Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 60 for the week of March 26th. Alex, this is the last week of Q1 of 2018.
It's gone fast. It has gone really fast. I feel like it just vanished. Um, there were a lot of other things I wanted to get done in the first quarter that I think are still ongoing. Yeah, it's just amazing.
It seems the older we get, the faster time goes. And hopefully, hopefully we keep getting older. So I guess time's gonna keep getting faster. It's also spring. It's spring.
Spring has sprung. Yeah. Yeah. And actually, it's not only officially spring, it actually feels like spring. It does feel like spring.
Beautiful day. Yeah. Uh, 70 degrees yesterday, I think it was. We had at Ping, we had an outdoor little happy hour thing. It's a really good time.
Nice. All right, so, so as a reminder, we do have a Slack channel now, well over 350 people. This is a great opportunity for you to get to know the community here in Denver. Um, we talk to, talk to folks like yourself at different positions, and it's a good way to get to socialize with people. Yeah, we've started to add even additional channels in the, the Slack group.
So we had one, uh, this week on, uh, studying for the CISSP. So some people were interested in talking about that, so there's a channel out there for that now. So So come and check it out. Yeah, next reminder, we have a Patreon campaign. Patreon is a place where you can go to be an ongoing sponsor of the show to support us.
Alex and I, you know, we fund this out of our own pocket. We've had a couple of folks come along and sponsor us, and we really appreciate that very much. Yeah, and all of the money that we get through Patreon will go back into the podcast. This is not something that we're looking to profit off of. So it'll either go to hosting fees or equipment or You know, once we get to the point where we're covering costs, maybe we'll start doing some other cool stuff too.
Yeah, absolutely. So we do want to say a big thank you to our current Patreons. We've got 5 of you out there who are sponsoring us. So thank you very much for what you're doing. Yeah, it's awesome.
So let's jump into the news. First, we had an article this week. Denver was a top 10 US city for entrepreneurs. And some familiar cities on that list with us, with obviously San Francisco and Austin and Portland, Seattle, a lot of good stuff, but just goes to show what we knew that Denver has a thriving startup environment and it's recognized here in the study. Yeah, and just to be clear on that, they said top 10 because we were number 10, which is still great, but the things that they were looking for were areas that had startup friendliness as well as beneficial financial environments and good demographics in the culture.
Yeah, looking at the next article, we have a story around the blockchain technology being used in the state of Colorado. We— I think we talked about this a while back when there was a proposed law, or there was a request that the OIT, the Office of Information Technology, look into using blockchain for the state. And this article just talks a little bit more that they're still thinking about it. And there's a couple quotes from Vance Brown, who's the CEO of the National Cybersecurity Center in the Springs, talking about how he thinks this would be a good thing. Yeah, I mean, I think both you and I are still a little skeptical of the blockchain Um, but it really, I think you have the opportunity that you could do something, uh, with it.
I'm not sure if we're really to the point where we need to start pushing it on something as important as, you know, all of our government data. But I think the thinking about it, doing research, um, get going down that road, not a bad idea. So I've come around a little bit on the blockchain. So, so number one, I think we've talked about this before. I don't think we should refer to it as blockchain.
I think we should talk about distributed ledgers, because blockchain is a pretty poor implementation of a distributed ledger, with really high transaction costs, really bad energy inefficiency. But distributed ledger as a way for us to ensure one of the 3 pillars of our triad, right? We have confidentiality, integrity, and availability as the core building blocks of security. And I really firmly believe that distributed ledgers can can very quickly and very well assure integrity, not only integrity, but non-repudiation as well, where we can make sure we know who made what change at what time in the blockchain or the ledger. Yeah, great point.
And to your point also earlier, there is a bill currently around using blockchain in Colorado state government, and it is right now in the Senate Appropriations Committee. So still early on in the process for that. Um, so we, we have an article in here from the Denver Post, um, Pay Us Bitcoin or You'll Never See Your Files Again. And it's really just a kind of a walkthrough of what ransomware looks like. The reason we call this out is this would be another one of those good articles for you to share with your less technical friends and family who may not know what this is.
It's written by Tamara Chuang, the, the tech reporter for Denver Post, and it's written in such a way that non-IT people can understand what's going on here. Yeah, and it's actually a pretty in-depth article too. It's fairly long, lots of stuff in there. One of the things that I pulled out of it, they said that over $1 billion has been paid in ransom so far. So it's a pretty good market, right?
It's a pretty good market. Yeah. All right, next, there was an audit of the Colorado Substance Abuse Treatment Program that revealed some gaps in the state's data security practices. So it looked like reading the article, what this boiled down to was, uh, they don't have great termination processes in the substance abuse area. It looked like they weren't fully leveraging, uh, the state's OIT, the centralized resources for this.
