, you know, many folks are using things like, you know, like, I don't know, LinkedIn or Twitter or other systems. [27:36.230 --> 27:39.750] And if anybody hasn't actually met Robin Sage, here she is. [27:43.030 --> 27:44.010] It's worth ten bucks. [27:44.590 --> 27:47.390] So the visibility piece is interesting. [27:48.270 --> 27:49.030] Access, right? [27:49.150 --> 27:50.590] Access to systems is key, right? [27:50.650 --> 27:54.330] People have access to systems, you know, developers have access to systems. [27:54.490 --> 27:55.010] What's our goal? [27:55.130 --> 27:55.790] Really, what's our goal? [27:56.070 --> 27:59.270] Can I hire that ex-employee that has access to information? [27:59.650 --> 28:04.510] Can I go ahead and pay for him to give me some detailed background information about who I need to talk to or who I need to knock over? [28:05.030 --> 28:10.810] Is there a laptop that's stolen out of a car that really wasn't stolen by some drug user who wanted to get a quick laptop to point it? [28:10.910 --> 28:12.590] No, it was really stolen because I knew where it was. [28:12.670 --> 28:14.790] I knew it was vulnerable because the guy was in a bar for four hours. [28:15.330 --> 28:23.710] At the end of the day, systems are potentially under attack if you're a target of the organization, if you have something to hide, you know, because again, people are typically in this for money. [28:25.550 --> 28:28.750] Looking at situations, trust restrictions, I think that's fairly important. [28:29.430 --> 28:39.390] How many people have to deal with situations where that you have remote users in an environment that are using, you know, personally owned machines that are unmanaged, but however they can connect to an organization that's very tight, quote unquote. [28:39.930 --> 28:48.570] They connect to an organization, they have limited ability to control said workstation because it's, you know, the executive system from home that is three-year-old and five-year-old and 15-year-old use. [28:49.110 --> 28:53.290] These are systems that are, again, typically not in your control as an organization. [28:55.010 --> 29:07.750] Looking at, you know, what type of alarms are in place for an organization to be able to identify, alert, and be able to mitigate that, in fact, there has been a problem or a breach within an organization that potentially is going towards the treasure, [29:08.010 --> 29:08.250] right? [29:08.430 --> 29:12.150] So this could be something that happens very quickly or it could happen over a period of time. [29:12.270 --> 29:16.570] But at the end of the day, being able to do log file analysis and looking at systems is fairly important. [29:16.710 --> 29:17.730] Again, on the network side. [29:18.030 --> 29:18.370] Okay? [29:19.230 --> 29:22.890] So I like to take this kind of view of things. [29:23.070 --> 29:24.110] This comes from White Hat Security. [29:24.530 --> 29:28.170] But if you look at kind of the concept here of a website, right? [29:28.250 --> 29:28.790] We all see these. [29:28.910 --> 29:30.910] I'm just trying to put it into contextual stuff. [29:31.910 --> 29:32.870] What's wrong with this picture? [29:34.330 --> 29:35.450] You are the red team. [29:35.750 --> 29:37.050] What are you going to attack here? [29:37.850 --> 29:38.530] Shout it out. [29:38.530 --> 29:39.510] It's an exercise. [29:40.050 --> 29:40.370] Session ID. [29:40.370 --> 29:41.130] Log in box. [29:41.350 --> 29:42.110] No SSL. [29:42.130 --> 29:42.330] Okay. [29:42.570 --> 29:43.010] Session ID. [29:43.150 --> 29:43.530] I heard that one. [29:43.630 --> 29:43.730] Good. [29:44.410 --> 29:45.210] No SSL. [29:45.350 --> 29:45.670] There's two. [29:46.710 --> 29:47.510] SQL injection. [29:47.750 --> 29:47.990] There's three. [29:48.770 --> 29:49.570] Languages aren't right. [29:49.790 --> 29:50.610] Languages aren't right. [29:50.790 --> 29:50.890] Eh. [29:51.150 --> 29:51.410] Next. [29:52.450 --> 29:54.230] Well, here's how I look at it. [29:54.370 --> 29:55.330] Forget your password. [29:55.530 --> 29:55.750] Right? [29:55.990 --> 30:01.470] So folks are going to look at a system, based on our examples earlier, really as a kind of a word problem. [30:01.770 --> 30:02.010] Right? [30:02.110 --> 30:04.490] So the word problem is how do I f*ck with you today? [30:04.490 --> 30:08.090] How do I get to this particular system as to what exactly it's trying to protect? [30:08.390 --> 30:10.290] So we can talk about, you know, malware. [30:10.470 --> 30:11.710] We can talk about mobile devices. [30:11.830 --> 30:13.050] We can talk about web applications. [30:13.210 --> 30:16.010] We can talk about, you know, any system you want to put into said bucket. [30:16.190 --> 30:17.750] But it all really comes down to what? [30:17.930 --> 30:19.750] It comes down to that threat model conversation earlier. [30:20.030 --> 30:22.510] Because again, there's a combination that has to happen. [30:23.290 --> 30:31.790] Again, kind of the full scope exercise between Internet security, social engineering, wireless security, communication, et cetera. [30:31.890 --> 30:32.910] These things all intertwine. [30:33.570 --> 30:38.850] So if we live in a vacuum and we don't believe that this is actually true, well, I strongly disagree. [30:39.550 --> 30:47.610] But at the end of the day, hopefully organizations that have intellectual property to protect would agree that these things are fairly important within the entire enterprise. [30:47.770 --> 30:48.790] And it really starts with the users. [30:49.570 --> 30:59.670] For many, many years, I recall working for a bank here in the city, and one of the conversations was, ah, we're not going to worry about education to the end user because they're too stupid to understand that we're not going to invest the money to teach them. [31:00.470 --> 31:06.370] I really just shudder there that conversation because that was the people that were potentially a gateway to chaos. [31:06.770 --> 31:11.090] In the same breath, I always hear organizations say, ah, the developers? [31:11.270 --> 31:16.670] We're not going to spend the time training or educating those guys because they're going to be fired in two years or they're going to go away or we're going to outsource it. [31:16.730 --> 31:17.590] And I'm like, wow. [31:17.590 --> 31:19.610] So here you are trying to run an organization. [31:19.610 --> 31:21.310] You don't trust your staff over here. [31:21.470 --> 31:22.790] You don't trust your staff over here. [31:22.890 --> 31:25.030] You're trying to protect this intellectual widget over here. [31:25.330 --> 31:27.470] It seems very soft and mushy in most cases. [31:27.650 --> 31:32.330] So, you know, at a higher level, guys, it's very interesting to look at exactly what's going on. [31:32.530 --> 31:34.470] So, we're going to play two more games. [31:35.310 --> 31:36.170] Here's the first game. [31:39.310 --> 31:40.530] Now, this one's important. [31:40.890 --> 31:41.690] Does anybody have a beer left? [31:41.810 --> 31:42.830] We can give away a beer on this one. [31:42.930 --> 31:43.350] This will be fun. [31:43.350 --> 31:44.250] No beers left. [31:44.430 --> 31:44.630] No beers? [31:44.730 --> 31:45.270] We have a beer. [31:45.910 --> 31:47.590] An hour earlier would have had beers. [31:47.730 --> 31:48.170] Yeah, exactly. [31:48.510 --> 31:49.610] So, this is for a beer. [31:50.810 --> 31:51.850] Listen, listen, listen. [31:51.970 --> 31:54.930] If anybody knows the answer ahead of time, please don't run it for anybody else. [31:55.730 --> 31:57.390] This is a test of selective attention. [31:59.650 --> 32:03.350] Count how many times the players wearing white pass the basketball. [32:32.400 --> 32:32.800] Okay. [32:33.320 --> 32:35.360] So, how many passes did you count? [32:35.680 --> 32:36.000] 15. [32:36.820 --> 32:37.220] Wow. [32:37.340 --> 32:38.040] We only have one beer. [32:38.040 --> 32:40.200] So, whoever gets a beer first probably can have it. [32:40.860 --> 32:41.880] 15 is the right answer. [32:42.000 --> 32:42.580] Who wants the beer? [32:44.300 --> 32:44.960] Come get it. [32:45.760 --> 32:46.460] Fight for it. [32:46.740 --> 32:49.080] But for the rest of you in the room, did you guys see the gorilla? [32:49.200 --> 32:49.960] How many passes did you count? [32:52.300 --> 32:55.040] The correct answer is 15 passes. [32:56.420 --> 32:57.780] But did you see the gorilla? [33:13.300 --> 33:17.920] This video is from research by Daniel Simons and Christopher Shabrie and is copyrighted. [33:18.680 --> 33:19.480] With permission. [33:21.380 --> 33:30.680] So, really what that just goes to show is that focus too much on what you believe to be the objective potentially kind of gives you tunnel vision around the rest, right? [33:31.000 --> 33:32.740] So, we are going to play a couple more brain games real quick. [33:33.060 --> 33:38.240] So, the first brain game we are going to do is I am going to throw out a word and throw out another sentence. [33:38.380 --> 33:42.720] And you are going to shout out the first person that shouts out the right answer kind of wins. [33:42.980 --> 33:43.060] Okay. [33:43.560 --> 33:43.900] So, ready? [33:44.160 --> 33:44.440] White. [33:47.790 --> 33:48.170] Water. [33:48.770 --> 33:49.050] Good. [33:50.170 --> 33:50.550] Water. [33:50.790 --> 33:51.450] Answer is water. [33:51.750 --> 33:51.870] Okay. [33:51.930 --> 33:52.050] Ready? [33:52.630 --> 33:53.070] Next one. [33:53.990 --> 33:54.370] Spot. [33:58.980 --> 33:59.600] Very nice. [34:00.120 --> 34:00.480] Go. [34:00.700 --> 34:02.180] This is the right answer by the way in the back of the room. [34:03.080 --> 34:03.480] Roast. [34:03.640 --> 34:03.880] Chicken. [34:04.580 --> 34:05.260] Why did I have an area? [34:05.400 --> 34:05.480] Wait. [34:06.840 --> 34:07.160] Red. [34:07.420 --> 34:07.620] Red. [34:08.180 --> 34:08.360] Red. [34:09.240 --> 34:09.640] Good one. [34:09.780 --> 34:11.160] You are learning the game. [34:11.780 --> 34:11.960] Alright. [34:12.220 --> 34:18.240] So, really the conversation here as we expand into other areas here, we start talking about you know, the almighty red team. [34:18.320 --> 34:22.240] The almighty red team that social engineers is their victim to provide all the information that they potentially need. [34:22.340 --> 34:24.280] Well, that does certainly happen in some scenarios. [34:24.520 --> 34:29.620] But in fact, there are fairly technical concepts as well that need to be done by technical folks. [34:29.620 --> 34:34.440] And at the same time, it's always good to have humans as part of subject matter that are going to be part of your testing. [34:34.960 --> 34:37.960] So, we are going to look at another sort of a word problem. [34:43.310 --> 34:43.630] Exlexia. [34:45.630 --> 34:53.730] So, again, if we would agree, this again is an example of how your mind as a human kind of looks at things and kind of comes up with your own interpretation and result. [34:53.730 --> 35:00.770] Because, again, it doesn't necessarily need to have all the picture before it kind of says or before it kind of paints a picture. [35:00.930 --> 35:11.990] So, with illusion, going back to our terms earlier that have been around forever, and sly of hand, et cetera, there's many cases where that an organization can be kind of duped, right? [35:12.130 --> 35:14.310] Into kind of acting as you need them to act, right? [35:14.310 --> 35:20.950] So, it's more important to come to an organization as an example, cause a problem, be the solution, and then ask for something. [35:21.190 --> 35:23.510] Because if you've already solved their problem, you must be a trusted asset. [35:23.730 --> 35:28.630] So, it's very interesting how psychology plays a very big game in the overall picture of a full scope assessment. [35:30.390 --> 35:39.010] So, some suggestions for people that ask, you know, what should they do or how do they get involved in these type of areas or involved in red teaming to begin with. [35:39.690 --> 35:44.010] I always kind of point out that I think it's really, really important to have kind of a mixed background. [35:44.410 --> 35:52.570] The people on the stage, as well as everybody here in the room, certainly has a long part of a long history of different types of backgrounds and they're really, really important. [35:53.130 --> 35:57.710] To be proficient in this particular space, I think it's really important to at least have some basic programming background. [35:58.370 --> 36:02.510] Being able to automate simple tasks is really, really important in this world, cause it saves a lot of time. [36:03.390 --> 36:14.750] Basically familiarize with the application world, cause application security, you know, based on the Verizon report, is typically where things are happening, but certainly it's a very low-hanging fruit for attackers looking for PII data or breaches or potentially attack, [36:14.910 --> 36:16.390] pivot, and break into an organization. [36:17.410 --> 36:20.330] Certainly having a cross-platform experience is fairly important. [36:20.530 --> 36:22.990] Being able to be proficient with both is really good, right? [36:23.070 --> 36:28.090] There's no more, you know, one or the other sort of guys, cause there's tools for both platforms that people use to automate tasks. [36:29.290 --> 36:38.930] Having background understanding of encryption, you know, for when you go ahead and spend time on trying to break HID systems or badging systems is a fairly important area, as well as other areas that are coming to market, RFID, et cetera. [36:40.770 --> 36:41.810] Having a hobby. [36:42.570 --> 36:44.210] And Josh Marpet pointed that out earlier. [36:44.310 --> 36:45.830] If anyone saw Josh's talk, I thought it was great. [36:46.650 --> 36:47.930] I used to work with Josh. [36:49.990 --> 36:52.390] His hobby is one of his passions, right? [36:52.470 --> 36:54.810] So facial recognition, CCTV, that sort of space. [36:55.170 --> 37:00.810] It's great to have an area of expertise that might be used later in life that you're, you know, it's your thing. [37:01.110 --> 37:02.750] It's something that you should do as a pastime. [37:02.750 --> 37:06.510] And as a pastime, I like the scenario that he said that all day I stand in front of a computer. [37:06.710 --> 37:08.690] And then I stand in front of a computer. [37:09.130 --> 37:11.010] Cause most of us probably are in that same space. [37:12.450 --> 37:13.850] All members of the team, right? [37:13.930 --> 37:15.230] Certainly is an integrity issue. [37:15.610 --> 37:18.890] You know, I've many times had to really trust my life with people. [37:19.510 --> 37:21.610] And at the same time, it's really, really important, right? [37:21.690 --> 37:23.750] So there's no question relative to your team, right? [37:23.830 --> 37:25.590] Your community that is going to be there to support you. [37:26.110 --> 37:29.150] At the end of the day, you have to have that trust because it's really, really important. [37:29.990 --> 37:30.290] So... [37:31.430 --> 37:32.090] What did I leave out? [37:32.830 --> 37:34.990] Usually a military guy is good to have. [37:35.390 --> 37:37.570] Well, you know, Tom says a military guy is good to have. [37:37.670 --> 37:38.210] Well, that is. [37:38.290 --> 37:40.530] I was leaving that off based on the last talk. [37:40.610 --> 37:40.850] I don't know. [37:42.190 --> 37:43.430] I said a military guy. [37:43.550 --> 37:44.630] I didn't say helicopter pilot. [37:44.790 --> 37:45.110] Exactly. [37:45.370 --> 37:45.650] Exactly. [37:45.910 --> 37:46.030] Yeah. [37:46.110 --> 37:47.070] Marine Corps isn't... [37:47.070 --> 37:48.070] Well, I never flew helicopter. [37:49.130 --> 37:49.450] So... [37:49.950 --> 37:53.130] So, again, so you want a red team. [37:53.250 --> 37:54.170] We have another exercise coming up. [37:54.610 --> 37:55.830] So you want a red team, right? [37:55.930 --> 38:02.230] So it's good to have, you know, red teamers that have a thick skin, like Tom can attest to, that can always take criticism, give criticism, et cetera. [38:02.350 --> 38:04.210] End of the day, nobody in this room knows everything. [38:04.310 --> 38:05.750] I don't care how f*cking good you are, right? [38:05.890 --> 38:11.830] If you're not willing to sit down, have a conversation, go grab the experts downstairs, go grab the experts that are talking, and say, hey, here's my problem. [38:11.890 --> 38:13.610] I'd like to kind of work with you on this particular solution. [38:13.850 --> 38:14.890] Here's the scope of the problem. [38:15.190 --> 38:16.190] Let's kind of collaborate on this. [38:16.890 --> 38:19.670] Everybody I've ever encountered in this community does that. [38:20.150 --> 38:21.810] Show of hands, who's going to DEFCON or Black Hat? [38:22.650 --> 38:22.990] Okay. [38:23.290 --> 38:26.510] So it just kind of goes east coast to west coast to wherever you go, right? [38:26.630 --> 38:28.370] So the conversation kind of expands. [38:28.550 --> 38:30.130] So this is really, really important. [38:30.510 --> 38:31.690] It's not so much the conference. [38:31.830 --> 38:34.270] It's the conversations in the hallways that typically are really interesting. [38:35.210 --> 38:38.270] But, again, good red teamers, you know, have integrity, and that's really, really important. [38:38.610 --> 38:38.790] Okay. [38:38.790 --> 38:43.310] So we are going to try to do a defend exercise and an attack exercise. [38:43.490 --> 38:46.230] However, the guys in front of the screen here are going to be able to see it. [38:46.290 --> 38:46.890] You guys won't. [38:47.010 --> 38:50.950] So what we're going to do is, it's going to be one team of experts, one team of three. [38:51.050 --> 38:53.590] It happens to be three guys in the first row, so you guys become our defenders. [38:53.990 --> 38:54.230] Okay. [38:54.710 --> 38:55.430] This is going to be fun. [38:55.670 --> 38:57.730] So you guys have limited time, limited budget, et cetera. [38:58.010 --> 38:58.810] Are they on the blue team? [38:59.510 --> 39:00.730] Yeah, they're the blue team. [39:01.070 --> 39:02.370] That's a good observation. [39:03.770 --> 39:05.790] The attackers are going to be the next five rows. [39:06.350 --> 39:11.890] Because the next five rows are gonna work together because those five rows are going to be... Let's see, 1, 2, 3, 4, 5... [39:11.890 --> 39:13.770] There's a lot of people you guys have to defend against. [39:13.990 --> 39:23.490] So these guys are gonna collaborate amongst themselves and potentially, you know, take down your system that you're trying to keep up and running during the environment of making sure that, you know, the business just happens to run. [39:24.530 --> 39:30.210] They're gonna, you know, they kind of have an unlimited budget, right, because they're trying to attack a system that has a treasure chest behind it. [39:30.410 --> 39:33.150] You guys are trying to defend it, but you don't have a limited budget, right? [39:33.210 --> 39:35.170] So you have to do the best thing you can possibly do. [39:36.070 --> 39:37.930] At the end of the day, it becomes quite interesting. [39:38.870 --> 39:41.890] So, your exercise attack target is there. [39:42.150 --> 39:50.950] It's kind of good that you guys are in front of the screen, because you guys can actually see what ports and configurations you've done on your network, so you can actually, you know, maybe make comments as to what and why such things are happening. [39:51.250 --> 39:56.230] The guys in the other four rows or five rows behind you, if they can see the screen, they can see some of the detailed stuff. [39:57.310 --> 40:03.690] What we're looking at here is trying to attack this organization to get to their process control network to affect their business, right? [40:03.690 --> 40:06.170] So, this is courtesy of Sandia National Labs. [40:06.430 --> 40:09.870] This is an exercise, a red team exercise, that's done as part of a training course. [40:10.650 --> 40:14.610] And what we're looking at here is kind of the conversation of attack and defend. [40:14.870 --> 40:22.310] So, we've kind of walked through a process that spoke about exercise and questions and kind of making people think outside the box a little bit. [40:22.670 --> 40:23.310] Excellent, thank you. [40:23.630 --> 40:26.950] And then being able to take that information and apply it to real-world scenarios. [40:27.150 --> 40:31.770] So, most of us here, I'm assuming most of the guys here, you guys raise your hand if you guys work in the IT industry, most of you. [40:31.770 --> 40:33.590] Okay, everybody in that row pretty much does. [40:33.790 --> 40:35.350] So, they probably do this every day. [40:35.930 --> 40:40.510] So, from the defender's perspective, you know, you just inherited the network and they fired everybody in the company. [40:40.690 --> 40:42.750] They hired you three guys and, hey, you're responsible for everything. [40:42.890 --> 40:44.110] So, you have limited documentation. [40:44.730 --> 40:46.210] People really don't know where things are. [40:47.170 --> 40:49.030] You know, it's probably most people's life in this room. [40:49.530 --> 40:54.290] The people behind you, they have kind of the same analysis because they don't have any information at all. [40:54.530 --> 40:56.930] But they're going to start their attack in kind of a different way. [40:56.930 --> 41:00.390] So, you three guys looking at that environment, keep this in mind. [41:00.610 --> 41:03.210] Your goal here is to protect the process control system. [41:03.510 --> 41:07.370] You do not want to allow a process control system to go down. [41:07.630 --> 41:10.350] And what I mean by that is, it could be, you know, power gas. [41:10.490 --> 41:11.610] It could be control. [41:11.950 --> 41:14.710] It's an exercise, guys. [41:14.790 --> 41:15.330] So, don't get nuts. [41:16.150 --> 41:18.250] And the guys behind you, they're going to listen to you. [41:18.370 --> 41:22.730] And they're going to listen to your three comments that you're going to improve this environment after looking at the board. [41:23.250 --> 41:28.330] And then they are going to throw five comments