Earlier quoted context omitted.
Because the tooling getting out impacts everyone and thus warrants a public post. Some government information being stolen only impact those customers and only warrants notifying those customers.
Information pertaining to government customers invariably impacts civilians under that governance (and potentially civilians outside of it).
FireEye Shares Details of Recent Cyber Attack
121–130 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#122As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
Re: FireEye Shares Details of Recent Cyber Attack
#123From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?
Re: FireEye Shares Details of Recent Cyber Attack
#124If only hacked companies were as good at defense as they claim to be at attribution.
You can build a case on the flimsiest of IOCs, and anyone who questions you gets smeared as a foreign agent or cutout, without a shred of evidence. Really, quite neat.
Re: FireEye Shares Details of Recent Cyber Attack
#125"They used a novel combination of techniques not witnessed by us or our partners in the past." This is the scary part. FireEye and the others have been studying and watching APTXX nation-state teams for many years. They should have some idea by now. It is entirely possible that a new team is out there.
If it's something novel indeed, the entire industry would like to know please.
Re: FireEye Shares Details of Recent Cyber Attack
#126Earlier quoted context omitted.
>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way
Airgaps protect against low to medium level attackers. Nation state tools for bypassing airgaps are a dime a dozen. One of the most common is interdiction of computers in shipping and installation of hardware implants.
Re: FireEye Shares Details of Recent Cyber Attack
#127Earlier quoted context omitted.
Also fingerprints will only stop the lowest level of attackers. You can easily change binaries in a way the fingerprint is changed but the functionality remains the same. Reorder functions, add some garbage data, etc.
That makes sense. So given that the attacker is technically sophisticated in this case, what are the tangible benefits of publishing the fingerprints? I guess one benefit might be to push the development of new detection techniques to detect the underlying implementation of these tools.
Re: FireEye Shares Details of Recent Cyber Attack
#128Earlier quoted context omitted.
> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.
Matthew in accounting should be given an ipad pro instead of a laptop or pc, with a glued in lightning cable that can only do power. ^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Cur…
0: https://www.amazon.com/REDDOTMOBILE-Detachable-Magnetic-Ligh...
Re: FireEye Shares Details of Recent Cyber Attack
#129As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
> Matthew in accounting that will open that invoice attachment so he can pay it. This is painfully accurate. A chain is really only as strong as its weakest link :/
Even better is that the company should have its own internal ordering system.
Re: FireEye Shares Details of Recent Cyber Attack
#130As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
Does Matthew in accounting need access to the same network as the engineering staff?