And I think we've all been at a point where we've been somewhere where we're not terminating people as quickly as we should. We're not doing all of those steps to make sure that someone who doesn't need to have access to data anymore doesn't have access to it. If you've ever been through any kind of an audit the auditors will always, always, always go for provisioning and deprovisioning, right? It's an easy thing for them to look to. They want to see a ticket that shows when it happened and when it was supposed to happen, what their last day was, and make sure it all matches up.
And, and if you don't do that well, it's going to get called out in the audit. So this is not surprising at all. Yeah, and I think in this case there were actually still some accesses that were there, not just documentation errors. So, so the NIWOT high The next article here is about the NIWOT Girls Cybersecurity Team. So this goes back to that story we talked about, well, a few months ago around the Girls Go Cyber program.
This is a— there was a couple different teams from NIWOT who competed in Girls Go Cyber. And this, one of the teams finished first in all of Colorado and 9th across the whole country. That's awesome. Congratulations to them. You know, it's really great to see this push for young people in STEM and cybersecurity.
Along with CyberPatriots and all this other stuff. Great that there are all these opportunities out there. One thing that I pulled out of that article was that they noted that it's, in the global cybersecurity workforce, it is still 11% women and 25% in information technology overall. Yes, we just don't have a huge number of women in security, and this Girls Go Cyber is a good way to start helping with that pipeline, right? For sure.
Coalfire has named their COO to be its new CEO. So, Larry Jones, who was the CEO who stepped in after Rich Dakin unexpectedly passed away a few years ago, has decided to retire. And Tom McAndrew, who has been at Coalfire for 12 years, is stepping up to be CEO, moving out of that COO role. So big congratulations to Tom. That's, that sounds like a good thing for him.
And it's good to see them promoting from within rather than grabbing some other industry name and, and doing that. I love to see new opportunities for folks internally. Hopefully they find their new COO from internally as well. There you go. Uh, our next story from a local security company, CyberGRX, has been selected to be a finalist for RSA's Innovation Sandbox.
So anyone who's ever been to RSA conference, the Innovation Sandbox is, you're probably familiar with it. It's a pretty cool thing. They have these, this kind of room set aside for the sandbox where they, I think they get somewhere, it was like 6 to 8 of the kind of hot upcoming technologies, put them in a room and everyone kind of goes through and reviews them all. They have little like quick presentations for the group. Then there's a vote to say, you know, which of these is kind of the innovation company of the year and they end up winning.
Yeah, congratulations to them. I think it's also one of those areas where, you know, a younger up-and-coming kind of company can participate in RSA because it is not cheap to, you know, to get a booth and be an official part of RSA. So that Innovation Sandbox really highlights some of those new up-and-coming vendors. Yeah, so even if they don't win, there's— this is awesome exposure for them. They're gonna have thousands, tens of thousands of people probably come across them because of this opportunity.
And of course, if they win, that'd be even bigger. So big congratulations to those guys. Yep. Uh, Red Canary had a blog this week, uh, How an IT Service Provider and Red Canary Stopped a Malware Outbreak. So basically, um, a little case study here on incident response and how Red Canary went through that with one of their customers.
A couple, uh, takeaways there at the end of the article. Um, good overview again on, on how you should be prepared and be ready for an incident. Yeah, I love these kind of blogs and articles because they give us a view into what actually happened at a company. And what this does is it shows you, you know, case study for a place that has an outsourced IT provider in combination with Red Canary. How do those 3 work together effectively to really reduce this risk and recover a lot more quickly than they would have otherwise?
Yeah, exactly. Next, Webroot also had a blog, Spectre Meltdown and the CLIME Exploit. This is another sort of primer article. It had some details on vulnerabilities and exploits and malware. Yeah, lots of definitions, not necessarily for your seasoned security professional there, but again, an article that you can use to help explain some of these concepts to people.
Yeah, if you're one of the many SecureSet students or graduates listening, this might be a good way for you to get a primer on what those things are. Last article here for this week is a blog from InteliSecure about properly framing the cost of a data breach with executives and boards. So this is by Jeremy Whitcop, who's their CTO over there, and I was really impressed by this article. He took some data that we've— it's already been out there. I think he mostly used the Ponemon Cost of a Data Breach report, but looked through the data to find some new angles on it rather than, you know, the way it currently or normally is presented, it's a kind of a linear function.
How many records get breached impacts the cost in a linear fashion. And what Jeremy found as he was doing this research is that it's not really linear. It's really, um, it's really— there's a few inflection points where it goes from, you know, a gradual curve to a really steep curve to a steeper, you know, the, the— and these inflection points are around how much publicity you have around your breach, how much, um, you know, is it only known by folks like us in the security industry? Or does it start to get known by, you know, local reporters? Or then does it get to national news where it's on the front page of, right, you know, Bloomberg, in which case, all of a sudden, you know, the costs just skyrocket per record.
