#egress

4 posts· Last used 12d

Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1]. "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance" They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network. While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security. [1] https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations/profile-gru-cyber-and-hybrid-threat-operations [2] https://web-assets.esetstatic.com/wls/2016/10/eset-sednit-part-2.pdf
0
0
0
0
65% of breaches could've been prevented according to this research by Niels Provos if only Hardware second factors, Egress control and Positive execution control would've been in place. I couldn't agree more when he says, "most companies don’t realize they need this protection" on #egress filtering. Number of times I've had to explain outbound connections originating from within a network to DevOps, SecOps alike 🤯 https://securityblueprints.io/posts/three-security-invariants-ciso-challenge/
0
0
0
0
You've seen all posts