惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
量子位
月光博客
月光博客
罗磊的独立博客
宝玉的分享
宝玉的分享
博客园_首页
酷 壳 – CoolShell
酷 壳 – CoolShell
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
WordPress大学
WordPress大学
博客园 - 叶小钗
博客园 - 聂微东
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
雷峰网
雷峰网
博客园 - 三生石上(FineUI控件)
Jina AI
Jina AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
美团技术团队
爱范儿
爱范儿
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Y
Y Combinator Blog

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
How to Use Backdoors & Breaches to do Tabletop Exercises ...
BHIS · 2022-05-16 · via Black Hills Information Security, Inc.

, , , , , , , , , , , , ,


Slides

Have you heard of Backdoors & Breaches, or even have a deck of your own, and yet… still don’t know how to use it?

We created an incident response card game that helps you and your organization conduct engaging and effective tabletop exercises. Watch us demo the game and play through the free online version so that you can use Backdoors & Breaches in your organization, club, or association.

Get Backdoors & Breaches: https://spearphish-general-store.myshopify.com/collections/backdoors-breaches-incident-response-card-game

0:00 intro to the team and Backdoors & Breaches story

2:23 Online open-source game copy

3:15 Why we sell physical copies and info for educators

3:40 Red Card (Initial Compromise)

5:28 How the “Detections” were created

7:29 Yellow Card (Pivot and Escalate)

10:56 Brown Card (C2 and EXFIL)

11:35 Purple Card (Persistence)

12:32 Game Setup

13:12 Procedures and rolling your D20

14:34 Procedures being used

15:15 Green Cards (Consultants)

16:00 The Scenario

21:05 Actions that don’t require dice roll, “clarity vs. analysis”

27:30 First Procedure Dice roll and turn cool off counters

30:00 Debug Cautionary word from Jason

32:10 Procedure that works! (successful dice roll)

34:07 Revealing Attack Scenario cards upon successful roll

35:45 understanding the difference in established procedures and other procedures

39:56 Expansion Gray Card (Inject Card)

45:50 “at what point does an incident become a crisis?” Who on your team knows the difference?

52:57 Game Wrap up

53:40 Is this a plausible attack? Always ask that question at the end of the game

58:27 Goodbyes and Thank Yous

––– Join the BHIS Community Discord: https://discord.gg/bhis

––– Play Backdoors & Breaches Online: https://www.blackhillsinfosec.com/projects/backdoorsandbreaches/



We are self-publishing free Infosec Zines called PROMPT#.

PROMPT# will contain: 

  • Infosec articles 
  • Challenging puzzles 
  • Comic book based on real-life hacking adventures 
  • Coloring contests 
  • Bonus Backdoors & Breaches Consultant Cards (print version only) 
  • Other stuffs 

You can check out current and upcoming issues here: https://www.blackhillsinfosec.com/prompt-zine/