at you, because they have had more time to analyze the same problem. [41:28.910 --> 41:29.730] That's typically how it works. [41:30.650 --> 41:31.750] So guys, in the first round. [41:34.170 --> 41:35.330] First off, can you see the ports? [41:35.410 --> 41:36.110] Is it even clearer? [41:36.550 --> 41:38.790] I had handouts, guys, they didn't arrive, so I apologize. [41:40.850 --> 41:46.090] So I'll kind of give some people some narrative here from the left to the right, and the people in the back, I apologize in advance. [41:46.490 --> 41:52.270] So from the left to the right, we have public-facing Internet systems, routers, et cetera, using HSRP as a front end. [41:52.770 --> 42:00.390] They're tied back into another public-facing switch, that then go to a set of redundant firewalls that are in active-active mode. [42:01.590 --> 42:05.130] These public-facing firewalls, they're going to do the following. [42:05.310 --> 42:09.910] They're going to permit any TCP to any TCP in DMZ, which is whatever. [42:10.510 --> 42:17.330] They're also going to permit 11, 22, 33, and, you know, 22 to anything over 4760. [42:18.470 --> 42:21.650] Again, this is really, really hard, guys, without the handouts, so I apologize. [42:21.810 --> 42:24.130] This isn't going to be as fun as I thought it was going to be without the handouts. [42:24.370 --> 42:28.470] But the concept here is that the compartmentalization of the network is fairly interesting. [42:29.550 --> 42:33.770] On the DMZ side, you have systems that intercommunicate back to the corporate network. [42:34.030 --> 42:39.970] In the corporate network side, you have systems that can communicate outbound with very limited controls, right? [42:40.150 --> 42:42.890] Because, again, based on the firewalls that you may be able to see. [42:43.890 --> 42:51.150] On the process control network, you have systems there that have to talk the systems in the corporate network, and vice versa, based on their role. [42:51.550 --> 42:58.730] You have systems that are named or naming standard, which is fairly unified or uniformed as to, you know, where organizations place their assets. [42:59.690 --> 43:06.670] And you three guys have to run this whole ship, which is fun, because you have probably a Cisco guy, you probably got a network guy, probably I got a wireless guy, whatever. [43:07.150 --> 43:09.070] But you three guys are kind of running the show in the front. [43:09.350 --> 43:22.130] So, in a short observation here, if I was to attack you from the inside, what would be something that you would potentially want to change fairly quickly? [43:23.690 --> 43:24.410] Go ahead, go. [43:24.710 --> 43:25.470] Motom access. [43:25.750 --> 43:26.530] Okay, good. [43:26.730 --> 43:30.430] Motom access from the outside, because he's concerned about being attacked from the inside. [43:30.990 --> 43:31.350] Okay. [43:31.570 --> 43:32.550] Plain text protocols. [43:33.050 --> 43:34.350] Plain text protocols, good. [43:34.690 --> 43:34.790] Good. [43:34.990 --> 43:37.550] Because, again, we have knowledge here on the ports that are there. [43:37.690 --> 43:38.190] I'm helping them out. [43:38.930 --> 43:42.210] You know, 23 and FTP, et cetera, that are going to be clear text protocols. [43:42.370 --> 43:45.210] So, he wants to ensure that those systems are maybe not going to be clear text. [43:45.550 --> 43:46.050] Anything else? [43:46.270 --> 43:47.470] Before we have you attacked? [43:52.510 --> 43:53.800] Any roles in the perimeter? [43:55.100 --> 43:57.620] And you have workstations that can talk to each other, right? [43:57.620 --> 43:59.260] They can... they have intercline communication. [43:59.580 --> 44:01.060] They can... all servers can talk to anybody. [44:01.480 --> 44:02.440] There's really no limitation. [44:02.620 --> 44:03.180] No VLANs. [44:03.260 --> 44:04.300] There's nothing separating the environment. [44:04.480 --> 44:05.140] It becomes quite interesting. [44:06.620 --> 44:06.940] Alright. [44:07.400 --> 44:12.560] So, now, guys, as you're still thinking about how to fix your environment, row 2, 3, 4, and 5. [44:13.200 --> 44:13.520] Go ahead. [44:14.060 --> 44:14.480] Attack it. [44:14.730 --> 44:15.800] What's the first thing you're going to do? [44:15.920 --> 44:16.400] One of the admins. [44:16.860 --> 44:17.880] Kidnap one of the admins. [44:17.940 --> 44:18.580] Like this guy. [44:19.710 --> 44:24.580] So, he's going to go, potentially, to one of the admins' house, try and befriend him, try and get some information out of him. [44:24.660 --> 44:25.820] Maybe he'll steal him with a black hood. [44:25.920 --> 44:26.230] Depends. [44:27.790 --> 44:28.230] Yeah. [44:28.340 --> 44:30.060] So, here's a good question. [44:30.200 --> 44:31.360] So, how would you get that employee's address? [44:31.880 --> 44:32.160] Google. [44:33.560 --> 44:34.000] Facebook. [44:34.760 --> 44:35.200] Blake? [44:35.820 --> 44:36.700] Voter Registry. [44:36.820 --> 44:37.480] Voter Registry. [44:37.680 --> 44:38.100] Excellent. [44:38.560 --> 44:39.000] DMV. [44:39.180 --> 44:39.620] DMV. [44:39.980 --> 44:40.380] Alright. [44:40.600 --> 44:44.840] So, again, you're trying to protect the human assets in your organization, as well as from the attackers. [44:45.060 --> 44:50.840] You know, row 3, 4, 5, any quick comments as to, potentially, as an inside attacker, how you'd want to attack this organization? [44:51.160 --> 44:52.260] You have physical access. [44:52.680 --> 44:53.230] Get malware. [44:58.320 --> 44:58.980] Good point. [44:58.980 --> 45:04.060] So, he wants to maybe fish the environment with malware, so that the organization can pretty much attack itself from the inside. [45:04.260 --> 45:05.000] DDoS the environment. [45:05.160 --> 45:05.560] Knock it over. [45:05.880 --> 45:06.540] How would you do it? [45:06.620 --> 45:07.800] Probably from phishing attack or something. [45:08.360 --> 45:08.480] Okay. [45:09.580 --> 45:13.020] So, as you go through these scenarios, you know, this is another example. [45:13.140 --> 45:15.400] And it's a little more extensive, guys, with the handout. [45:15.740 --> 45:16.900] And we have 10 minutes. [45:17.020 --> 45:17.100] Cool. [45:18.000 --> 45:19.200] So, I apologize in advance. [45:19.340 --> 45:20.260] These slides will be available. [45:20.260 --> 45:25.640] I do highly recommend you do check out National Labs exercise that's well documented. [45:25.840 --> 45:34.040] It's something really useful to do tabletop within your own organization, to have them start thinking outside the box, because you really should potentially start looking at, you know, an attacker's perspective. [45:35.020 --> 45:38.800] This visualization is showing an attacker perspective, right? [45:38.800 --> 45:48.100] So, from the outside in, being able to pop a box, break, pivot, and hit other systems from within the environment, based on the rule sets that are there within the organization, can be quite scary, right? [45:48.260 --> 45:51.800] So, most people don't think three, four, you know, four systems down the line. [45:52.220 --> 45:57.200] But it's really important to actually have visualization to show someone, you know, when this box was broken, here's what I did. [45:57.920 --> 45:58.920] So, it goes from there. [45:59.520 --> 46:02.040] There's a few methodologies, I think, that are worth mentioning. [46:03.400 --> 46:04.580] Again, it's an evolving art. [46:04.980 --> 46:06.580] The first one is the IATRP. [46:06.580 --> 46:09.580] Some people might remember this as the NSA IEM. [46:09.800 --> 46:16.020] That's been changed, because the National Security Agency does not want their name associated with this particular training or certification, for whatever reason. [46:17.200 --> 46:18.920] So, IATRP is the new one. [46:19.520 --> 46:21.500] There's a bunch of companies that do it. [46:21.560 --> 46:22.840] Security Horizon is probably being the best. [46:24.420 --> 46:35.660] IEEE 1471 is now an innovative study of engineering systems that are useful in conducting a red team exercise on dynamic systems, system design, et cetera. [46:35.660 --> 46:41.360] A little more on the system design space than the attack and break sort of space. [46:41.600 --> 46:43.860] But again, IEEE 1471 should be reviewed. [46:44.660 --> 46:46.940] Again, Sandia has an IDART. [46:47.820 --> 46:52.060] Their team has been very proficient in protecting our nuclear power plants here in the U.S. [46:52.160 --> 46:52.820] so far. [46:53.180 --> 46:55.620] So, at the end of the day, they've done some good work. [46:56.080 --> 46:58.300] Peter Herzog, as I mentioned earlier, has done the OSTEM. [46:58.520 --> 46:59.500] OSTEM is pretty awesome. [46:59.500 --> 47:02.600] I'm really impressed with the work that Pete's put in there, Blood, Sweat, and Tears. [47:02.900 --> 47:04.920] Hasn't got a lot of traction here in the U.S., quite frankly. [47:05.000 --> 47:05.580] That's unfortunate. [47:06.040 --> 47:09.800] But it has done a really good job of getting out there into space in Europe and other countries. [47:09.940 --> 47:11.020] So, OSTEM is well worth checking out. [47:11.700 --> 47:15.440] The OWAS testing guide is really cool if you want to learn how to break web applications. [47:16.660 --> 47:17.320] A lot of fun. [47:17.740 --> 47:21.380] And certainly, the NIST standards for network testing, et cetera, are fairly useful. [47:21.380 --> 47:31.020] So, if you're looking for something to do, it's not really the BangWiz tool widget tool that's out there this week or the new exploit that just came out that you've got to compile and launch against all your friends. [47:31.620 --> 47:32.500] That's cool and all. [47:32.820 --> 47:43.980] But it's kind of like that view of if you don't understand the methodology and approach in order to accomplish a goal, the ancillary items are going to be kind of difficult to plug into the conversation. [47:44.220 --> 47:54.340] So, when you're trying to defend against the attacker, if you are the defender or if you're the attacker, hopefully within your own authorized scope, these methodologies will help you. [47:54.540 --> 47:57.460] In addition, these methodologies are also a razor blade. [47:58.020 --> 48:05.520] Because these razor blades are actually being used today by organizations and individuals that are attacking systems. [48:05.660 --> 48:06.100] Why? [48:06.220 --> 48:06.780] Because they work. [48:06.940 --> 48:08.200] And they're fairly proficient. [48:08.440 --> 48:11.680] So, they're no longer secrets as to how people operate. [48:12.860 --> 48:17.280] I got to go back to WikiLeaks and kick the video in the ass because I could... [48:17.280 --> 48:19.740] All I can say is that if you're going to walk behind a report... [48:19.740 --> 48:28.280] If a reporter is going to walk behind two insurgents or three insurgents into a building with guns slapped over their shoulders, you're probably going to get lit up. [48:28.400 --> 48:36.580] And in addition to that, you have clear communication that was going back to their COs and basically saying, here's