This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Continuous Reconnaissance Approaches to Reduce External Risk

Download resources

About this session

Yohan Trépanier Montpetit, chief product officer at Flare Systems, opens with Stanley McChrystal's realisation that a rigid army could not keep pace with decentralised insurgent cells, and draws the parallel to cybercriminals who share the same goals and starting points against every organisation. His subject is the first phase of the kill chain, reconnaissance, from the defender's side. Employees trying to be productive leak data without any malicious pattern: code and API keys on GitHub, public Trello boards indexed by Google, open Elasticsearch instances, misconfigured cloud buckets. Today recon happens at punctual events (red-team assessments, pen tests, an analyst's ad hoc searches), with limited coverage and no response plan, so a finding can trigger a costly, chaotic incident over a mere test database. He proposes continuous external reconnaissance as a cycle of discovery, collection, prioritisation and response, lists the sources to watch, and compares a homegrown stack of OSINT scripts, a database and alerting with commercial and managed options. The lesson from McChrystal is not to copy the enemy's structure but to see yourself as they see you, faster.

For over 10 years, Yohan has led technical teams to reach ambitious goals on innovative
projects. From building autonomous robotic vehicles to creating immersive, real-word guest experiences, he has led software teams on projects worldwide, from New York to Abu Dhabi. As Cofounder and Chief Product Officer at Flare Systems, he brings a broad technological background to develop innovative Cyber Threat Intelligence and Digital Risk Protection solutions to solve real-world business challenges.  

   
Intoday’s post-COVID rapidly changing IT landscape, organizations struggle to keep track of their evolving digital footprint. Employees and consultants use an increasing number of known and unknown public cloud platforms, especially with the growing work-from-home trends, and rely on collaborative websites to share information and data. Malicious actors use advanced techniques to monitor for human errors and quickly take action on potential vulnerabilities. External-based continuous reconnaissance approaches provide modern ways for organizations to understand their security posture in real-time and identify imminent threats and critical issues, all from an attacker’s perspective. In this talk, we go over tools, techniques and processes to leverage this
intelligence to better plan and execute defensive security strategies.  

Key takeaways

  • Treat reconnaissance as the phase to defend: reducing what an attacker can find before intrusion lowers the risk of every later kill-chain step.
  • Monitor beyond known infrastructure: code-sharing platforms, domain registrations for typosquatting, dark-web forums, leaked-credential dumps, anonymous upload sites, SaaS tools and cloud buckets.
  • Make it continuous, not punctual: an open database exposed the day after a red-team exercise can sit for a year before the next assessment finds it.
  • Define a response plan before you start looking: who evaluates the risk, who gets called, and what a domain or GitHub takedown looks like, so a finding does not become a costly false-positive incident.
  • If building in-house, script OSINT tools on a VPS, store results in a database to diff over time, and alert on anomalies; weigh that maintenance against a vendor or managed service.

Speakers

Yohan Trépanier Montpetit
Yohan Trépanier Montpetit
Chief Product Officer · Flare Systems

Resources

Tags

More from GoSec 2021

Also from Yohan Trépanier Montpetit

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.