Posts

Bypassing CrowdStrike in an Enterprise Production Network [in 3 Different Ways]

Image
EDR solutions and specifically CrowdStrike Falcon are giving us a hard time recently. It seemed that no matter how covert we tried to be, a well-trained blue-team was able to utilize these type of solutions to pick up on our activity relatively fast. That’s why when we had an opportunity to travel to India and sit in the same room with the SOC team of one of the biggest companies in the world, a team that built their detection capabilities around CrowdStrike, we couldn’t resist the urge to test out some of our ideas on how these tools can be bypassed. tl;dr: We ended up with 3 new techniques for CrowdStrike bypass that force blue-teams (and CrowdStrike) to re-think some of their current detection and mitigation tactics. What is CrowdStrike anyway? CrowdStrike looks at the OS of a machine, logs pretty much everything that happens on it (processes, memory, etc.), and alerts on deviations and anomalies from standard behavior (I’m sure it does many more things, but for our purposes this de...

Penetration Testing vs. Vulnerability Assessment – What's the Difference?

Image
Penetration testing and vulnerability assessment are both important tools used in the field of cyber security. They serve different purposes and have distinct advantages and disadvantages. Penetration Testing Penetration testing, also known as “pen testing,” is a simulated attack on a computer system, network, or web application to evaluate the security of the system and identify any vulnerabilities that could be exploited by a real attacker. The goal of a penetration test is to penetrate the system, meaning to gain unauthorized access or to disrupt normal system operations. This is done by simulating the actions of a real attacker. It consists of tactics such as researching, social engineering, network scanning, and exploiting software vulnerabilities. Advantage of Penetration Testing One of the main advantages of penetration testing is that it provides a realistic assessment of the system’s security. Since the test is conducted using the same tools and techniques as a real attacker, ...

Benchmarking Top 5 Managed Application Security Service Companies in 2023

Image
Introduction When it comes to protecting your business from cyber threats, managed application security services can be a valuable addition to your security strategy. These services provide expert guidance and support in identifying and mitigating applications’ vulnerabilities, helping you reduce the risk of data breaches and cyber-attacks. In this benchmark, we have compared the top five managed application security service companies in 2023 — Komodo Ranger, Nessus, Qualys, Synopsis, and Rapid7. Criteria for Comparison For comparing these companies, we have considered a range of criteria, including the services they offer, the expertise and experience of their security professionals, their reputation and track record in the industry, and the overall effectiveness of their services. We have also considered any additional features or services they may offer, as well as their pricing and affordability. Komodo Ranger Komodo Ranger is a leading provider of managed application security se...

Black Box Penetration Testing: An In-depth Guide

Image
Black Box Penetration Testing is a process of testing in which the tester has no prior knowledge of the system under test. The tester is essentially “blind” to the system’s internals and must rely solely on its external interface (e.g. web interface, API, etc.) to carry out testing. Despite its name, Black Box Penetration Testing is not actually about breaking into systems. Rather, it is about testing the system’s security from the perspective of an attacker. The goal is to identify any security weaknesses that could be exploited by an attacker to gain access to the system or its data. Black Box Penetration Testing is an important part of any security assessment. It can help to identify vulnerabilities that would otherwise be missed by traditional security testing methods. It is also a good way to gauge the security of a system from the perspective of a real-world attacker. Pros and Cons There are pros and cons to black box security testing, just like everything else in life. On the pl...

Open Sesame by Open.AI – How We Became Masters of All Doors

Image
Disclaimer: This post is written using the ‘Da Vinci’ open.ai model and has been edited to make it more presentable. Watch this space for a more technical article on this topic in the future. It was fun and exciting to write this post using the ‘Da Vinci’ open.ai. This story is based on real experience and there is a lot to learn from it. So, we decided to share it with the world. Our firm moved to a new office which is located on the 25th floor of a contemporary business building in Tel-Aviv, providing a stunning view of the city’s skyline. The space features a range of amenities to ensure comfort and productivity, but the thing that we love most about the new office premises are the doors. The doors are connected to an IoT device that uses a Bluetooth protocol. A mobile application with a user-friendly interface allows employees to authenticate and control the doors. The application allows residents of the building to open and lock the door from their phones. The system piqued our cu...

Can Security Red-Team Exercises Give You ROI On Your Cyber Security Expenses?

Many organizations have learned this lesson the hard way, with several attacks launched against large corporations, such as Sony Pictures, Marriott, Yahoo, Target, Alteryx, and Equifax. However, this shift also came from industry leaders, seeing where other companies fail and proactively handling these situations. Nowadays, we see company leadership asking questions like: How can we tell if we are a victims of a cyberattack? Will we know when it happens? Are we equipped enough to handle this incident in real-time? Have we wisely spent the millions from our security budget on these security tools? Can we trust them when the time comes? This maturity phase of the security industry is also the dawn of understanding that for an organization that wants to be ready for cyberattacks, there is no magic solution, no silver bullet. When companies start performing these security red team exercises, I usually see initial shock. At first, most organizations don't even know that anyone has infil...