Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Adversarial Tradecraft in Cybersecurity

You're reading from   Adversarial Tradecraft in Cybersecurity Offense versus defense in real-time computer conflict

Arrow left icon
Product type Paperback
Published in Jun 2021
Publisher Packt
ISBN-13 9781801076203
Length 246 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Dan Borges Dan Borges
Author Profile Icon Dan Borges
Dan Borges
Arrow right icon
View More author details
Toc

Summary

In conclusion, there are many ways for attackers to blend into the existing environment. Doing so will help them stay on the victim host longer and potentially avoid detection. We saw how attackers can strengthen their positions by setting up persistence and decoupling their operational implants. We also explored many ways for attackers to obfuscate their C2 protocols, by abusing legitimate protocols. There are also still many techniques available to defenders to highlight abnormal traffic patterns, drill down on infected hosts, and root out persistence items. Further, defenders can add many utilities and sensors to a host to enrich their various logs and understanding of the executables on the system. Finally, the defender can set juicy traps and lure the attacker out of their hidden positions. While there are many variations on these honey techniques, they ultimately rely on defenders deceiving the attacker into thinking the honey infrastructure is a legitimate target.

...
lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime