65% of breaches could've been prevented according to this research by Niels Provos if only Hardware second factors, Egress control and Positive execution control would've been in place. I couldn't agree more when he says, "most companies don’t realize they need this protection" on #egress filtering.
Number of times I've had to explain outbound connections originating from within a network to DevOps, SecOps alike 🤯
https://securityblueprints.io/posts/three-security-invariants-ciso-challenge/
Remote
Dhruv AHUJA
@new23d@infosec.exchange
Making network egress filtering effective, reliable and usable.
Founder & Chief Engineer at @ChaserSystems@infosec.exchange
0 Followers
0 Following
5 Posts
Joined November 02, 2022
blog:
Open post
Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1].
"Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance"
They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network.
While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security.
[1] https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations/profile-gru-cyber-and-hybrid-threat-operations
[2] https://web-assets.esetstatic.com/wls/2016/10/eset-sednit-part-2.pdf
0
0
0
0
Open post
RE: https://infosec.exchange/@ChaserSystems/117003455836858257
This isn't a reason to be complacent. We're working on an Agentic Defence Assurance and Product Integrity Testing (ADAPT) harness to continually challenge our assumptions and discover new evasions. More to be released in a few weeks on that.
Outbound Traffic Inspection (OTF) / Egress Filtering is an extremely effective post-compromise defence with asymmetric ROI.
We also demo in-process resolver monkey-patching, btw. Because that doesn't need write access to files /etc or root.
Open quoted post
Open quoted post
Quoting
Happy to reassure our users that the #egress evasion TTPs used by the Agent in the OpenAI and Hugging Face incident have long been mitigated in #DiscrimiNAT OTF (outbound traffic filtering). In fact, in our demos, we show these attacks being caught. #2 is SNI spoofing, btw.
https://huggingface.co/blog/agent-intrusion-technical-timeline

0
0
0
0
Open post
Does anybody know an illustrator/graphics designer who can tweak and convert AI-generated two sticker ideas I have to print-ready? Theme is computer circuits, LCD screens and a bit retro Windows 95 dialog boxes. Need this done asap, really. Preferably Cambridge/London based.
0
1
0
0
Open post