The document discusses lessons learned from emulating cyber adversaries. It recommends choosing adversaries based on relevance and intelligence available, and harvesting intelligence from diverse open sources as well as direct investigation. The document emphasizes following adversary techniques closely based on intelligence rather than personal preferences. It stresses balancing accuracy with making the emulation impactful and enjoyable through an iterative process of learning, sharing, and improving.
1 of 35
Download to read offline
More Related Content
Reaping What They Sow - Hard Lessons Learned Emulating Threat Actors
1. Reaping What They Sow -
Hard Lessons Learned
Emulating Threat Actors
Jamie Williams
@jamieantisocial @MITREATTACK
3. Why Emulate Adversaries?
Variety of offensive assessment
types, each with its own place
Intelligence-driven
approach provides:
- Realism
- Scoping
- Diversity
- Repeatability
8. But Also Mistakes
Source: https://giphy.com/gifs/8jzdgXpr9Po1a
Source: www.microsoft.com/security/blog/2020/06/11/blue-teams-helping-red-teams-
a-tale-of-a-process-crash-powershell-and-the-mitre-attck-evaluation/
9. But Also Mistakes
Source: https://giphy.com/gifs/8jzdgXpr9Po1a
Source: www.microsoft.com/security/blog/2020/06/11/blue-teams-helping-red-teams-
a-tale-of-a-process-crash-powershell-and-the-mitre-attck-evaluation/
10. But Also Mistakes
Source: https://giphy.com/gifs/8jzdgXpr9Po1a
Source: www.microsoft.com/security/blog/2020/06/11/blue-teams-helping-red-teams-
a-tale-of-a-process-crash-powershell-and-the-mitre-attck-evaluation/
13. Make Something Special
A lot of great emulation
work going on
across industry
Each emulation has an
opportunity to capture a
unique scenario /
combination of behaviors
Source: https://giphy.com/gifs/l0HlVWsgDwQgGz1io
32. You Are Not Your Adversary
Ignore your preferences/
what you would do
Dont fix things that
arent broken
Be willing to learn and
try new things
Source: https://giphy.com/gifs/AEMyf9Oj6MpS8
33. Trust Your Intelligence
You have a roadmap
There may be small
gaps to fill,
circle back/ask around
Would they do this?
Source: https://giphy.com/gifs/bcZ8T9ctIriAU
34. Important Takeaways
Adversary emulation is
impactful, but also
a lot of fun
Balance of a lot of
delicate skillsets
Not an exact science, so
learn, share, and get better
as you go
Source: https://gph.is/1auqnpt