噪音致死:利用警报疲劳绕过安全运营中心(EDR版).pdf

编号:981921 PDF 47页 1.79MB 下载积分:VIP专享
下载报告请您先登录!

噪音致死:利用警报疲劳绕过安全运营中心(EDR版).pdf

1、#BHUSA BlackHatEventsDeath by Noise:Abusing Alert Fatigue to Bypass the SOC(EDR Edition)Rex Guo Khang NguyenAlert Fatigue in Enterprise SOC 1K-10K+99%alerts/day false positives https:/ are medium and low severity The Consequences of Alert FatigueIgnore medium/low alerts Shallow investigationsMost ar

2、e medium and low severity Suppress noisy alerts Is Default EDR Detection Sufficient?Many SOC teams rely on default EDR configuration to provide detection4 principles to downgrade or avoid the detectionsRex GuoCEO/Co-Founder Culminate DEFCON 2024 SOC Competition,#1 human efficiencyEngineering Lacewor

3、k,XMCyber,Cisco4th Time BlackhatKhang Nguyen Founding Security Researcher Started in binary analysis&vulnerability research Moved to Fullstack Exploit Dev Playing&hacking FPS gamesAlert Severity in Chosen EDRsCrowdstrike:Critical,high,medium,lowMS Defender:High,medium,lowSentinelOne:Malicious,Suspic

4、iousTargeting Linux Server WorkloadLinux Server Threat LandscapeLinux Target Infrastructure Spring Cloud Function hosted inside a Docker container Vulnerable to CVE-2022-22963 Docker container hosted on an EC2 instance EC2 instance has EDRs installed EC2 instance is connected to other services i.e.,

5、S3 bucketsAWS InfrastructureSpring Cloud FunctionDocker ContainerLinux EC2 InstanceS3 BucketS3 BucketS3 BucketExploit CVE-2022-22963Drop Container Escape ExploitAttack Chain PlanDrop Shell Utility&Establish sessionEscape to HostPersist on HostExfil DataEstablish Shell Session from HostExploit CVE-20

6、22-22963Attack Chain Attempt#1(Cont.)Drop Shell Utility&Establish sessionCVE-2022-22963 Vulnerability Spring Cloud Function is used regularly for API gateways,serverless applications Uncontrolled Spring Expression Language(SpEL)evaluation leading to RCE Provide a crafted SpEL using routing functiona

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(噪音致死:利用警报疲劳绕过安全运营中心(EDR版).pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