"APT Attack Techniques in Azure Cloud" by Lina Lau, BSides Canberra 2023

  Рет қаралды 2,119

BSides Canberra

BSides Canberra

5 ай бұрын

Difficult to detect and pervasive in nature, cloud attack techniques attract the likes of APT groups like Nobellium who have increased their focus on abusing identity federation. Techniques like Golden SAML and AD FS skeleton keys provide threat actors the double-edged sword of combining both lateral movement and privilege escalation into a single technique - with the added benefit of leaving little trace in the cloud logs for defenders.
For a long time, compromise and detection has focused primarily on on-premises techniques, but the ecosystem has shifted, and the cloud is the new frontier. As most organizations utilise cloud services in one way or another - it’s only a matter of time before we see commodity threat groups and other nation states abusing these techniques. This talk aims to break down APT techniques in the cloud like Golden SAML and AD FS skeleton keys to demonstrate the wide range of possibilities of cloud compromise, and to highlight the future of cloud attacks and the untapped research potential yet to be uncovered.
Lina Lau (@inversecos)
Lina is the Founder of XINTRA, a platform providing advanced cybersecurity training focused on APT techniques and detections. She has an extensive background in incident response, where she was formerly the Principal IR Consultant at Secureworks APJ and the AAPAC Incident Response lead for Accenture ANZ. She has worked in Incident Response for multiple years leading complex international cases covering sectors such as national defence, banking, energy, and manufacturing.
Lina is also a Black Hat trainer, SANS advisory board member and has presented at several international conferences and authored a book on cybersecurity. She currently holds the following certifications: GXPN, GASF, GREM, GCFA and OSCP.

Пікірлер
Keynote | Hacking the Cloud Like an APT
42:02
SANS Offensive Operations
Рет қаралды 7 М.
Haha😂 Power💪 #trending #funny #viral #shorts
00:18
Reaction Station TV
Рет қаралды 16 МЛН
Must-have gadget for every toilet! 🤩 #gadget
00:27
GiGaZoom
Рет қаралды 12 МЛН
"Scudo Allocator exploitation" - Zac Ecob, BSides Canberra 2023
43:48
Why I Quit the Scrum Alliance
7:58
The Passionate Programmer
Рет қаралды 10 М.
Unmasking the Iranian APT COBALT MIRAGE
30:59
SANS Digital Forensics and Incident Response
Рет қаралды 6 М.
I Left The U.S. For Thailand - Look Inside My $544/Month Apartment
8:39
Lina Lau
9:29
Dark Reading
Рет қаралды 1 М.
reading classic books to convince people I'm smart
26:09
acollieralso
Рет қаралды 26 М.
2014 Three Minute Thesis winning presentation by Emily Johnston
3:19
University of South Australia
Рет қаралды 5 МЛН
Мой инст: denkiselef. Как забрать телефон через экран.
0:54
ОБСЛУЖИЛИ САМЫЙ ГРЯЗНЫЙ ПК
1:00
VA-PC
Рет қаралды 864 М.
Main filter..
0:15
CikoYt
Рет қаралды 15 МЛН