TRANSCRIÇÃOEnglish

AEV Demo | BreachLock Unified Platform | Adversarial Exposure Validation (AEV)

15m 8s2,482 palavras380 segmentsEnglish

TRANSCRIÇÃO COMPLETA

0:00

[Music]

0:05

Welcome to Breach's adversarial exposure

0:08

validation platform.

0:10

We're going to call it AEV for short.

0:13

What this is is a fully autonomous

0:15

pentesting/redteaming

0:17

tool for your team to be able to use to

0:20

simulate adversarial uh simulations

0:23

behavior uh and mimic what AP groups

0:26

would be able to do if they were able to

0:28

breach inside your network or from the

0:31

web.

0:37

So, our AEV solution is meant to be a

0:40

tool for your teams to be able to use to

0:43

either augment or uh hire a a virtual

0:47

redteamer or pentester for lack of a

0:49

better term. What this has the

0:51

capability of doing is autonomous

0:54

testing of infrastructure and of APIs

0:57

that are internal or public facing. So

1:00

an anticipated use case for this would

1:02

be we need to run continuous red teams

1:06

throughout the year inside our

1:08

infrastructure to assess risk to assess

1:11

the behaviors of what groups would do if

1:13

they were to breach and see what the

1:16

risk of uh CVE being exploited is.

1:21

The beginning of the journey here inside

1:23

AEV is first going to start from an

1:25

internetfacing lens. So, we need to run

1:28

an investigation against your company,

1:29

your organization to do a couple

1:31

different things. First, we want to

1:33

figure out who you are as a company, the

1:35

type of customers and clientele that you

1:37

service, but also your assets, your your

1:41

tech stack, what exists out there on the

1:43

web that APS and and threat actors may

1:47

be able to use as context for

1:49

engagements.

1:51

So, our first step here is going to be

1:53

adding a seed domain.

1:56

So let's just say the C domain is

1:58

breachlock.com.

2:00

As soon as I create this domain, a

2:04

public-f facing investigation is going

2:05

to launch with the intent of figuring

2:08

out your footprint to the web. So

2:10

subdomains, IP addresses of the servers

2:12

hosting those applications, locations,

2:15

and then also some contexts.

2:18

When that investigation has finished,

2:21

you can come in here and see the

2:22

results. So, if you've never engaged

2:23

with Breach Lock before and this is your

2:25

first time, here after a couple minutes

2:27

scan, you can see a list of uh all of

2:30

our public facing assets, what they're

2:32

doing, and then just also some context

2:34

about what it appears to be with a

2:36

screenshot of the landing pages.

2:39

Why is this information important for a

2:41

AEV tool set? Well, because this info

2:45

helps us marry it up into some thread

2:47

intelligence feeds.

2:49

So once that investigation is launched,

2:51

we're going to assign either a nominal,

2:54

a significant, or an elevated risk if

2:57

any of these groups were to target your

2:59

company.

3:00

If I click into an AP1, I can say, okay,

3:04

here's a description of what AP1 does,

3:06

who they are, who they tend to target.

3:09

They favor using these specific tools,

3:12

and they also favor these TTPs.

3:16

Based on that information about them and

3:19

you, we think that they pose a

3:20

significant risk if they were ever to

3:22

target your company because you're the

3:24

type of company they target and these

3:26

techniques may be successful against

3:28

your specific tech suite.

3:32

So, what this is going to do here is

3:33

it's going to later help uh influence

3:36

the objectives throughout both the

3:38

external and the internal engagements if

3:40

you would like to emulate the behavior

3:42

of any of these groups. Before we get

3:45

there, we need to deploy some footholds

3:47

internally so that we have a jump host

3:49

in order to reach those inside assets.

3:52

So, we're going to come into the

3:53

deployment phase here.

3:56

Now, the uh AEV deployments, these are

3:59

not agent-based. This does not need to

4:01

live on every workstation or every

4:04

endpoint. Think of this as a a physical

4:06

laptop that one of your pentesters would

4:09

have. So, creating a deployment is as

4:11

easy as naming this. I tend to name it

4:14

by location

4:17

and then choosing what type of hardware

4:19

or operating system this is going to run

4:21

on. So we do support Linux distros. We

4:24

can run on Mac, either Intel or

4:26

silicone. We can run on Windows. And

4:28

then we also do have an OVA file if you

4:31

would prefer to run on a on a

4:33

hypervisor.

4:35

Deploying this is as easy as dropping

4:38

this command in command line on that

4:40

host device. That's going to install all

4:43

the dependencies that are needed

4:45

throughout the testing engagement and

4:47

it's going to connect to our SASbased

4:49

tenant here for you to be able to

4:51

remotely manage.

