Posts

Showing posts with the label Threat Detection

Data Analysis Skills for Security Analysts: What CySA+ Expects

Security operations is a data problem before it is a technical one. An analyst who can query, aggregate and reason about distributions finds things a signature never will, and the skills involved are closer to basic data analysis than to data science. This is what those skills look like in practice and where they appear on the CySA+ objectives. Baselining Almost every useful detection is a deviation from normal, which means normal has to be established first. What does this host usually connect to, how much data does this user usually move, when does this service account usually run, how many failed logins does this application usually see on a Tuesday. Two mistakes recur. Baselining over too short a window captures an atypical period and produces alerts every month-end. Baselining a whole population instead of a role produces a "normal" that fits nobody — a developer's workstation and a receptionist's behave nothing alike, and averaging them describes neither. B...

Windows Remote Execution: The Techniques Attackers Use to Move Laterally

Lateral movement in a Windows environment rarely involves an exploit. An attacker with valid credentials uses the same remote execution mechanisms administrators use, which is why it looks like legitimate activity and why detection has to be based on pattern rather than on the mechanism itself. How the credentials are obtained is covered under pass-the-hash ; this is what is done with them. Service creation The oldest and most reliable. Connect to the target's administrative share, copy an executable, create a service pointing at it remotely, start the service, then delete it afterwards. The service runs as SYSTEM. It is noisy by modern standards, and it still works everywhere, which is why it remains common. The detection is straightforward: event 7045 records a service installation, and a service created remotely with a random or short name, running from a temporary path, and removed minutes later is not an administrator doing maintenance. WMI Windows Management Instrume...

Reverse Shells and Living Off the Land: Why Netcat Still Matters

Netcat reads and writes arbitrary TCP and UDP connections. That is all it does, and it is why the same tool appears in a network engineer's troubleshooting kit and in an attacker's toolkit — the general-purpose nature is the point. The concept worth extracting from it is the difference between a bind shell and a reverse shell, which explains most of how command channels work. Bind shells and reverse shells A bind shell listens on the compromised host and waits for the attacker to connect to it. Conceptually simple, and almost always blocked in practice, because inbound connections to an arbitrary port on an internal host are exactly what a perimeter firewall exists to prevent. Address translation makes it worse for the attacker, since the host may not be addressable at all. A reverse shell inverts it: the compromised host connects outward to the attacker, who is listening. The firewall sees an outbound connection from an internal host, which is the traffic it is configur...

Adversary Emulation with MITRE ATT&CK: Testing Detections You Assume Work

Most organizations do not know which attacks they would actually detect. Tools are deployed, rules are enabled, dashboards look healthy — and nobody has confirmed that a given technique produces an alert. Adversary emulation answers that question by executing known techniques deliberately and checking whether anything fired. The gap it exposes Detection coverage is usually assumed rather than measured. A vendor claims a product detects credential dumping, so the technique is marked covered. In practice the rule may be disabled by default, the relevant log source may not be forwarded, an exclusion added a year ago may suppress it, or the alert may fire into a queue nobody reads. Every one of those failures is invisible until a real incident, which is the worst possible time to discover it. Running the technique yourself turns an assumption into a measured result: either the alert appeared or it did not. How ATT&CK structures the problem MITRE ATT&CK catalogs observed adve...

Threat Hunting: Working From a Hypothesis Instead of an Alert

Alert triage is reactive: a tool decides something is suspicious and a human investigates. Threat hunting is the opposite — a human forms a hypothesis about what an attacker might be doing, then goes looking for evidence, whether or not anything fired. It exists because detection coverage is always incomplete, and the gaps are exactly where a competent attacker lives. Where hypotheses come from A hunt without a hypothesis is browsing logs, which produces nothing reliably. Good hypotheses have three common sources. Threat intelligence. A report describes a technique used against organizations like yours. The hypothesis writes itself: are we seeing this behaviour, and would we have detected it if we were? This is the operational level of intelligence doing its job, as described under the intelligence cycle . Known detection gaps. Control validation shows which techniques produce no alert — the outcome of the testing under adversary emulation . Anything in the "telemetry...

The Cyber Kill Chain: Seven Stages and Where to Break It

The Cyber Kill Chain models an intrusion as a sequence of stages an attacker must complete in order. Its value is the framing rather than the list: the attacker has to succeed at every stage, and the defender only has to break one. That asymmetry runs the other way from the usual "attacker only needs to be right once" and it is the point of the model. The seven stages, and what breaks each 1. Reconnaissance. Gathering information about the target — staff names and email formats from public sources, exposed services from scan indexes, technology from job postings. Almost entirely outside your visibility. The counter is reducing what you publish and monitoring what is exposed, as covered under OSINT collection . 2. Weaponization. Building the deliverable — pairing an exploit or payload with a document, a link, or an installer. This happens entirely on the attacker's side, so there is nothing to detect and nothing to block. It is the stage with no defensive action, wh...

