This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Comment prévenir des attaques de type ransomware avec une bonne gestion de vulnérabilités Voyez comment Contileak a permis de mieux comprendre le modus Operandi des groupes criminels tel que Conti.

Download resources

About this session

Julien Hamel, senior security engineer at Tenable, walks through the Conti leaks: the internal chats and operating manual that a disgruntled member of the ransomware group published in early 2022, and what they reveal about how a criminal 'company' with HR, R&D and a customer-support line actually breaks into networks. Using a machine-translated copy of the Russian playbook, he follows the sequence step by step: revenue research on ZoomInfo, initial phishing compromise, share hunting with PowerShell, Kerberoasting and Mimikatz, DCSync and DCShadow, Zerologon, PrintNightmare and MS17-010, SMB brute force with seasonal passwords, AnyDesk persistence, shadow-copy deletion, exfiltration to Mega and finally encryption. The lesson for defenders is that Conti relies on known vulnerabilities, and that three quarters of those in the playbook are privilege-escalation flaws rated 'high' rather than 'critical', exactly the ones teams postpone. He closes with Tenable's attack-surface and Active Directory products, a partly failed live demo of DCSync detection and an AdminSDHolder persistence trick, and a short Q&A.

Les fuites de conversations internes entre les membres du groupe Conti offrent un aperçu unique de ses méthodes de travail internes et fournissent des informations précieuses, notamment des détails sur plus de 30 vulnérabilités utilisées par le groupe et ses affiliés, ainsi que des détails sur ses processus après avoir infiltré un réseau, comme la façon dont il cible Active Directory.

Key takeaways

  • Treat 'high' privilege-escalation CVEs as urgently as 'critical' RCEs: three quarters of the vulnerabilities in the Conti playbook are local privilege escalations, not remote code execution.
  • Patch the flaws Conti scans for first, Zerologon, PrintNightmare and MS17-010, plus exposed Fortinet, Exchange, VMware vSphere and vCenter, since the group tries them in sequence.
  • Harden Active Directory against Kerberoasting, DCSync, DCShadow and AdminSDHolder abuse, and monitor the replication channel for fake domain controllers.
  • Enforce password length and rotation policies that defeat seasonal and 'month plus year' patterns, and audit GPOs for cleartext passwords.
  • Watch for the late-stage signals, volume shadow copy deletion, AnyDesk installs and sync to Mega, which precede encryption by hours.

Speakers

Julien Hamel
Julien Hamel
Senior Sales Engineer · Tenable
For Julien , Everything has started with this big brown box which was father’s Apple II. For a reason that he never totally understand, computers always fascinating him even as a Young child. This fascination with the combination of challenge has… Read moreRead less

For Julien , Everything has started with this big brown box which was father’s Apple II. For a reason that he never totally understand, computers always fascinating him even as a Young child. This fascination with the combination of challenge has set the path of his career. Julien has been in the IT Security field for over 15 years, he work extensively with many companies in different fields: Finance and Insurance, Communication, Energy, Education, Retail, Wood and paper, Food industry, Police department, Transportation, and more. His technical security background is very broad: Network Security, Web applications security, Malware, Wireless security, Open-source intelligence, Pentesting and Incident response.

Resources

Tags

More from GoSec 2022

Also from Julien Hamel

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.