> Consistent with a nation-state cyber-espionage effort, the attacker primarily sought information related to certain government customers. If this was the primary objective of the attackers, why is it buried in the seventh paragraph of FireEye's blogpost, after a lengthy discussion of the attackers targeting -- though apparently not primarily targeting -- FireEye's internal tooling?
FireEye Shares Details of Recent Cyber Attack
111–120 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#112From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?
Re: FireEye Shares Details of Recent Cyber Attack
#113> Consistent with a nation-state cyber-espionage effort, the attacker primarily sought information related to certain government customers. If this was the primary objective of the attackers, why is it buried in the seventh paragraph of FireEye's blogpost, after a lengthy discussion of the attackers targeting -- though apparently not primarily targeting -- FireEye's internal tooling?
Because the tooling getting out impacts everyone and thus warrants a public post. Some government information being stolen only impact those customers and only warrants notifying those customers.
Re: FireEye Shares Details of Recent Cyber Attack
#114As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.
Re: FireEye Shares Details of Recent Cyber Attack
#115As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
Whats your opinion of open source tools and distributions of them (like Kali) in this space and the tradeoff between open sourcing your red team tools vs reimplementing tools that are already out there.
If you are doing penetration testing and basic security work, there is no value in having private tools. It becomes important in red team work because you are trying to emulate a real attacker that has access to non-public tools.
Re: FireEye Shares Details of Recent Cyber Attack
#116As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
Re: FireEye Shares Details of Recent Cyber Attack
#117As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.
^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Curious if this is feasible.
Re: FireEye Shares Details of Recent Cyber Attack
#118Earlier quoted context omitted.
If I understand your comment correctly - even though the fingerprints are published, the attacker can still reverse eng the implementation from the tools and bypass antivirus systems at least in the near future?
Also fingerprints will only stop the lowest level of attackers. You can easily change binaries in a way the fingerprint is changed but the functionality remains the same. Reorder functions, add some garbage data, etc.
I guess one benefit might be to push the development of new detection techniques to detect the underlying implementation of these tools.
Re: FireEye Shares Details of Recent Cyber Attack
#119As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.
Re: FireEye Shares Details of Recent Cyber Attack
#120Earlier quoted context omitted.
Interest != Used or Stolen Client Data.
"no evidence" != "didn't happen", either, tho, especially if the attackers really were that capable as they claim,