An inside look at NSA tactics, techniques and procedures from China's lens
1–10 of 76 posts
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#2Re: An inside look at NSA tactics, techniques and procedures from China's lens
#3Re: An inside look at NSA tactics, techniques and procedures from China's lens
#4Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays.
> Two zero-days were used to breach any company with SunOS-exposed systems in neighbouring countries to China
SunOS? Wonder if it's because it's genuinely used still quite a bit or they simply had zero-days for it since many of those are old and unpatched?
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#5[flagged]
Sure, we all have the freedom of speech here. Will you have freedom after speech though, I don't know? It depends on your particular situation ;-)
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#6I assume it's a jungle out there, so teams need to protect themselves 24/7/365 and I'm surprised to find no activities in holidays.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#7[flagged]
> can I comment freely here Sure, we all have the freedom of speech here. Will you have freedom after speech though, I don't know? It depends on your particular situation ;-)
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#8Re: An inside look at NSA tactics, techniques and procedures from China's lens
#9the traffic redirection is interesting in that i would be curious if they rate limited it or used on device selectors in their implant to redirect traffic. the trade off between memory caching packets to sort on selectors vs.stealthy throughput would have been a fun design meeting.
hunting these kinds of actors would be supremely fun. the main thing that protects them is few outside massive bureaucracies really care enough or find it economical, as the rewards are more in finding new zero day and not hunting state level threat actors. the exceptions who do (p0, citizenlab etc) are attached to massive orgs and dont really led themselves to privateering. amazing write up anyway.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#10It seems like the most efficient way of detecting NSA tools is a regular expression of two all caps dictionary words
Similarly, 0day ABNF to identify probable NSA front companies:
[optional-firstname] [optional-adjective]