what we see, here's what we see, do we have clearance to go? [48:36.700 --> 48:40.800] And based on the information I saw in that video, all that makes me want to do is not follow insurgents into a house. [48:40.800 --> 48:45.080] But, at the end of the day, it was the disclosure, not the video. [48:45.280 --> 48:45.560] Right? [48:45.620 --> 48:47.780] It was the disclosure in that scenario that was the issue. [48:47.840 --> 48:53.880] I think it was the disclosure that it was a friendly fire problem opposed to an insurgent issue. [48:53.980 --> 48:54.480] I'll leave that alone. [48:55.880 --> 49:00.340] So, in conclusion, there's a lot of organizations that really need your help, right, for various threats. [49:00.480 --> 49:01.820] Again, I work with OWASP. [49:01.900 --> 49:02.880] I do a lot with those guys. [49:03.200 --> 49:06.740] I also do a lot with other organizations like InfraGard, et cetera. [49:07.180 --> 49:11.240] If you're looking to get plugged into an organization, they're the places you should probably start. [49:11.660 --> 49:16.020] Because these organizations can help you get connected with the people that are hiring in these spaces. [49:16.600 --> 49:20.280] Or, if you're already in a comfortable setting, you should probably look to them as resources. [49:20.880 --> 49:22.640] These are really important times. [49:23.440 --> 49:27.000] Have a positive impact on security of critical systems and infrastructure is fairly important. [49:27.180 --> 49:29.740] I would like to think that the power should stay on in this room for a while. [49:29.940 --> 49:32.860] And that could actually be as a result of somebody actually doing some diligence. [49:33.780 --> 49:37.020] It's always fun to work with high-energy, light-hearted, and unique people. [49:38.300 --> 49:42.740] So many times I've had to go outside my circle to find an expert, a subject matter expert in a particular area. [49:42.860 --> 49:45.140] And there's so many of them here, including Steve. [49:45.400 --> 49:45.780] Hey, Steve. [49:46.520 --> 49:52.780] So, it's nice to work with folks that bring various backgrounds to the table, including beers, which is good. [49:53.700 --> 49:55.740] Visit interesting places, touch powerful systems. [49:56.000 --> 49:59.740] That's kind of fun and all, but it's really cool to also get paid to be bad without going to jail. [49:59.740 --> 50:03.760] I don't know about you, but I'm not a big fan of Bubba's, as Josh would say. [50:05.140 --> 50:07.280] So, a couple quick credits, and then we'll go for any questions. [50:07.400 --> 50:12.040] We've got a bunch of guys on the panel here, if you will, that'll be able to give you some good feedback very quickly. [50:12.720 --> 50:18.460] First, I'd like to give the United States Marine Corps a good shout-out for some of their background that helped me with OPSEC and doing what we do. [50:19.100 --> 50:21.360] Cyndia National Labs for some of the work they've done here. [50:21.820 --> 50:24.720] Partners that I work with, Chris, Ryan, and Luke for Tiger Team for the video. [50:24.720 --> 50:28.020] Provide Security, Tom Ryan, Endor, AKA Robin Sage. [50:28.720 --> 50:31.080] Simon and Chabras for their guerrilla video that you've seen. [50:31.560 --> 50:34.020] And even Emmanuel Goldstein or Evil Corley. [50:34.260 --> 50:37.040] So we really appreciate him helping out as well. [50:37.380 --> 50:39.140] And Linda for the reviews on these slide decks. [50:39.560 --> 50:43.660] So, if there are any questions, it's kind of a high-level talk, as I understand that. [50:44.000 --> 50:50.060] But we would certainly be happy to do our best to ask or answer any question in the last five minutes that we have. [50:50.060 --> 50:55.020] So do we have any questions from the audience about red teaming tactics, components, systems? [50:55.180 --> 50:55.300] Sir? [50:55.740 --> 51:01.220] Are there recognized professional organizations that such companies or individuals can join? [51:03.760 --> 51:06.280] So, does anybody want to comment on that before I take it? [51:08.240 --> 51:15.020] Well, as Tom mentioned, OWASP, InfraGuard, all those professional organizations that deal within the scope of the space. [51:15.780 --> 51:17.320] It's definitely worth a look-see. [51:18.420 --> 51:19.680] Especially OWASP, I would say. [51:19.840 --> 51:22.820] Because OWASP, first rounds on OWASP after the meeting. [51:23.560 --> 51:27.360] So if you want a free beer after you talk about hacking, it makes sense to me. [51:29.120 --> 51:31.020] So, I would answer that question like this. [51:31.240 --> 51:34.920] I'm probably aware of about 35 teams around the world that do that type of work. [51:35.520 --> 51:37.040] And they have different proficiencies. [51:38.320 --> 51:43.320] Many of the teams subscribe to different organizations, OWASP and other places as well, to be a part of it. [51:43.740 --> 51:49.720] You have other professional information like SCIP and SIC and IC that are kind of in that space. [51:49.920 --> 51:51.820] But it really depends on what the discipline is, right? [51:51.940 --> 51:56.960] So if you're an AppSec-focused sort of an organization, then, you know, you have one particular group of guys. [51:56.960 --> 51:58.360] And it's kind of a mishmash. [51:58.460 --> 52:01.480] Unfortunately, there's not, you know, redteamassociation.com. [52:01.600 --> 52:02.540] Like, that doesn't exist today. [52:03.340 --> 52:05.100] So you should probably register that. [52:05.300 --> 52:05.720] Yeah, cool. [52:06.280 --> 52:06.620] Next. [52:06.620 --> 52:17.260] How do you defend your people against money, booze, sex, or sort of having their arm twisted? [52:17.720 --> 52:19.160] Kidnapping of a family member. [52:19.380 --> 52:22.880] And then you send them back into work to do your bidding. [52:23.520 --> 52:24.840] I can answer that one. [52:25.820 --> 52:28.800] Let me give them one scenario first, then you can answer. [52:28.800 --> 52:32.380] I've got to give Tom his... I know where he's going to go with this one. [52:33.000 --> 52:36.880] So I just came back from Mexico, and that was a pretty scary place, quite frankly. [52:37.080 --> 52:43.240] And one of the things I found at my doorstep when I walked out of the hotel room in the morning was a publication with four pictures on it. [52:43.420 --> 52:45.740] And the four pictures were of body parts. [52:45.960 --> 52:51.880] And the body parts that were translated to me, because I don't speak Spanish, was that a new police chief was sworn in. [52:51.900 --> 52:52.600] You guys can Google this. [52:52.640 --> 52:54.040] It's only in Spanish for some strange reason. [52:54.180 --> 52:54.700] It hasn't hit the U.S. [52:54.720 --> 52:54.980] papers. [52:55.440 --> 53:06.140] But basically, after the police chief was sworn in, 16 hours after he was sworn in, he was abducted from Headquarters Police Station in Acuaclientes, Acuaclientes, Hot Water, Mexico. [53:06.800 --> 53:08.000] And he was dragged out. [53:08.560 --> 53:09.640] He was taken. [53:10.040 --> 53:14.620] And 12, 14 hours later, his body parts were found around the perimeter of what he represented. [53:14.860 --> 53:22.480] And on his body parts was a permanent marker telling them that the narco, the narcotics industry, if you will, Narco as a consortium basically owned the territory. [53:22.700 --> 53:27.600] For anybody else that wanted to have the police chief sort of role, they might face a similar fate. [53:27.820 --> 53:28.420] So that's part one. [53:28.640 --> 53:38.380] Part two, also while there, an interesting article actually hit the paper, and I was told it to be true as well, was that there were seven insurance companies in Mexico, in that particular region. [53:38.380 --> 53:47.320] They were all invited to a room like this for an education about doing more insurance stuff. [53:47.740 --> 53:53.500] And they sent cars to the various organizations, picked up all the people, brought it back, and there were 40 people that were from all these different insurance companies. [53:55.100 --> 53:58.620] And what they did was they did a few presentations, and then they locked the doors. [53:59.160 --> 54:06.680] And then they told everybody in the room that beginning today, you'd start paying us $10,000 U.S. because we already own your data, and we're going to do a slideshow to prove it. [54:06.900 --> 54:19.800] And it was basically showing that they knocked into people, they knocked into people that had access to backup tapes, they put insiders into the organizations, and they said it's cheaper to pay us than the damage you're going to face as a result of your business. [54:20.020 --> 54:22.860] So to answer your question, how do you defend against it? [54:23.080 --> 54:29.840] It's quite difficult because without compartmentalization, as well as trust within a business, it's quite difficult to get anything done, right? [54:29.840 --> 54:36.700] Tom, do you want to add to his how do you keep people safe from being abducted and killed and how to give up information? [54:37.640 --> 54:37.960] All right. [54:38.020 --> 54:43.340] One of the key aspects, one of my big things is executive protection, also with cybersecurity. [54:43.400 --> 54:48.380] So the other thing you want to do is watch out the information that you put out there about yourself. [54:48.720 --> 54:52.920] So it could be something as simple as tagging your wife and kids on a Facebook. [54:52.920 --> 54:55.560] It becomes public knowledge who they are. [54:56.300 --> 54:57.320] You know, who you friend. [54:57.860 --> 55:01.120] Everybody saw it in my Robin Sage little experiment. [55:01.480 --> 55:02.640] Who became my friend? [55:02.760 --> 55:04.660] I mean, you had the CIO of the NSA. [55:05.080 --> 55:07.820] You had, you know, Chief of Staff of the House of Representatives. [55:09.560 --> 55:11.480] So it's how you keep your information. [55:11.680 --> 55:15.680] When you make a donation to an organization, how is that information handled? [55:16.140 --> 55:16.580] Okay? [55:16.800 --> 55:18.920] Are you using your real address or a company address? [55:19.160 --> 55:22.360] If you use a real address, guess what? [55:22.360 --> 55:24.560] Half your information is out there on LimeWire. [55:24.740 --> 55:25.180] One minute. [55:26.060 --> 55:35.260] So if you were to go to LimeWire and just Google, say, go in LimeWire and do star.mdb, you'd be amazed how many people's databases you now have access to. [55:35.780 --> 55:40.860] Do a star.q data, you'd be surprised how many people's QuickBooks data you have access to. [55:41.320 --> 55:43.320] So it's all about how you keep information. [55:43.880 --> 55:46.400] So we have time for one more question. [55:47.860 --> 55:48.360] We're done? [55:48.460 --> 55:48.820] Okay. [55:49.040 --> 55:49.660] We were saying we're done. [55:49.840 --> 55:51.040] So again, guys, thank you. [55:51.220 --> 55:52.040] These slides will be available. [55:52.040 --> 55:53.480] We'll send me a note if you want them and we'll go from there. [55:53.640 --> 55:53.860] Thank you.