Stopping the Unseen, AI for High Confidence Low-risk Threat Response with Fortinet
Cyber threats are increasingly sophisticated, often evading traditional detection methods and remaining undetected until significant damage occurs. Fortinet’s presentation at Cloud Field Day highlighted how AI-driven insights from network and cloud intelligence significantly improve threat detection, enhance overall visibility, and enable faster, lower-risk responses for security teams. The core message emphasizes empowering security operators by providing high-fidelity insights that allow for efficient and safe remediation, ultimately minimizing attack surface and reducing organizational risk.
The presentation detailed how Fortinet’s solutions address the challenges of increasingly complex cloud environments with numerous ingress/egress points and ephemeral networks. They ingest a vast amount of signals from various sources, both Fortinet and third-party, then utilize advanced machine learning to correlate this data into high-confidence threat assessments. This composite risk view prioritizes threats and presents actionable information to security operators, even providing AI-powered assistance for investigation and remediation steps, thus reducing the burden of low-value tasks.
A live demonstration showcased how Fortinet’s AI-powered security solutions could uncover and prevent an attack. The scenario, presented by a Fortinet threat analyst, simulated a real-world attack leveraging a known vulnerability, demonstrating the system’s ability to detect the initial compromise, trace the attack’s escalation across cloud infrastructure, and pinpoint critical misconfigurations. The presentation concluded by emphasizing Fortinet’s commitment to innovation and leadership in threat intelligence, backed by a significant patent portfolio and a broad range of security solutions designed to assist organizations in maintaining security posture in dynamic cloud environments.
Presented by Aidan Walden, Global Director, Cloud Engineering & Architecture, Fortinet, and Julian Petersohn, Cloud Cyber Threat Analyst, Fortinet. Recorded live in Santa Clara, California on February 20, 2025 as part of Cloud Field Day 22. Watch the entire presentation at https://techfieldday.com/appearance/fortinet-presents-at-cloud-field-day-22/, https://techfieldday.com/event/cfd22/ or visit https://www.fortinet.com/ for more information.
Transcript
For, for this session. It's really continuation of the theme that I, I think we've been known for. It's, you know, really putting the, the security operator, um, and, um, understanding, um, what they're going through day in and day out in terms of being productive, having to deal with, you know, tons of, of threats on their dashboard every day.
And, you know, we we're trying as an organization to deliver a much better experience for the security operator, uh, to make their life much easier, uh, to help them address the right problems for the business to drive risk out of the business. And so that's how we came to today's title. We wanna stop the unseen, those unseen threats.
And, and unseen doesn't necessarily mean that, uh, they're just, it can't be seen. It just means that maybe there's some signal buried in a bunch of other signal. And finding that needle in the haystack is, uh, very difficult to do.
And we wanna make that simpler. And, and we do that by creating much, uh, higher fidelity and high confidence insights, um, so that when we respond to things that operator, that practitioner cannot, you know, can expect to do that with very low risk in the, in the actions that they're taking. We don't want to break things as we're trying to improve them.
And I'm joined by my teammates. Uh, Julian Peterson, uh, is, uh, our resident threat analyst. He has many CVEs to his credit.
Um, he's, he's very insightful from the attacker perspective, usually plays that role. Uh, Derek G***h is our, uh, DevOps architect in, in our cloud organization, or one of them very talented, can, uh, serves a, a multiple, uh, co, uh, competencies for our organization. Um, super expert on the security front.
Uh, and Gabe O'Brien is really responsible for the, the data that drives our ability to present, uh, the, uh, cloud, um, native application protection platform for to CNAP. Uh, you may have known this in the past as, as Lacework, and my responsibilities generally cover cloud engineering, uh, broadly at Fortinet. So I think we start with a problem statement.
And the problem statements are not unfamiliar to this group. You are all professionals. Um, but to baseline, we talk about constantly sophisticated threats, and maybe the threats are sophisticated.
Oftentimes they're, they're not sophisticated, um, or sophisticated threats. Start with zero, very simple attacks, like somebody's able to get in with some compromised credentials, and then they persist in my network for a very long time. Why do they persist in my network?
Uh, to do complicated advanced things and sophisticated things is because probably I have visibility gaps. I have lots of signal that's coming at me. I can't, I don't know what to do with it.
Um, I don't necessarily control all of the access points, uh, that come and go into my maybe flat network, uh, consistently. And maybe I just have blind spots where I've got shadow IT developing on my cloud estate, and I just never accounted for it. Um, and then finally, the volume of network data.
