寻找无声的妥协.pdf

编号:991793 PDF 14页 1.23MB 下载积分:VIP专享
下载报告请您先登录!

寻找无声的妥协.pdf

1、The Hunt for Silent Compromise Detecting Cloud-Native Persistence Without Malware or AlertsAnkit GuptaShilpi MittalAgendaModern Threat LandscapeAttacker TechniquesHunting StrategiesCase StudiesDefense&TakeawaysThe“Silent Compromise”DefinedSilent Compromise:No alerts triggeredCloud-Native Persistence

2、:Uses legit functionalityAppears as“business as usual”activityOften detected late,if at allCore Persistence Vectors to PrioritizeOAuth app abuse and illicit consentService principals and app credentialsToken replay and gaps in conditional accessAPI keys and long-lived secretsPassive infrastructure a

3、buse rules,connectors,automationOAuth Apps Illicit Consent GrantsConsent Phishing:“Grant access”scamAttackers app gets an OAuth token for the userLong-Lived Access:via refresh tokensNo malware on endpoint;uses legit API callsUnified Hunting and Telemetry FrameworkHunt by layers:identity,apps,mail,an

4、d dataCollect logs from Entra,AWS,Okta,and SaaS appsCorrelate in one SIEM or data lake for full contextBehavioral Indicators That MatterNew app consent with broad scopesToken use from a new geo or impossible travelNon-admin creating admins or adding app secretsSudden bulk read of mail or files by a

5、new principalReady to Deploy Hunts in Sentinel KQL High-risk OAuth consent Abnormal refresh token usageAWS and Okta Hunt Patterns CloudTrail new keys and policy changes Okta admin and token eventsCase Snapshots and LessonsCompromised Cloud Compute Credentials(Unit 42)Commvault Azure Breach&M365 Late

6、ral MovementMicrosoft AI/Azure Data Exposure via SAS MisconfigurationAction Plan and TakeawaysEnable and retain critical logs and protect trailsRestrict consent and disable legacy protocolsShip the sample hunts and tune for your orgAutomate

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(寻找无声的妥协.pdf)为本站 (可不可以) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