So interesting perspective. And I think his point on this was, you know, by knowing the kind of data and the amount of data you have, you can get an idea what's your worst case scenario. Because for a company that's, you know, 500 people and has the data for, you know, a few thousand people, you're never going to be on the front of Bloomberg. Um, so you're never probably going to have that steep of an angle. But if you're, you know, if you're Facebook and you let, you know, let people scrape 50 million user profiles, then, yeah, you know, you have a pretty big, uh, you know, worst-case scenario.
And the numbers he showed for the, the economic damage done to Equifax was startling. It was in the many billions of dollars, the damage. And his, his argument would be, it is that there was no reasonable amount of security spend that would have been too much to avoid this. That as you look at, as you look at the results here, you know, going and spending an extra billion dollars in security would have made sense for Equifax because of the potential impact for them, whereas of course for most organizations it just simply wouldn't make sense. Yep, exactly.
So, uh, that is our news. We will jump over to our trivia question. So last week, the trivia was, who was Colorado's first official CISO? And you could get bonus points if you could say what they've been doing since. So we did not get a winner this week.
We got several guesses. We had lots of guesses. And all of the guesses were former CISOs of the state of Colorado, but they were not the first. Right. So the correct answer is Mark Weatherford.
He was the first official CISO with that title. Prior to him, Harley Reinertsen essentially was the CISO but did not have that official title. He played the role but didn't have the official statutory title. Yep. And then since that, Mark has been CISO for California, CSO for NERC, Deputy Undersecretary for Cybersecurity.
He was a principal at Chertoff Group, and he is the Chief Cybersecurity Strategist at V Armor. So he has been very busy since. Yeah, absolutely. He's been— he's done a lot of cool stuff. Yep, and he is still in Colorado.
I don't think I knew that. Yeah, I think he's down in Castle Rock or something like that. That's cool. Yeah. Hey Mark, hopefully you're listening then.
All right, um, so talking with Andre Gaeta, our sponsor for trivia, we've decided to change things up a little bit here. Rather than asking you another trivia question this week, um, we want to acknowledge some, some of the cool stuff we've seen in the Slack channel. So, um, going forward here, at least for a little while, we're gonna each week pick us a message from the Slack channel that we thought was the message of the week And we're going to give that person the prize. So if you want to be considered for this, obviously you need to get into the Slack channel. As we mentioned earlier, you can find the Slack channel on our website.
There's a nice little button there that'll get you into the Slack channel. So come on, participate, say things that are witty and insightful and intelligent, and maybe you'll get picked. Or just make me laugh. That could be too. That'll work too.
So, but this— we do have a winner this week from Curtis Helsley. We had a discussion I think the discussion was really all around what had happened with Uber and some of the other— actually, and Facebook, where we had some companies making decisions that go against best practices from a security and maybe even ethical perspective. And Curtis pointed that out just to say security and privacy are quickly becoming moral problems, not merely business problems. He had a much longer comment than this. If you guys want to check it out, go go ahead into the Slack channel.
But good job, Curtis, and we'll reach out to you with your prize. Awesome. So let's move into our upcoming events. As always, you can check out the website and see the full event calendar there. We've got events nearly to the end of the year now.
So I know definitely all into October and November. Yeah, so go check it out, plan the rest of your year. First event we have on there, SecureSet. They are having their career conversations with Karen Warstall. And that's on March 27th.
Also on the 27th is the GDPR meetup. Carlin Dornbusch has been putting this together. Good opportunity to talk about privacy and what the impacts of GDPR are going to be. This particular meeting is about GDPR and the legal basis for processing. Is consent really required?
On the 29th, ISSA Colorado Springs is doing their 5th annual Cyber Focus Day. That's kind of their— 2nd biggest conference of the year. They have their big one in August, but this is a big full-day conference as well with good speakers. Hopefully you guys can make it to that. On the 3rd of April, SecureSet has a Hacking 101 workshop, Intro to Threat Analysis.
There is a critical infrastructure hackathon going on on April 6th through the 8th. We had some information passed to us regarding this. I believe it's something that you have to sign up for, I think, as a team, but I'm not positive. Um, but we've got a link in there to it. Uh, go check it out.
Uh, could be interesting. And then, uh, final event for the next couple weeks is actually yet again Colorado Springs ISSA is going to be doing a Security+ prep course. So they have a 2-week— it's 2 days of prep for Security+. The first day is going to be on April 7th. The second day is the week after on April 14th.
There's a link in the show notes. It's really affordable. This is a really good chance for you guys to get that basic security knowledge. One of my employees recently got his Security+, went to that, and I don't know if that was a reason why he passed or not, but he did enjoy the prep work. Awesome.
Congratulations. So let's jump over to jobs. Yeah, you want me to start these off? I think you can probably start, Robb. Yeah, I got a few Ping Identity jobs here.
The first one on the list is a senior security analyst. This is going to be someone helping us with our infrastructure security program. Need someone who's strong with Linux, having strong networking, and it'd be awesome if the person had AWS experience as well. Really looking for someone who knows security operations and can help us with, you know, kind of centralization of alerts and alert workflow management. All that stuff would be fantastic.
