Jason Lang Profile picture
Jan 2 โ€ข 14 tweets โ€ข 2 min read โ€ข Read on X
Welcome to my 2023 Irreverant Red Team TTP Wrap Up (Trends, Trolls, Predictions)

It's likely some of these will ruffle feathers, but hackers break things right? ๐Ÿ˜

๐Ÿงต๐Ÿ‘‡
1. SIEMs are being replaced by XDRs, which are winning in that market space. Top best defensive product additions are identity based: CSI & MDI (or whatever MS is calling it these days).
2. AI hasn't replaced anything (yet). We are still on the upswing of using it to assist with coding, rather than full service replacement. Some neat AI based red team products are starting to emerge.
3. Cobalt strikes are down! Yes, the C2 matters. While FOSS-C2s are still great, lots of shops are buying commercial alternates and/or writing their own. Nighthawk/BRC4 drama continues to remain hilarious.
4. UBA has yet to really take off, but will be an incredible defensive force if and when it does.
5. Deceptive techniques are on the rise. Orgs are (slowly) figuring out they can have more than one honey service account that doesn't have "Infosec - do not delete" in the description field.
6. Red Team telemetry is the hotness. Started with Red Elk, picked up with Nemesis, and lots of groups are doing it internally. You need that data. Get on it.
7. Assumed Breach has reached mainstream and is still rising. Various types are now being fleshed out and continue to bring great value to clients. This trend will likely continue for some time.
8. Tradecraft sharing has largely gone to DMs. Still happening between trusted groups. This is way more a reflection of the speed to detect rather than the OST debate, which nobody really cared about.
9. X remains the best place for latest infosec news and sharing. The mastothreads movement came and went o/. POC sharing is up while full tool sharing seems to have decreased due to liability concerns.
10. Vocabulary continues to shift. Talk of "risk" is gone. "Findings" are becoming "observations". "Skids" are now "cyber novices". Hacker culture of old continues to slowly decline in its effort to placate lawyers.
11. Stealth is important but takes a back seat as the gig continues as more and more engagements are including tightened collaboration with the defense.
12. R&D is now more critical than ever as defenses increase. Except for top shelf TAs, red teaming tradecraft seems to have handily outpaced the whoami groups of the world (should have ran whoami1.exe tsk tsk)
13. Nano has been awarded "breakglass" status as the world has shifted to modern editors.

Thanks for reading!

:wq!

โ€ข โ€ข โ€ข

Missing some Tweet in this thread? You can try to force a refresh
ใ€€

Keep Current with Jason Lang

Jason Lang Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @curi0usJack

Jun 24, 2020
One infosec professional's perspective on OST.

Beware, this thread contains nuance...
1 Having watched the OST debate from the sidelines, I have enjoyed the thinking challenge that the debate represents, which is fundamentally searching not for the "best" thing to do, but for the "most right" thing to do - an ethical search at its core.
2 I have worked on the offensive side of the industry for 6+ years (defensive 10+), and have written tools used by both nation state actors (confirmed) as well as defenders. The knowledge that my tools caused others harm is what fundamentally stopped me from releasing more.
Read 15 tweets
Mar 27, 2020
Just finished giving my first virtual training class.

Here are a few lessons learned for other instructors who are getting ready to do the same...
My class was a technical one. Very focused on labs that had students using a lab manual (PDF) to perform the various steps (SSH, Linuxy things). The general flow of the class was lecture, lab, lecture, lab over a 2 day period.
1) A dedicated chat room for class is a must. This was the best decision I made. During the lecture, I was on the call running through my slides, then turned them loose on labs and muted myself. All lab support was based on the Slack room.
Read 14 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(