威胁模拟专家的一天——揭秘进攻性网络安全.pdf

编号:991831 PDF 40页 5.38MB 下载积分:VIP专享
下载报告请您先登录!

1、John RodriguezCyb3rH0undCyber Dagger LLCA Day in the Life of a Threat Emulation SpecialistDemystifying Offensive SecurityWHO DATJohn Rodriguez cyb3rH0und15 years in ITBig 4 FirmFinance Telecoms Offensive OperationsUSAF Primarily FocusedAPT EmulationRed Team BuildingSecurity Solution TestingCapabilit

2、y DevelopmentTraining and EducationAgenda01Intro to Offensive SecurityIndustry,Specialty 02Offensive MethodologyThreat Emulation,Red Teaming,Psychology,Tactics 03A Typical Day in the RoleClients,Taskings,Planning,Training04Essential SkillsTechnical skills,Soft skills,Mentality05Career&GrowthBridging

3、 technical and soft skills WHY OFFENSIVE SECURITY?Prepare organizations to face the current threat landscapeThreat ActorsHacktivistCyber WarfareAmateur HackersMisconfigurationsComplianceWHY OFFENSIVE SECURITY?Stealthy Persistence Mechanisms:Injects malicious code into legitimate processes to evade d

4、etection.Uses rootkit capabilities to maintain long-term access.Sophisticated Command and Control(C2)Infrastructure:Cloud On-premCustom Tooling:Uroburos sophisticated rootkitKuzuar ImplantCarbonCustom CapabilitiesWHO CAN JOIN THE FIELD?NewcomersCareer PivotersAspiring Cyber ProfessionalsAnyone with

5、a passion to learn and serve 01When the path you walk always leads back to yourself,you never get anywhere-Master OogwwayIntro to Offensive SecurityWHAT IS THREAT EMULATION?IoTAerialEnterpriseHardwareTech StacksSpace SystemsWHAT IS THREAT EMULATION?Typically,a better return on investment for matured

6、 security programs.Do you need to validate defenses against a specific threat Salt Typhoon,APT 28,APT 29 Threat EmulationWHAT IS THREAT EMULATION?Penetration Testing-Identify,Validate,Reportsecurity vulnerabilitiesRed Teaming Stealthy Larger Scopes6-12 weeks or continuous02Never tell people how to d

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(威胁模拟专家的一天——揭秘进攻性网络安全.pdf)为本站 (可不可以) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