Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories...

62
Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations March 21, 2019

Transcript of Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories...

Page 1: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Cyber War Stories from Adriatic SlovenicaSandi Bižal C|EH

IT Security Officer - Security Operations

March 21, 2019

Page 2: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Agenda

•Who are we?

•Goal of the Day!

•Why are we Here?

•Use Cases

•Answers

•Q & A

Page 3: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Who are we?

Page 4: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Sandi 101

• 12 years in InfoSec | SIEM ROCKS!• Nessus & Metasploit enthusiast

• Classical music lover!• Very much into Food porn!

Page 5: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Google is NOT your friend!

Page 6: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Goal of the day!

Page 7: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Whateveryou do !!!

DO NOT GET ARRESTED

Page 8: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Why are we Here?

Page 9: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Just how tough is it to get the passwords?

https://www.youtube.com/watch?v=RfAdux3XidM

Page 10: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

OK Seriously…Why are we Here?

Page 11: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 12: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Real World Top-of-Mind Problems

Email

GDPR

Botnet

Authentication Anomalies

Malware

Privileged Account Monitoring

Funny Story

Page 13: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Trivia Question #1

What is this?

Page 14: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Trivia Question #2

What is this?

Page 15: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Use Cases

Page 16: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #1Email Tracking

All data we can have – now what?

Page 17: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 18: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 19: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #2GDPR Auditing - A

As seen by the Security officer

Page 20: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 21: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #3GDPR Auditing - B

As seen by the DPO

Page 22: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Make a guess? So who the hell is DPO?

Page 23: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Data Protection Officer

Page 24: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 25: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #4BOTNET !

From an unknown computer

Page 26: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

No data about workstation and

Workstation IP number!

Page 27: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

No data about workstation and

Workstation IP number!

End of story:

- Event logging on DC was raised with NTLM

Security

- Workstation was on DA (DirectAccess)

- User was administrator on laptop

- Computer was blocked in domain

- Now we get more data from DC to SIEM.

Page 28: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Lessons Learned

• Our data feeds were not enough

• User was administrator on laptop

• Active Directory auditing policies were incorrect

• After the re-config, we found the infected computer, because it was still….. <WHO WOULD LIKE TO ANSWER>?

Page 29: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

What is this?

Page 30: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

BEACONING !

Page 31: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #5Daily Events

As seen by the security officer

Page 32: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 33: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 34: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #6Anomalies within authentication logs

As seen by the security officer

Page 35: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 36: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #7Asset model with vulnerabilities

As seen by the security officer

Page 37: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 38: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #8Malware occurrence detected

As seen by the security officer

Page 39: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 40: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #9Regular group membership changes

Page 41: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 42: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #10Irregular group membership changes

Page 43: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 44: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #11Multiple changes to security groups

Page 45: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 46: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

UC #12Funny story

System administrator bulk created and deleted users after discovering a mistake in provisioning script

Page 47: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 48: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 49: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Trivia Question #3

THE BEST OF THE BEST !!!

Page 50: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

What the ?!? is this?

Page 51: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Answers

Page 52: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Answer #1:

Domain Admin Failed Login & Lockouts in 1 Month

Page 53: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Answer #2:

Domain Admin Failed Login & Lockouts in 1 Hour

Page 54: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

PLEASE PATCH PUTTY !!!

Page 55: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

• FROM HACKER NEWS!

FROM YESTERDAY: FROM HACKER NEWS!

Page 56: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Bonus Slides

Page 57: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Number of Privileged Account Logins per Minute

Out-of-the-box Dashboard

Page 58: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Privileged Account Logins per Minute

300

1,500

Page 59: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 60: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations
Page 61: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Q & A

Page 62: Cyber War Stories from Adriatic Slovenica - RISK conference · 2019-11-28 · Cyber War Stories from Adriatic Slovenica Sandi Bižal C|EH IT Security Officer - Security Operations

Thank You.