Keynote | Hacking the Cloud Like an APT

  Рет қаралды 6,809

SANS Offensive Operations

SANS Offensive Operations

7 ай бұрын

On-premises to cloud lateral movement should be one of the top techniques in a red teamer’s arsenal. Difficult to detect and pervasive in nature, these techniques attract the likes of APT groups like Nobellium who have increased their focus on abusing identity federation. Techniques like Golden SAML and AD FS skeleton keys provide threat actors the double-edged sword of combining both lateral movement and privilege escalation into a single technique - with the added benefit of leaving little trace in the cloud logs for defenders.
For a long time, compromise and detection has focused primarily on on-premises techniques, but the ecosystem has shifted, and the cloud is the new frontier. As most organizations utilise cloud services in one way or another - it’s only a matter of time before we see commodity threat groups and other nation states abusing these techniques. This talk aims to break down cloud lateral movement techniques like Golden SAML and AD FS skeleton keys to demonstrate the wide range of possibilities of cloud compromise, and to highlight the future of cloud attacks and the untapped research potential yet to be uncovered.
SANS HackFest Summit 2023
Keynote | Hacking the Cloud Like an APT
Lina Lau, Founder of XINTRA, XINTRA
View upcoming Summits: www.sans.org/u/DuS

Пікірлер
Cloud Penetration Testing Workshop | SANS Pen Test HackFest Summit 2020
1:34:12
SANS Offensive Operations
Рет қаралды 12 М.
hacking every device on local networks - bettercap tutorial (Linux)
7:06
Nour's tech talk
Рет қаралды 912 М.
50 YouTubers Fight For $1,000,000
41:27
MrBeast
Рет қаралды 138 МЛН
Now THIS is entertainment! 🤣
00:59
America's Got Talent
Рет қаралды 16 МЛН
WHO LAUGHS LAST LAUGHS BEST 😎 #comedy
00:18
HaHaWhat
Рет қаралды 21 МЛН
Cat Corn?! 🙀 #cat #cute #catlover
00:54
Stocat
Рет қаралды 15 МЛН
What I Wish I Knew Before Pentesting AWS Environments
32:57
SANS Offensive Operations
Рет қаралды 4 М.
Enhancing Red Teaming with AI and ML
29:41
SANS Offensive Operations
Рет қаралды 734
"APT Attack Techniques in Azure Cloud" by Lina Lau, BSides Canberra 2023
23:15
Unmasking the Iranian APT COBALT MIRAGE
30:59
SANS Digital Forensics and Incident Response
Рет қаралды 6 М.
AI Security: Understanding the Threat Landscape
57:22
Robust Intelligence
Рет қаралды 1,1 М.
The Invisible Threat: AI-Powered Vishing Attacks and Defense Strategies
34:19
SANS Offensive Operations
Рет қаралды 718
What Does a Former Black Hat Hacker Carry Everyday?
27:05
Shawn Ryan Show
Рет қаралды 431 М.
Proxyjacking: The Latest Cybercriminal Side Hustle
31:19
SANS Offensive Operations
Рет қаралды 683
VulnerabilityGPT: Cybersecurity in the Age of LLM and AI
1:18:28
SANS Offensive Operations
Рет қаралды 20 М.
WATERPROOF RATED IP-69🌧️#oppo #oppof27pro#oppoindia
0:10
Fivestar Mobile
Рет қаралды 19 МЛН
Сколько реально стоит ПК Величайшего?
0:37
Samsung laughing on iPhone #techbyakram
0:12
Tech by Akram
Рет қаралды 432 М.