♫musicjinni

BSides DC 2019 - Sun - T2 - Offensive PCAP

video thumbnail
When writing malware, oftentimes we need a bit more flexibility (i.e. sneakiness) than the victim's "normal" network stack provides us. Enter libpcap. Aside from powering tcpdump, it enables us to send and receive all sorts of strange (and hopefully invisible) network traffic we can use on the offensive side of things.

In this talk we'll first take a broad look at what libpcap is and what it can do for us, then we'll explore how to use it to do devious things like circumvent host-based firewalls, grab interesting info off the wire, ask system processes call us back with shells, and keep pesky EDR connections from happening. Source code for all of the techniques discussed in the talk will be made available.

Stuart McMurray (Red Team Operator and Developer at IronNet)
Stuart is a Red Teamer at IronNet, where he focuses on tool development, Unix, and general Swiss Army knifery. He's been on the offensive side of public and private sector security for six years, during which time he's been an operator and trainer and developed a small arsenal of public and private offensive tools. Stuart's been a speaker at BSides and CarolinaCon and has red teamed for Quantum Dawn and the Collegiate Cyber Defense Competition.

BSides DC 2019 - Welcome

BSides DC 2019 - No IOUs with IOT

BSides DC 2019 - CryptKids Keynote

BSides DC 2019 - Courage from a Zero Day Inside

BSides DC 2019 - Offensive PCAP

BSides DC 2019 - 0-day Research Disassembled

BSides DC 2019 - Malware Behavior Catalog

BSides DC 2019 - Sun - T2 - No IOUs with IOT

BSides DC 2019 - Sun - T2 - Offensive PCAP

BSides DC 2019 - Sat-T3 The APT @home - when the attacker knows your mother's maiden name

BSides DC 2019 - Sat-T3 Malware Behavior Catalog

BSides DC 2019 - Overcoming Workforce Retention & Recruitment Challenges in Cybersecurity

BSides DC 2019 - Keeping CTI on Track: An Easier Way to Map to MITRE ATT&CK

BSides DC 2019 - Digital Canaries in Coal Mines: Detecting Adversarial Enumeration with DNS & AD

BSides DC 2019 - Sat-T2 - Bringing IACD (Integrated Adaptive Cyber Defence) to the

BSides DC 2019 - Mind the Gap - Managing Insecurity in Enterprise IoT

BSides DC 2019 - Sun - T1 - What did the SIEM See?

BSides DC 2019 - Sun - T3 - Breaking Through the Boundaries of Cyber Security Job Search Challenges

BSides DC 2019 - JARVIS for Code? Meaningful AI Research for Software Reverse Engineering

BSides DC 2019 - Insights for secure API usage in conjunction w/ security automation & orchestration

BSides DC 2019 - Sun - T1 - 0-day Research Disassembled

BSides DC 2019 - The APT @home - when the attacker knows your mother's maiden name

BSides DC 2019 - Welcome and Keynote

BSides DC 2019 Sat-T2 - The journey begins: Preparing for Offensive Security

BSides DC 2019 - Sat-T3 Social Media OSINT Without the Indigestion

BSides DC 2019 - Breaking Through the Boundaries of Cyber Security Job Search Challenges

BSides DC 2019 - What did the SIEM See?

BSides DC 2019 - How Not to Cheat on Your Wife

BSides DC 2019 - Bringing IACD (Integrated Adaptive Cyber Defence) to the Financial Sector

BSides DC 2019 - Are your Network Devices Good or Evil? Introducing CHOX

Disclaimer DMCA