Top Categories

Spotlight

todayMay 7, 2024

Cyber Security Hubbl3

Survivorship Bias and How Red Teams Can Handle It

Reporting is, by nature, only the threat actors that have been caught. What about all the ones that didn’t get caught? There is no way to examine that and It comes down to the fact that we don’t know what they did and therein lies the problem for threat emulation.


Empire Operations: Tactics (APT28) – Cancelled

July 1, 2023my_locationDefcon Las Vegas

Background
share close
Details
Date July 1, 2023 H 08:00
End July 1, 2023 H 17:00
Location Defcon Las Vegas
Address Caesars Forum, Las Vegas
Add to Google Calendar

Click here to add this event to your google calendar

About the event

Training Description

Empire Operations: Tactics (APT28) is an intermediate-level course that focuses on executing Advanced Persistent Threat (APT) Tactics, Techniques, and Procedures (TTPs) using Empire. In this hands-on course, students will evaluate the 2021-2022 exploitation campaign from Fancy Bear (APT28) using MSHTML RCE (CVE-2021-40444) in macro-enabled docs, OneDrive C2 communications, and C# payloads. Next, attendees will learn the individual components of Empire and how to apply them to execute a red team operation. Key topics that will be taught are building C2 infrastructure, deploying customized payloads in C# and PowerShell, and creating tailored scripts for engagements. Finally, the Empire TTPs learned throughout the course will be tested on a comprehensive range using an emulation plan provided on APT 28.

Course Overview

Day 1

  • Introduction and Background
  • Fancy Bear (APT 28)
  • Empire Basics
  • Attack Infrastructure
  • Malicious Macros
  • C# and DLL Exploitation

Day 2

  • Privilege Escalation
  • Lateral Movement
  • Exfiltration
  • Student Topics
  • Debrief
  • Conclusion

Student Skill Level

Intermediate – Basic understanding of Empire or another C2 framework is preferred.

Students Will Be Provided With

  • 30-day access to the course labs on ImmersiveLabs
  • Course Swag and Coin

What Should Students Bring To Training?

  • Laptop with 8GB of RAM
  • Virtualization Software (VMware, VirtualBox, etc)
  • Up-to-date Kali Linux Virtual Machine
  • Modern Web Browser (Chrome, Firefox, etc)
  • Microsoft Office (any version) or OpenOffice
Rate it