This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Enhancing Blue Teaming with Threat Emulation and Purple Teaming

Download resources

About this session

Chiheb Chebbi, a Microsoft Sentinel specialist and certified MITRE ATT&CK Defender at Intellisec Solutions, makes the case for threat-informed defence: static indicators of compromise sit at the bottom of David Bianco's Pyramid of Pain and are cheap for attackers to change, so detection should target tactics, techniques and procedures instead. He describes a purple-team programme built on the plan-do-check-act loop (pre-engagement, threat intelligence, adversary emulation, collaboration and reporting) and walks through a lab emulation of a Russian GRU group: a macro-laden Word document obfuscated with Evil Clippy for initial access, registry discovery and binary replacement for privilege escalation, Mimikatz and pass-the-hash for lateral movement, and exfiltration to cloud storage. The red team runs the chain with Prelude Operator agents, both teams log results in VECTR, and detection gaps become KQL rules shipped to Sentinel through a detection-as-code pipeline. He closes with limitations (thin documentation for advanced TTPs, custom tooling needed) and quick wins such as Sigma rules and a growing library of emulation plans, then takes questions on separating emulation noise from legitimate admin activity and on free tooling.

On a regular basis, modern enterprises confront cyber-attacks. Black hat hackers provide no sign that they want to quit. New tactics, techniques, and Procedures (TTP) emerge every day. Thus, organizations must make sure they are ready for a targeted attack. The presentation, through a balanced mix of theory and lab demonstrations, will start by providing a fair understanding of Threat Informed Defense. Later, attendees will explore how to leverage Purple Teaming and Adversary emulation exercises to enhance the effectiveness and maturity level of the defense teams of their organizations in addition to showing how to gain better visibility and monitoring coverage (The coverage is based on the MITRE ATT&CK framework). This talk will present how to plan and execute effective Adversary Emulations and Purple teaming assessments utilizing Open-source and publicly available tools and utilities. From the defensive side, the focus will be on Microsoft Sentinel SIEM/SOAR.

Key takeaways

  • Prioritise detections on adversary behaviour (TTPs) rather than hashes, IPs and domains, which attackers rotate at almost no cost.
  • Scope the threat groups to emulate from your sector and geography, and extract their TTPs from threat reports at least a month before the exercise.
  • Run purple teaming as a continuous plan-do-check-act loop, not a one-off assessment, with red and blue teams documenting in the same place (for example VECTR).
  • Use an agent-based emulation platform so the red team can pivot when a control blocks a step instead of stopping the exercise.
  • Treat detection rules as code: write them in KQL or Sigma, store them in Git and let a pipeline deploy them to the SIEM.

Speakers

Chiheb Chebbi
Chiheb Chebbi
Cybersecurity Consultant · Intellisec Solutions
Chiheb Chebbi is a Cybersecurity Consultant at Intellisec Solutions with proficient and thorough experience and a good understanding of information technology. He is specialized in proactive incident response using Microsoft Sentinel. He authored… Read moreRead less

Chiheb Chebbi is a Cybersecurity Consultant at Intellisec Solutions with proficient and thorough experience and a good understanding of information technology. He is specialized in proactive incident response using Microsoft Sentinel. He authored, contributed, and reviewed many information security books. He holds many professional certifications from Microsoft and MITRE (Certified MITRE Defender in 3 areas: Threat intelligence, ATT&CK SOC assessments, and Adversary Emulation). He is a versatile, bilingual professional and a community contributor. In 2021, he was awarded the Microsoft Most Valuable Professional (MVP) Award.

Resources

Tags

More from GoSec 2022

Also from Chiheb Chebbi

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.