That one's not actually posted on the website yet. Send me a note if you're interested, and I will be happy to to help get this figured out. We'll probably get it posted next week, but I'd love to talk to you about it. Next is an infrastructure security specialist, which is a little bit more junior position on the same team, kind of helping do security operations and, and work on the tooling for the security program. And then the third one is our GRC analyst, which is, uh, kind of a 0 to 2 years experience, gonna help us with our compliance program, working on SOC audits, ISO 27001 audits, GDPR, all that fun compliance stuff.
All right, next, Red Robin is looking for a Director of Risk Compliance and Security. Very cool. We know a couple of the former directors over there, Bill Randall and Merlin Namath. If you like hamburgers and PCI, you should check that one out. Yeah, they both told me that they can't— you can't possibly imagine how much Red Robin you eat in that job.
So hopefully that's a good thing. The City and County of Denver is hiring an Information Security Manager. So if you want to work for the, the best-dressed CISO in town, Steve Corey. This is your opportunity. Gates Corp is looking for a senior security engineer.
Sam Masiello is the CISO over there. Sam's a fantastic guy. We've had him on the show. I think it'd be a fantastic place to work with Sam. Finalist for CISO of the Year last year.
He certainly was. Guild Education is hiring a security engineer. SecureWorks is looking for a senior security program manager. Uh, PwC is hiring a cloud security manager. And finally, FireEye is looking for an associate security consultant.
All right, I think that's the end of news for this week. We do have a, of course, as always, a feature interview. Alex, this week you sat down with Casey Smith from Red Canary and talked about the Atomic Red team, right? Yeah, so Casey is giving a pre-conference workshop at Rocky Mountain Information Security Conference. Uh, which we did not talk about as part of our events earlier.
Um, but so if you want to get in depth on that, you can go sign up for the class. If you want to get a primer and, and hear what it is and what it's all about, uh, that's a lot of what we talk about, uh, in the interview. So it's pretty good. So you guys may or may not be aware that Alex and I have, have been helping put together the program for RMISC and including the pre-conference trainings. And we specifically reached out to Red Canary and said, we want you to do an Atomic Red Team session because I think— I believe that everyone out there should learn how to test their program in this kind of a way.
While they're a vendor, they're not— they don't sell an Atomic Red Team service. This is just a thing that they do for the community, and it's really cool. Yeah, the framework and all the tools that they have around that are free. You can go get it from their GitHub, and I believe that Casey mentions that in the interview. Cool.
All right, Alex, thanks for your time. We'll talk to you next week. This is David Mackey, Director of Cyber Defense with General Motors. You are listening to Colorado Equal Security Security for Colorado security professionals by Colorado security professionals.
This is Alex Wood, and we are doing our feature interview today. We are talking to Casey Smith, Director of Applied Research at Red Canary. How's it going, Casey? Good, real good. Awesome.
So I don't know that many people that— well, I'm sure some people know you that listen to the show. Um, but for those that don't, why don't we give them an opportunity to, to hear a little bit about you and where you came from, what you've done in security, how you got to where you are today? Sure. Yeah, so I've been doing security probably since about 2000. I started— I was working as a pre-sales engineer for Cisco and got involved in security and kind of fell in love with it at that point.
And so back then it was firewalls, VPNs, and, you know, networking route switch kind of a thing. And then I fell into some like development and started doing security development from 2003 to mid-2000s. And then the latest gig I had before I came over here was working at First Bank up in Lakewood. I was a security analyst up there and was there for a while doing both incident response and red teaming. And so kind of fell into doing some research, and one of the things I really love is researching whitelisting evasion tactics, and that's been my real passion.
Just finding things like holes in that and like where, where, how to fix it, uh, has been a lot of fun. So yeah, cool. Yeah, uh, I'm a former customer, customer of Colorado's Bank4U. Okay, there you go. Nice, good stuff.
So I appreciate you keeping my money safe when I was over there. Yep. Um, so one of the things that we wanted to talk about today, we can jump right into it, is some of the work that you guys have been doing here, uh, research around the what you guys are calling the Atomic Red Team framework. Yep. So why don't you tell me a little bit about what that framework is, um, how you guys came to looking at that, what it encompasses, all that kind of thing?
Sure. Yeah, so Atomic Red Team, like, we, uh, we, we think of like atomic testing for like software development. So like, think like unit testing is where the term Atomic Red Team came from. And you're not trying to— you're not trying to blow stuff up, not nuclear stuff. Yeah, exactly.
But the idea was, uh, how do we test these products that we're deploying And what we found was, specifically with the Red Canary, was customers weren't testing well. So they would deploy something and they would just download some malware and say, you caught it or you didn't catch it. And we're like, well, that's not really testing EDR, right? We need to test post-exploitation activity like lateral movement, persistence, credential access. So we came up with Atomic Red Team primarily based on the MITRE ATT&CK framework.
