Black Hills Information Security 09月29日
企业渗透:深入侦察与攻击技巧
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文探讨了针对企业进行战略攻击所需的侦察知识和员工信息。文章强调了深入侦察的重要性,并介绍了发现外部资源、定位目标员工及其社交媒体账户的方法,以及利用个人信息进行攻击的新技术。

Beau Bullock & Mike Felch//









Strategically targeting a corporation requires deep knowledge of their technologies and employees. Successfully compromising an organization can depend on the quality of reconnaissance a tester performs up front. Often times testers only resort to using publicly available tools which can overlook critical assets.



Download slides: http://www.activecountermeasures.com/presentations/



In this one-hour BHIS podcast (recorded live as a webcast on 4/16/19), we will begin by examining some commonly overlooked methods to discover external resources. Next, we will show how to discover employees of a target organization and quickly locate their social media accounts. Finally, we will strategically identify and weaponize personal information about the employees to target the organization directly using new attack techniques.



You will learn an external defense evasion method, a new process to gain credentialed access, and get a demo on a newly released tool — FireProx!



While the approach is designed to assist offensive security professionals, the webcast will be informative for technical and non-technical audiences; demonstrating the importance of security-awareness for everyone





















Psst If you liked this blog, we think you’d enjoy Beau’s class:




Breaching the Cloud 





Available live/virtual and on-demand!























Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

企业渗透 侦察技巧 攻击方法 安全意识 FireProx
相关文章