4:54

Now, once those footholds are deployed

4:56

and you're able to reach the hosts that

4:58

need to be in scope for testing, we're

5:00

going to do something similar on the

5:01

inside that we did on the outside. We're

5:03

going to visualize what that surface

5:05

looks like. So, from within here, I can

5:08

choose an individual foothold.

5:12

and I'll be able to see all of my

5:13

network interfaces and all hosts that

5:16

are reachable by ping across various

5:18

subnets. So here's a list of every host

5:20

that I can ping using this foothold. And

5:23

now I know that I can put these in scope

5:25

for my internal engagements.

5:28

So the next step is going to be to

5:30

actually craft and launch those

5:32

engagements.

5:34

Up here I'm going to go into the

5:35

engagement stage. This is where you'll

5:38

also be able to ingest all of the

5:39

results. But first, we're going to

5:42

create.

5:44

So, from within here, we currently have

5:46

the ability to launch internal and

5:48

external network pentest teams. And we

5:53

can also launch uh tests against REST

5:56

based APIs, both internal and external.

6:00

For me right now, I want to launch an

6:02

internal engagement and I want it to be

6:04

somewhat red team focused.

6:07

So let's just say this is my data

6:09

center.

6:11

I'm going to choose that live foothold

6:14

that's able to reach the hosts that I

6:16

want to target.

6:19

Here I can explicitly allow hosts to be

6:21

put in scope for testing. So just

6:23

because we can reach 100 hosts doesn't

6:25

mean that you want to actively test all

6:27

of them. We will require your

6:29

intervention here to add them.

6:34

Here are those adversary profiles again.

6:36

So if throughout this engagement you

6:38

would like to mirror and mimic the

6:40

behavior and activities of these APS,

6:43

you can put them in scope. Otherwise,

6:45

we'll just do a base sweep and test any

6:47

way that we can.

6:51

From within here is how I get to dictate

6:53

how I want this story to play out. So I

6:55

had mentioned I want this to be more

6:57

like a red team. I want a very low and

6:59

slow engagement. Maybe I have Crowd

7:02

Strike or a Sentinel One, some sort of

7:04

EDR solution in play in my

7:05

infrastructure and I want to see if I'm

7:07

able to bypass those solutions. I also

7:10

want to see if I have the ability to

7:12

bypass alerts and alarms from the sock

7:15

from the blue team and remain

7:16

undetected.

7:19

On the other hand, we can also pump this

7:20

up to an extreme engagement where this

7:22

is very fast and very loud. Uh

7:25

simulating maybe somebody walking into a

7:28

branch or a brick and mortar, plugging

7:30

in a device with a reverse shell. What

7:32

are they able to do until they are

7:35

locked out of that environment?

7:38

Here we'll let you set a threshold for

7:40

the severity that you would like to

7:42

report on. So maybe you don't have an

7:44

SLA for low orformational findings and

7:48

you only care about medium and above.

7:50

I'll set that threshold for medium. Or

7:53

maybe you just want to configure a test

7:55

to run every week on a Friday and you

7:58

only want to check for critical severity

8:00

findings every week. You can set that

8:02

threshold here.

8:08

Now, within this exploitation phase

8:10

here, we're going to let you choose

DESBLOQUEAR MAIS

Registe-se gratuitamente para aceder a funcionalidades premium

VISUALIZADOR INTERATIVO

Assista ao vídeo com legendas sincronizadas, sobreposição ajustável e controlo total da reprodução.

REGISTE-SE GRATUITAMENTE PARA DESBLOQUEAR

RESUMO DE IA

Obtenha um resumo instantâneo gerado por IA do conteúdo do vídeo, pontos-chave e conclusões.

REGISTE-SE GRATUITAMENTE PARA DESBLOQUEAR

TRADUZIR

Traduza a transcrição para mais de 100 idiomas com um clique. Baixe em qualquer formato.

REGISTE-SE GRATUITAMENTE PARA DESBLOQUEAR

MAPA MENTAL

Visualize a transcrição como um mapa mental interativo. Entenda a estrutura rapidamente.

REGISTE-SE GRATUITAMENTE PARA DESBLOQUEAR

CONVERSAR COM A TRANSCRIÇÃO

Faça perguntas sobre o conteúdo do vídeo. Obtenha respostas com tecnologia de IA diretamente da transcrição.

REGISTE-SE GRATUITAMENTE PARA DESBLOQUEAR

APROVEITE MAIS DE SUAS TRANSCRIÇÕES

Inscreva-se gratuitamente e desbloqueie o visualizador interativo, resumos de IA, traduções, mapas mentais e muito mais. Não é necessário cartão de crédito.