I don't know if you're familiar with that. So MITRE ATT&CK, we mapped tests back to MITRE's ATT&CK framework. So they've done a great work of building a taxonomy or classes of attacks, and we've built unit tests essentially for that. So the idea is like, hey, if you see an attack in the MITRE framework and you wanna know how to test it or how to run it or what does it look like, then we've got test cases on the Atomic Red Team that somebody could use to do that. So we think it gives people a chance to do a couple things like, one, it demystifies the attack so people know a little bit about what it is and it's not something that's out of their reach of understanding, and then 2, it gives them the ability to generate that telemetry that endpoint sensors should detect, and then they could vary those tests as they need to on there.
But that's kind of the heart of Atomic Red Team, is we're hoping for community feedback, like put something out there that people can use to really test more often than just waiting for a pen test or red team engagement. These are tests you could run and schedule uh, weekly, daily on your environment. So yeah, I know I always run into the problem where, um, you put in a new technology or, uh, you know, you build a new rule in your SIEM or something like that and you're like, um, well, okay, I'm just gonna sit here and wait and I'm gonna hope that something happens, right? And I'm gonna sit and I'm gonna look and I'm gonna wait. And then, you know, most often, you know, nothing happens, right?
Uh, and that's never a good feeling because you don't know if it really works. Exactly. You know, and from my perspective, you know, you put in controls and you're not doing an effective job of managing your controls if you can't, you know, put a metric around it, right? You can't test it if you can't make sure that it's working the right way. So I think it's a really cool idea that you guys came up with to try to do that kind of testing.
It's been fun. Like you said, like, we don't want people to wait for something horrible to happen until to find out there's a misconfiguration or something not set properly. Like, Like find out early and often, generate that noise, generate those tracks that you can trace through your environment, make sure you can pivot from one event to another event. Like that's kind of the heart of the project. So yeah, awesome.
So these unit tests, what, what makes up the test? Is it a description of what you should be doing to do the test? Is it scripts or tools or other things like that that you can use to implement the actual test? Yeah, so it's, yeah, it's a good question. So it's a little bit of both.
So each test comes with a description and a mapping back to the MITRE framework, so you can go get more information. We've kind of pushed that back to MITRE. They own the descriptions and taxonomy, but then the actual test is usually a command line or a batch file or a PowerShell script that actually invokes the action that you're trying to detect. Regsvr32 is one that we use, which is like a built-in Microsoft tool that reaches out and pulls down a payload, so we've got all of that on GitHub, so it's all sort of self-contained, so you could run that attack and test it. So yeah, so there's a little bit of both, a description and then also actual payloads, and then we've created something called, we call them chain reactions, sort of keying off the nuclear theme, but the idea is like, what if I wanted to emulate a particular actor?
MITRE's done a good job of tracking groups, so you can say like this, you know, whatever APT3 is doing, they've got some good stuff. So you could go and actually see like, okay, these are the actions they take, and then we could chain those together in a chain reaction and run that test to see how would we do against somebody using this sequence of events or these particular techniques. And are these all made to run, say, against a single host, or is it, you know, you mentioned lateral movement earlier, Are some of them designed where you'd go from several hosts or things like that? Yeah, most of it, I mean, the idea is it could be one or many. The idea is run these tests on anything that you've instrumented with your endpoint software.
So whatever you're using it for detection on endpoint, whether it's basic open source things or something that you've purchased, the idea is ideally it's just there's really very little setup. So we use sort of a living off the land approach for a lot of these attacks, so there's nothing to install, there's no binaries to compile, you can just run these tests right off a single host, or if you wanted to test lateral movement, obviously you'd test multiple systems, but you would hope that all of those are instrumented to collect the test data so you could see the pivot or the movement. And how many tests do you guys have at this point? I think we have about 93 test cases across Mac, Windows, and Linux. We're pretty heavy on the Windows side.
I think that's my background. Mike, my colleague who's helped with this tremendously, is also working on getting some more Mac or OS X tradecraft in there as well. That's awesome. And so what's sort of the future that you guys see for this? Obviously, you mentioned earlier putting out to the community for input and other things like that.
Are you gonna continue to build this? Are you looking to collaborate with people? Sure, yeah, I mean, a couple things that we wanna do. One is, one, we wanna get better technique coverage. I think MITRE's at 183 or something techniques.
We wanna push into that more. Some things we just can't do, but we wanna cover what we can. For example, we can't really write firmware bootkits and distribute those. Although that's a technique, we're just not gonna play in that space. But there's other coverage like maybe token manipulation that we don't have that we wanna add.
So technique coverage is one, and then Mike and I are working on a, we're calling it a framework, menu-driven capabilities. So right now these scripts are very ad hoc, and we really want some sort of a harness that somebody could go in and say, I wanna run this, this, this, and think more like a Metasploit or PowerShell Empire, some sort of menu-driven framework where they could run those test cases and generate the telemetry they need. So that's just something we need to build into it to pull it all together into a single framework with some good ASCII art, I'm sure, too. You mentioned that, and I know MITRE recently came out with a tool called Caldera. Yes.
