Black Hills Information Security 09月29日
紫队企业侦察:提升安全态势
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文探讨了紫队企业侦察方法,旨在提升网络意识与整体安全态势,通过分析攻击者可能获取的信息,帮助组织预防威胁。







Do you know what your attackers know?



There’s a good chance you know, but you might not be aware of just how much information can be found historically and in real-time about your business operations and organization.



Join Jordan Drysdale and Kent Ickler as they discuss and demonstrate Purple Team Enterprise Reconnaissance methods that increase operational network awareness and overall security posture.



Slides for this webcast can be found here: https://www.blackhillsinfosec.com/wp-content/uploads/2020/09/SLIDES_EnterpriseReconForPurpleTeams.pdf



00:00 – Intro



00:42 – Executive Problem Statement



02:25 – Recon You Say?



06:11 – Your Internal Friends… Sometimes



09:01 – What Does Purple Team Do, Exactly?



10:13 – There Are A Ton Of Sources Out Here



49:55 – And Now For Some Crappy Code



Learn how to monitor cloud services for your organizations’ data being dumped on the web, account compromises, and source code disclosure.



Use external services to keep an eye on your external landscape to alert on unexpected changes.



See configurations of operational awareness uncover potential attacker’s methodology and infrastructure to provide you an upper-hand in stopping threats before they escalate.



See how an attacker utilizes common internet sources to gather intelligence about your technology stack, your perimeter security, your wireless networks, and plan attacks against your organization.



Know what your attacker knows.




















Want to learn more mad skills from the person who wrote this blog?



Check out these classes from Jordan and Kent:




Defending the Enterprise



Assumed Compromise – A Methodology with Detections and Microsoft Sentinel

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

紫队 企业侦察 网络安全 威胁预防
相关文章