Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Adversarial Tradecraft in Cybersecurity

You're reading from   Adversarial Tradecraft in Cybersecurity Offense versus defense in real-time computer conflict

Arrow left icon
Product type Paperback
Published in Jun 2021
Publisher Packt
ISBN-13 9781801076203
Length 246 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Dan Borges Dan Borges
Author Profile Icon Dan Borges
Dan Borges
Arrow right icon
View More author details
Toc

Defensive perspective

In the last section, we saw a number of techniques for blending both network traffic and on-host persistence items into the target environment. In this section, we examine some of these techniques more closely, looking at how the covert channels differ from the normal protocols.

We will also look at how to audit and detect various persistence items and rogue executables. The crux of this section is knowing what normal looks like and how to spot an attacker as abnormal in your normal environment. We will end this section by baiting an attacker into revealing themselves with several techniques and traps.

C2 detection

Let's start by looking at ways to detect anomalous traffic. If you can detect malicious traffic on your network, then this is often a strong indicator of which hosts are infected on your network. We can drill down on the infected hosts by first detecting them calling out of the network, then finding which process on a particular host...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €18.99/month. Cancel anytime