Which I think is trying to do some of the similar things that you guys are doing, trying to do some of these tests and make it more of a, like a Metasploit, a tool framework that you can put agents out and then run these tests across various different areas. So 2 things on that, is that something that is sort of, helpful to you guys? Is it duplicative of what you guys are already doing? And are you working with those, with the guys? Well, we're in conversations with MITRE.
We're not, I mean, we're not working directly with them. We've submitted some techniques. I've submitted some techniques personally. Red Canary submitted some techniques. Caldera has some requirements for infrastructure to stand up, and so that may be for maybe a more mature shop that can build out and do some more DevOps like SecOps type type work with that infrastructure to build the testing infrastructure.
We sort of have in mind or heart the small security team that doesn't maybe have the capability to go stand up infrastructure, monitor infrastructure, and they can go ahead and just run these test cases. So I think there's probably a place for both. We haven't worked too much with Caldera at all, but we're familiar with the product they're putting out. Nice. Um, so one of the other reasons that we wanted to get together is that you are, um, you're going to be putting together a class for Rocky Mountain Information Security Conference on the pre-conference day, a half, half-day class talking about Atomic Red Team.
I wonder if you could talk a little bit about what people could expect from that. Yeah. And what sort of, uh, you know, maybe who should take it, um, what they might learn from it kind of thing. Yeah, we— I think, I think this— I'm super excited that we have the chance to do this class. We're doing a free 4-hour workshop on this.
I don't know how many seats we'll have, but we're super excited. We'll have a couple instructors there to cover the class. The idea is, we think it's more for practitioners, so people that would be actually running these tests and collecting the data, although it would also be good for people who are making strategic decisions about how do they test their products and things like that. The class itself is going to be quite a bit of hands-on. We'll have some lecture on background and we'll go over the specific techniques.
Like, you know, if there's a technique that we're going to run a test for, we want to make sure everybody understands what it is instead of just running a test case. So we'll dive deep into, you know, maybe a dozen or so techniques. Then we'll look at measurement and collection. So what do you do with the data? So you've run the test, how do you know where it ran?
What telemetry did it generate? And then, you know, maybe you missed it, run the test again, go back and measure your And then lastly, we have what we're calling like a capstone, which is going to be like take some threat reports that you see, like recent threat reports, and build out those chain reactions. And that's something that we want students to be able to do. So we've got like 3 or 4 reports that we can model after on different threat actors, their techniques. And then, you know, people will walk away from the class with actual capability to run those tests on their systems at work with permission, of course.
'Cause these tests obviously model adversary activity, but they would come away with some actual test cases that they've written and feel comfortable using the framework. That's kind of the objective. And so it's a lot to cover in 4 hours, but we're pretty excited about it, and I think it'll be really a lot of fun. Yeah, that's awesome. I'm really glad you guys are gonna be able to come and do that as part of the conference.
Should be exciting. So for those of you that want more information on that class, you can go to rmisc.org, check that out.
One thing I guess I didn't ask earlier is if people want more information on the Atomic Framework itself, do you guys have a site set up for that? Yeah, so we've got a couple of sites. It's on GitHub, github.com/redcanaryco, and then there's an Atomic— that's where the actual repo is, Atomic Red Team. And then on the Red Canary page under resources, we've got some Atomic— like we've done a couple webinars and training, so there's a place where people can get more information right off the redcanary.com page, resources, and then the Atomic Red team from there. Nice.
And can folks contribute directly to that GitHub page? Yes, absolutely. So we're following the model where we accept pull requests, so we expect people to sort of fork the project, edit it, and then submit back into, you know, submit pull requests back to us, and we'll accept those and merge those as we see that they fit. So we've had some good feedback, like a couple of external folks have given us some good Linux and Mac tradecraft that we've been able to add in there, so it's been good. Yeah, that's really good.
I'm interested to see that grow. Yeah, I am excited. We've got a good following and good feedback so far, so we're hoping to continue to get that feedback and improve as we need to.
So obviously the Atomic Framework is one big thing that you're working on. Um, is there other, uh, interesting research that you're doing as, as part of your job here, or, or maybe even other cool research? Yeah, so yeah, a couple things that I'm always interested in. Like lately I've been really interested in telemetry collection because we, um, as defenders, we're, we're putting a lot of capabilities into, um, endpoint collection. Yeah.
And so one of the areas I'm researching would be things like telemetry disruption or tampering. So what assurances do you have that the data streaming off the box is actually, it's a hard problem, like the absence of telemetry. Is the box down? Did an attacker take it down? What happened?
Those are some areas we're pushing into a little bit to try and understand what assurances do we have that endpoint collection is accurate and not been tampered with. You know, how do you trust a compromised host, right? That's sort of the, the challenge that sometimes we face with like EDR. At some point you have to realize you're not going to catch everything, but you're going to catch the bulk of things, right? There may be a set of apex actors that you just may not see, but you're going to see a lot of other things.
So just kind of pushing into that like telemetry collection assurance, I guess. I don't know, I don't really have a name for it. Yeah, well, it's sort of that next level, right? Because sort of in the old days, it was, well, hey, you've got to get all your data off of the box so that no one can mess with it, right? But now, especially with more data being on the endpoint itself, EDR agents being on the endpoint itself, everything is kind of right there.
Not that you're not centrally collecting it also, but there's a lot more sort of attack surface, I guess, on the boxes Yeah, and I think especially like tampering, depending on what you're collecting, like let's say for example you're collecting PowerShell logging, recently one of the folks at Spectra Ops released a tool that blocks logging in like 4 lines of code. So like turn on PowerShell, kill logging, do your thing, and then disappear. But then for the other PowerShell processes, logging would work fine. So those are the kind of things we're trying to look into, like how would you know when that happened? Or yeah, and I don't remember if it was that one or something else, but there's something else that came out recently.
I think it might have even been for Windows event logs where there was something that you could do that I'll say in quotes was undetectable, um, that would turn the logs off. You know, there was some— there's a couple tools, there's some code that would run, um, and turn the logs off but also not log that the logs had been turned off, right? Yeah, there's a couple of tools. There were some tool sets that were released earlier this year, or I guess 2017, that had the capability to edit event logs, so selectively delete events, or like Mimikatz has the ability to turn off logging, so just stomp logging at some point and then just stop the stream. So I mean, I'm certain that attackers are going that route, 'cause if you're dependent on logs for detection, they're going to try and circumvent or tamper with those logs to evade your detections.
So trying to just keep that, you know, like understanding where they're moving with their telemetry disruption. It's kind of an interesting area. Have you guys ever seen anybody— you're talking about disrupting the stuff that you know is coming— have you seen anybody either sending false flags or other stuff like that trying to throw you guys off? You know, they know stuff's being collected, but, you know, maybe it'll lead you in the wrong direction if they— if you think something else is happening. Yes, I haven't seen— I haven't seen that, like false flags.
I've certainly seen people trying to blend in. Yeah, so that what they're doing looks normal, but I haven't seen any sort of false flags like, hey, you know, I did this thing, but really I did this thing over here. I haven't encountered that yet. So, but it's certainly been the realm of possibility. So Cool.
So what other kind of stuff are you guys seeing in terms of where attackers are going, what they're doing, interesting detections that you've seen or encountered? Yeah, so one thing we've seen, and this has probably been in the last year or 2 years, we've seen a big uptick in living off the land. So less attacks using malware, more attackers using built-in operating system tools, PowerShell being a very popular tool or framework. Other tools, Regsvr32 is another tool that people will use to run these things called COM scriptlets. I don't know if you've seen like Nick Carr on Twitter has like a daily scriptlet or John Lambert from Microsoft.
It's kind of this old technology like from the late '90s, early 2000s. COM scriptlets were like this thing you could get to register on the system and run So we're seeing a resurgence of something like VBScript and JScript. It's kind of interesting that that's come back around, but I think people are, I think attackers are seeing there's a lot of binary scrutiny. So if you're gonna drop a binary on disk, there's either application whitelisting or there's endpoint telemetry or VirusTotal or sort of reputation being one. Has anyone ever seen this binary?
If it's only one computer in the world, Why am I running this thing, right? So I think attackers are trying to get more creative in ways to evade. So living off the land, if you can get, for example, a Microsoft trusted tool to do something malicious, then that's baked into the operating system. You didn't have to bring anything with you necessarily except for a text file or XML file. So those are probably some of the interesting things we've seen in the last couple years, I think, just attackers using that trade craft.
Yeah, and I've heard a lot lately of different strains of ransomware that are using stuff like PsExec to push itself around. It doesn't need to worry about actually trying to connect to these other machines through some of the advanced— well, I'll just push myself around through PsExec, run myself wherever I need to run. Yep, PsExec is one. There's some ransomware that's using— there's a tool I think it's crypt.exe that you typically use to encrypt files through Windows NTFS, but they can use that tool built in to encrypt. They didn't have to bring their malware, they just run this tool.
There's some other things like certutil is another one that they can use to encode and decode files in Base64. There's just a lot of things that are available on the OS that they don't have to write themselves. Functionality. Yeah, that, that reminds me, I was just— I was playing around the other day, um, with, uh, virtual, uh, Microsoft virtual disks encrypted with BitLocker. Okay.
Yeah, um, I can see where, you know, somebody using ransomware could, could get on your system, create a virtual disk, shove all your stuff in there, and then encrypt it with BitLocker. Yeah, all stuff that's available in Windows, right? That, right, tools that you, that you want to use And now all of a sudden all your stuff's locked up. Yeah, it's grim. So I haven't seen that, but yeah, that's kind of a scary thought for sure.
