惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
U
Unit 42
D
Docker
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Recent Announcements
Recent Announcements
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
V
Visual Studio Blog
I
InfoQ
Google DeepMind News
Google DeepMind News
小众软件
小众软件
L
LangChain Blog
C
Check Point Blog
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
J
Java Code Geeks
罗磊的独立博客

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Webcast: OPSEC Fundamentals for Remote Red Teams
BHIS · 2021-03-25 · via Black Hills Information Security, Inc.

, , , , , ,





During remote red team exercises, it can be difficult to keep from leaking information to the target organization’s security team. Every interaction with the target’s website, every email sent, and every network service probed leaves some trace that the red team was there.

Mature blue teams can correlate those pieces of information to identify red team actions and infrastructure, and use that information to either block the red team outright or execute deception operations to frustrate further attacks.

In this Black Hills Information Security (BHIS) webcast, Michael will discuss common sources of data leakage during remote red team exercises and steps red teamers can take to eliminate or disguise the leakage outright, or to compartmentalize their actions and keep the blue team from connecting the dots.

He’ll also discuss how red teamers can see the attack from the defender’s point of view so that these concepts can be applied to new tools and technologies in the future.

Join the BHIS Community Discord: https://discord.gg/bhis

0:00:00​ – PreShow Banter™ — It’s Not Delivery, Its Frozen

0:09:36​ – PreShow Banter™ — One Rural to Rule Them All

0:11:51​ – PreShow Banter™ — Proudly Sucking at Charity

0:13:08​ – PreShow Banter™ — SPECIAL GUEST: Rural Tech Fund

0:20:39​ – PreShow Banter™ — Meth Lab For Computers

0:25:41​ – FEATURE PRESENTATION: OPSEC Fundamentals for Remote Red Teams

0:27:00​ – WHOAMI

0:30:42​ – Why OPSEC is Important For Red Teams

0:34:01​ – Possible Countermeasures

0:36:37​ – Other Red Team Threats

0:38:06​ – Assessing Red Team Actions

0:39:26​ – Building OPSEC Standard Procedures

0:40:42​ – Local Workstation Setup

0:45:01​ – OS Modifications

0:49:44​ – TOOL Configurations

0:56:35​ – Source IP Addresses

1:01:36​ – Fail-Safe VPN

1:02:57​ – Other Third-Party Services

1:10:05​ – Network Services

1:15:19​ – Testing New Tools

1:21:42​ – Got Questions

1:27:03​ – PostShow Banter™ — Access Granted

Michael Allen is a security analyst at Black Hills Information Security, where he works exclusively on offensive security assessments like penetration tests and red team exercises. After earning an Associate’s Degree in Computer and Information Science and many years of hacking “just for fun,” Michael finally turned his hobby into a career in 2014. Since then, he has also spent time teaching courses at Black Hat USA and earning a multitude of InfoSec certifications, including the OSCE, MLSE, and CISSP, among others. He joined the BHIS team in 2019 where he is proud to work alongside some of the best and brightest InfoSec professionals in the world today.

Slides for this webcast can be found here: https://www.blackhillsinfosec.com/wp-content/uploads/2021/03/SLIDES_OPSECFundamentalsRemoteRedTeams-1.pdf

Want more content from Michael? Why not take a class with him?

Red Team: Getting Access

Available live/virtual and on-demand!