Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Adversarial Tradecraft in Cybersecurity

You're reading from   Adversarial Tradecraft in Cybersecurity Offense versus defense in real-time computer conflict

Arrow left icon
Product type Paperback
Published in Jun 2021
Publisher Packt
ISBN-13 9781801076203
Length 246 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Dan Borges Dan Borges
Author Profile Icon Dan Borges
Dan Borges
Arrow right icon
View More author details
Toc

Clearing the Field

Ending an operation is arguably just as important as starting an operation. Planning several end conditions early on with playbooks can help your team achieve their goals throughout the conflict. From the offensive perspective, after an operation, you will want to clean up the environment to ensure you are not caught or attributed to any breaches. In the event you've been detected, the offensive operations will need to save as much of the operations as they can, either pivoting deeper internally or by burning down their access and backing out of the target environment. If you are a defender, making sure that you've successfully scoped the intrusion is paramount. This is a daunting task, meaning the attacker has been properly identified with all assets they've compromised, the root cause of the compromise has been identified, and any evidence the defenders have collected has been exploited. After identifying and containing the attacker, the defense...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €18.99/month. Cancel anytime