So yeah, that's no fun. Yeah, so I think those are things that we've seen. Attackers are always innovating, always trying to find, push the new thing, and leaning into trying to understand those detections and what tools are they using in strange ways, like weird command lines or things connecting to the network out of sync. System32 on Windows, for example, that maybe shouldn't be, right? Kind of thing.
So, well, yeah, I mean, and then even beyond that, you know, lots of— I've seen more memory attacks, right? So it's— you're just— you're pulling down something directly into memory, right? Letting it run there, you know, PowerShell scriptlets, stuff like that. Yeah, PowerShell is very common for that. Exactly.
So yeah, trying to stay off the disk, because again, the disk has been, you know, instrumented for so long to detect new file writes, file modifications, modifications, so the less they can write or expose themselves at the disk level, then they'll just stay in memory. They may not care about persistence. If they can conduct the attack within hours, then they don't care if that system reboots or persisting. It just depends on their objectives. What do you tell somebody to combat that kind of stuff?
Is it PowerShell logging? Is it Yeah, I mean, that's a good question. I mean, to combat the living off the land sort of a thing, yeah, a lot of it boils down to detection. For Windows, for example, there's a great place, Sysmon's a really good tool to start getting that endpoint telemetry so you understand what's happening with the process create event, what's the process ancestry, who spawned it, for example, why did Microsoft Word spawn PowerShell? So those relationships can be picked up with the tools like Sysmon, I mean, and that's a free tool.
So I always tell people start with some form of collection to understand, like, and then I know, I don't wanna sound glib, but everybody talks about building a baseline, but at some point you do actually need to collect and understand, like, once you're getting that process data, you do need to actually run and say, like, well, how often does PsExec run in our network, for example? And do I wanna be alerted if a non-admin runs PsExec? Those are the kind of things that we have to start looking at because it's not just always about dropping a binary and running it. I'm also a big advocate of application whitelisting. I talk all the time about it.
AppLocker, Device Guard for Windows are great tools. Unknown, untrusted things don't run, and you can build rules and say if I want to block this, or Microsoft has a tool called EMATS which is pretty cool that has an attack surface reduction feature that actually allows you to say don't let this like red serve 32 load this DLL. So you can get really granular with some rules and block some attacks that way. So there's some good stuff out there like I said Sysmon, AppLocker are good to explore. So I know there's quite a bit to deploy those but they do go a long way to stop a lot of attacks.
Yeah, and I know you guys focus a lot on you guys being Red Canary focus on, you know, sort of your smaller medium-sized business, not necessarily the gigantic enterprise companies. Do you have— do you think that those kind of security teams have the resources and skills to do the Sysmon type work or other things like that? I think they do. I think, I think like we've seen like being able to pipe like event logs into Splunk or something, like I feel like As long as a mid-sized, a larger organization would definitely have the capability to do that. Some of the smaller shops, it's just hard, and that's where we can kinda come in and help augment some of that and say, hey, if you can get us the telemetry, we can help with the detections.
But it is kinda hard, I think, for some of those smaller shops to do that. But even locally, just starting to understand, say you have 100 machines, Sysmon would be really easy to push out and then start feeding that to some sort of event log collection and start looking at process starts. It would be a great place to start. There's some really good configs that SwiftOnSecurity has created. I don't know if you're familiar with that Twitter account, but that account, there's some really good stuff on GitHub for how to filter so your Sysmon logs are minimal.
So you can filter out things that are known good good, so to speak. So I don't know. I think it's possible. Cool.
So anything else that you've got going on? Cool research? Are you talking anywhere else? Let's see, I've got a couple fun things coming up. I'm speaking at SparkCon, which is in Bentonville in early April.
I'm doing a talk called Trusted Things That Execute Things. It's my research on known good binaries that do bad things, so to speak. And then I'm doing a talk in late April at the Blue Team Summit, and that's in Louisville for SANS, called Winning with Whitelisting. So hopefully to dispel the myths of like, what does it take to actually win with whitelisting? So those are a couple things I've got.
Then of course the Rocky Mountain Information Security Conference, we've got our Atomic Red Team class. So those are kind of the big 3 that are in front of me right now. So super excited about that. Awesome. Yeah.
I think that's most of the questions that I had. Anything else that you wanted to talk about before we get out of here? No, I think if people are interested, I'm on Twitter @SubT. Feel free to connect with me if you have questions or feedback on anything we're working on. That's a good way to find me.
Thanks for taking the time to talk to us. We're super excited about this. Awesome. We're really excited to have you at Rocky Mountain Information Security Conference. Everybody should go out there and see sign up for the class.
Yeah, should be great. And, uh, you know, if you guys have the, the desire and the skills, go out there and get some pull requests on the Atomic Red Team tests and, and help contribute to that too. Yeah, that'd be great. That'd be awesome. Thank you.
Awesome. Great. Well, appreciate your time. Thank you very much. This has been Colorado Equals Security, and we will talk to you next time.
Learn more about the Colorado security scene at colorado.gov/security. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.