29
Hack the SIEM and Win the War

and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

Page 1: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Hack the SIEM and Win the War

Page 2: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Many Thanks to the Following...

All the people that taught me this stuff

Page 3: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Who the hell is this guy?

Page 4: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 5: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

In The Beginning...

Page 6: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 7: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

And Now

Page 8: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 9: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

And The Hits Keep On Coming

Page 10: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 11: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

What is a SIEM?

I don’t know either but I’ll sell you 2 of them

Page 12: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 13: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Why is it Weak?

Have you ever tried to patch a SIEM?

Page 14: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 15: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Because this is your consultant

Page 16: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 17: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

And this is their company slogan

Page 18: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 19: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee
Page 20: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Why Target It?

Page 21: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Because it has its hands in everything

Page 22: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Seriously, how many servers does it take to make a SIEM?

Page 23: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Now let’s abuse it

Page 24: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

The Attack

Recon Exploit Collect

Page 25: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Recon

Check the Vendor Site

Under the customer section you will have all the targets you ever need

Documentation

You need the tech specs, specifically the API ports.

Check the Forums

Super strict member policy

Go to a Conference

Because we all know hotel wireless is frickin locked down.

Sales Engineers

You can spear phish or find them at a bar, it all amounts to the same thing.

Get a Free Version

Maybe...but you have to ask nicely

Page 26: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Say What????

Page 27: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

Exploit / Collect

Cred Reuse

This is always a thing

Default Creds

Cause Admins are lazy

Um….Lots of Stuff

Seriously, a metric F*** ton

API

CURL, CURL, CURL

Interface

Nothing to see here, just another user...

But Do You Need To?

Probably Not

Page 28: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

DEDEMO

Page 29: and Win the War Hack the SIEM - Immunity Inc...Alien Vault ZBlackStratus (NetForensics)l EventTracker Gestalt ALERTLOGIC tenable CLICK RSA n Trustwave (Intellitactics) a NetlQ V) McAfee

THANKS!