“Credential Theft” or “Credential Reuse” attack techniques are the biggest known threats to Active Directory environments. This can be attributed to significant advances in and broad distribution of attack and reconnaissance tools such as mimikatz or Bloodhound. This means that after the first system in an environment is compromised it often takes less than 48 hours for a complete compromise of an Active Directory but unfortunately typically 8 to 9 months until the attack is discovered.
Continue reading Continue readingIPv6 Talks & Publications
At first a very happy new year to everybody!
While thinking about the agenda of the upcoming
Troopers NGI IPv6 Track I realized that quite a lot
of IPv6-related topics have been covered in the last years by various IPv6
practitioners (like my colleague
Christopher Werny) or researchers (like my
friend Antonios Atlasis). In a kind of
shameless self plug I then decided to put together of list of IPv6 talks I
myself gave at several occasions and of publications I (co-) authored. Please
find this list below (sorted by years); you can click on the titles to access
the respective documents/sources.
I hope some of this can be of help for one or the other among you in the course
of your own IPv6 efforts.
Cheers,
macOS Mojave Hardening Guide
Due to the new release of macOS Mojave in September we updated the El Capitan hardening guide.
The hardening guide received a little revamp on some chapters which are now obsolete or had to be changed due to the new features of macOS Mojave. Further, the hardening guide got extended for the new privacy features in macOS Mojave.
You can check it out
here.
We hope some of you might find it helpful.
Cheers,
Birk
Secure CI/CD Pipelines @Troopers ’19
In the last couple of months we participated in an increasing count of customer projects following current trends of agile software development approaches and corresponding toolstacks. Especially the terms Continuous Integration and Continuous Delivery kept (and still keep) popping up on every corner. The frameworks and processes behind those two hypes aid developing software at higher quality in shorter release cycles. This is especially relevant since end consumers nowadays expect fast releases including the newest features. If companies neglect this demand, competitors might take advantage of their better time-to-market which might result in increased market share and -dominance. A lot of changes are happening in the space of CI/CD. Existing tools become more mature, gaining increased attention, and new ones are appearing every month including better ways of integrating them into existing or new processes. Companies benefit from more choices, increased flexibility, and faster integration into existing company policies.
Continue reading Continue reading35C3: Refreshing Memories
Hello fellow Troopers and Happy new Year!
35C3 is over, and the recordings are available so in case you did not have the chance or the time to watch the live streams during the holidays or overwhelmed with the number of talks, see in the following a list of recommended talks to fill your evenings or weekends. Apart from the broad coverage of topics in different areas (Ethics, Society & Politics, Hardware & Making, Resilience, Art and Culture, Security, Science, Resilience), foundation talks were aiming for the very basics following this year’s motto “Refreshing Memories.”
Continue reading Continue readingBlackhoodie at TROOPERS19
We are going to have a Blackhoodie event at Troopers 2019 on March 18th and 19th in Heidelberg. With a very exciting event last year, we have decided to roll it once again during Troopers.
As always, one of the main motivation for Blackhoodie is bringing more women into reversing and other core security topics. So we would like to see more women apply to the training slots. However, if you are not a women and still feel really excited about Blackhoodie, you are welcome to apply. We do have a very limited number of seats at this training site. So we apologize in advance if we can’t accommodate everyone, even though we wish we could! Please apply before “February 10th” and we will contact you regarding next steps.
Continue reading Continue readingCatching fire with Docker, DevOps & Security in Enterprise Environments
Docker has become the go-to technology in enterprise- and DevOps contexts. Yet, before mastering a skill, there is the thumb rule: one must learn the basics to have solid fundament before building a house on top.
Simon and I start from the very beginning. We introduce you to the fundamental concepts of containers starting at process isolation and extending our tour to the whole ecosystem of Docker and further associated technologies. We will cover Docker, microservices, containers, DevOps, continuous integration/deployment/delivery – all those fancy buzzwords that can be read in the context of modern software development methodologies.
Continue reading Continue readingMotivational Aspects and Privacy Concerns on Wearables in the German Running Community
Today I am proud to announce that another paper of my former colleagues from Heilbronn University and me was published in one of the journals with the highest impact factor for Medical Informatics research called JMIR mHealth and uHealth. There is a reason why we published in this journal besides its informatics focus. The journal is an open access journal. That means that readers are not charged on a pay-per-view basis or other business models to access the full text of the paper. In return, the authors need to pay publication fees. In my opinion restricting access to academic research is not a way to go. I think this isn’t a thing we see in the security community often anyway. But this is and was the standard in academia for years.
Continue reading Continue readingERNW Whitepaper 67: Active Directory Trust Considerations
Last week Will “harmj0y” Schroeder published an excellent technical article titled “Not A Security Boundary: Breaking Forest Trusts” in which he lays out how a highly critical security compromise can be achieved across a forest boundary, resulting from a combination of default AD (security) settings and a novel attack method. His post is a follow-up to the DerbyCon talk “The Unintended Risks of Trusting Active Directory” which he had given together with Lee Christensen and Matt Nelson at DerbyCon (video here). They will also discuss this at the upcoming Troopers Active Directory Security Track (details on some more talks, including Sean Metcalf’s one, can be found in this post or this one).
Continue reading Continue readingAnd Five Talks More Were Accepted at TROOPERS19!
And five talks more were chosen for TROOPERS19! It sounds like it is going to be the best year ever again…
Follow us on Twitter (@WEareTROOPERS) for more information and do not hesitate to use our hashtag #TR19 when you have questions or remarks about TROOPERS19!
Your TROOPERS Team
——————————–
Not A Security Boundary: Breaking Forest Trusts by Will Schroeder, Lee Christensen
Presenting at the Active Directory Security Track
Abstract:
Continue reading Continue reading