Covert Channels and Data Exfiltration Detection for CySA+

An attacker who has data and needs it out has a narrow problem: every obvious path is watched. Large uploads trip data loss prevention, unfamiliar destinations trip the proxy, and archive files leaving at 3 a.m. get looked at. So the data goes out through something that was never intended to carry it. That is a covert channel, and recognizing them is a core CySA+ skill. Storage Channels and Timing Channels The formal distinction is worth knowing because it appears as a definitional question. A storage channel hides data in a field that legitimately exists but is not being used as intended — an unused header field, a hostname label, padding bytes, a file's metadata. The data is present in the traffic; you simply have to know where to look. A timing channel encodes information in when something happens rather than what it contains. Delays between requests, packet spacing, the presence or absence of a beacon in a given interval. Nothing in any individual packet is anomal...

Wireless Intrusion Detection: Finding Rogue APs and Deauth Attacks

Wireless intrusion detection monitors the radio environment for threats that no wired sensor can see. Most enterprise wireless platforms include it, most organizations leave it unconfigured, and the detections it offers are among the cheapest available — the sensors are the access points you already own. What it detects Rogue access points. An unauthorized access point connected to your wired network — usually a consumer device someone plugged in for convenience. It bypasses every control on the wired side and advertises a way in from the car park. Detection combines a radio observation with a check of whether the device is actually on your network, because an access point belonging to the business next door is a neighbour rather than a rogue, and systems that cannot tell the difference generate alerts nobody reads. Evil twins. An access point advertising your network name from a radio identifier that is not yours. This is the one worth alerting on immediately, because...

UEBA: Risk Scoring Users and Entities Instead of Alerting on Events

Traditional detection asks whether an event matches a known-bad pattern. Behaviour analytics asks whether an event is unusual for this particular user or system , and accumulates that judgement into a risk score. It catches things no signature describes — an insider using legitimate access improperly, or an attacker operating entirely with valid credentials. A single signal from this family is covered under impossible travel ; this is the wider model it belongs to. Baselines, per entity The foundation, and where most of the work is. The system observes normal behaviour over weeks and builds a profile: when this person works, from where, on which devices, which applications and systems they touch, how much data they typically move, and which of their peers behave similarly. Entities other than users get the same treatment — servers, service accounts, and endpoints all have characteristic behaviour, and a service account is in some ways the better subject, because its beh...

Command and Control Architectures: Centralized, P2P, DGA and Fast Flux

Malware that cannot reach its operator is nearly harmless. Everything an attacker does after initial access — issuing commands, staging tools, retrieving data — requires a channel back. Command and control is therefore both the adversary's dependency and the defender's best opportunity. The architectures below exist because defenders keep taking C2 infrastructure away, and each design trades something to be harder to remove. Centralized Every infected host connects to one server or a small set of them. Simple to build, simple to operate, and simple to destroy — block the address or seize the server and the entire population goes silent. For defenders this is the easy case. A single destination stands out in flow data, and it is exactly the sort of indicator that reputation feeds distribute effectively. Tiered and Redirector-Based Infected hosts talk to disposable intermediaries — compromised websites, cloud functions, rented servers — which rel...

XDR vs EDR vs SIEM: What Extended Detection and Response Actually Adds

Extended Detection and Response correlates telemetry across endpoints, network, email, identity, and cloud in a single platform, and can act on what it finds. The category exists because attacks do not stay in one domain, while the tools built to catch them historically did. For CySA+ and Security+ the exam interest is in telling XDR apart from EDR, SIEM, and SOAR , which is harder than the marketing suggests. What EDR sees and misses An EDR agent has deep visibility into one host: processes, file changes, registry, memory, local network connections. That depth catches a great deal, but it ends at the edge of the machine. Consider a realistic chain. A phishing message arrives, a user opens the attachment, a process spawns and beacons to an external address, a credential is stolen and used to sign in from an unusual location, and a cloud storage bucket is accessed. EDR sees the process and the beacon. It does not see the message, the sign-in, or the cloud access. Each of the other ...

Watering Hole Attacks: Compromising the Site Your Targets Already Trust

A watering hole attack compromises a website the intended targets already visit, rather than approaching them directly. The victims browse normally to a site they trust, and the site delivers the attack. It is patient, indirect, and it defeats the controls organizations invest in most. Why an attacker chooses it Phishing requires the target to act on an unsolicited message, and organizations have spent years training people not to and filtering what arrives. A watering hole requires nothing unusual from the victim at all — they do their job. It also reaches people who are hard to phish. Someone cautious about links and attachments still visits their industry association's site, their regulator's guidance pages, or the supplier portal they use daily. And it self-selects. Compromising a niche site — a professional body, a sector news publication, a specialist software vendor — reaches exactly the population the attacker wants, without touching anyone else. That narr...

Flow Collectors: Turning Network Metadata Into Detection

A flow collector receives, stores and analyses flow records exported by routers, switches and dedicated sensors. Each record summarizes one conversation — who talked to whom, on which ports, using which protocol, for how long, and how many bytes and packets moved. No payload, just the shape of the traffic. Flow records versus packet capture Full packet capture records everything and answers any question you can think to ask. It also consumes storage at the rate of your network, which means retention measured in hours or days on a busy link, and it cannot see inside encrypted sessions anyway. Flow data is perhaps a thousandth of the volume, so months of history is practical, and it is unaffected by encryption because it never looked at content. What it cannot tell you is what was transferred. The working arrangement is both: flow data for broad, long-retention visibility, and targeted packet capture on specific segments or triggered by a flow-based alert. Flow tells you where...