So I, I guess in our context, network data, you can think of it as just this, the signal volume. There's no shortage of logging capabilities across your cloud environments. And, and when we work with customers, typically they have a cloud native sim, they have additional sims on top of that.
They're trying to, uh, you know, make sense of all of this information, not just from hosts and, uh, you know, uh, um, network security appliances, but also from pipelines that deliver those things. And so it's becoming very complex and this decreases the overall visibility in the fidelity ultimately of, of the insights that we're, we're trying to achieve. And the, and, and how we go about, or our job every day, and the things that we're trying to do.
You know, we're trying to minimize the attack surface in the face of a very, you know, constantly expanding cloud estate, um, where we have very, very, you know, poor visibility potentially. And then monitoring risks to, to be able to respond to them in a timely manner is very, very difficult under those circumstances. But we try to do that.
Uh, we want to provide the operator with the insights to solve the right problem at the right time. There are a lot of problems to solve in insecurity and in life, but are we addressing the right one at the right time? And then finally, I think overall, the goal's always been to reduce the risk, um, for the organization to reduce the threat impact.
Uh, this comes through a variety of activities that we do in terms of quarantining and segmenting and being able to in investigate and, uh, cut off attackers more quickly. Now, I, I think it's good from the security operator's perspective to draw some distinctions. If your cloud, obviously this is, you know, if you, if you have a very broad cloud background, this is very well understood.
But let's baseline the fact that if you're a security operator working in a data center architecture, that was maybe like the three-tiered architecture, uh, or maybe a, a spine leaf architecture, maybe it's a little more collapsed than that. But traditionally, you have this defined thing, and it's got defined objects that are physical, and even by virtual, I mean physical because you own that physical infrastructure. But in cloud, it, it's actually more like this.
It's an architecture that has lots of ingress and egress points. So it's very, very flat on the, on the left side, I've got choke points that I can control. I stick a firewall in there and, and, you know, I can control that and I can open up ports, very simple.
Uh, but here I've got internet gateways and transit gateways and VPN gateways and, and nat gateways and all these things that, um, you know, connect a network in a very flat way. And it's very hard to control as this, you know, the network is ephemeral, it comes and goes, and people add VPCs and V nets and so forth. And by the way, it's software defined, but the, the network isn't just this, it's actually this to deliver all of that.
I've gotta know this because I'm probably delivering it as code. And, and the security in and of itself is delivered as code, but it's actually also this, like a single application or a single host is actually multiple things that are separated in and of themselves. The microservices are spread out across networks.
And so identifying if an application is being attacked or some component of an application or services is being attacked, you know, then I have to understand how all of these things are plugged together to, to be a service. But it's not only that it's actually delivered this way. So if I'm a security operator, I might need to understand what this is and how these objects came to be.
Um, so you have all of these layers of understanding that go on top of the actual infrastructure components. So it's very, very different in that regard. And then finally, all of that, the code, the deployment, um, the infrastructure generates these things in the millions.
And so if I have to look at all these all day, I probably quit my job. But it's, um, very difficult to get ahead of, you know, a a bunch of JSON files and, uh, that tell you something about something that happened, uh, with some random U-U-U-I-D and, and trying to figure that out. So the, the challenge for the security operator is, is very, very, uh, difficult.
And then we talk about threats continuing to, continuing to evolve. They're, you know, advanced, they're, uh, rapidly evolving. And I think, you know, there, there are threats that are evolving, but oftentimes we can't even see the basic threats.
So we have basic threats that we're, we're challenged with solving, um, which lends the opportunity to, uh, create more advanced persistent threats. Um, and I think if we can focus on identifying the, the, the basic things like, you know, when somebody's credentials have been compromised, uh, then we can understand and, uh, we can cut out much of the, the more advanced stuff. Now, how do we do that?
We talked about all, I talked about all that signal. Um, the first thing that we do at Fortinet is we take lots and lots of signal. We're very good at this, in, in, in distilling it down into something meaningful.
So we're ingesting as many sources as possible. And this doesn't necessarily mean, hey, it has to be coming from a Fortinet thing. It's, it's coming from the cloud infrastructure itself.
It's coming from, uh, the customer defined ecosystem. So we can pull in all of these different sources, and then we start to correlate all of that. Now, when we're looking at the platform and, and, and code security and, and, uh, security of, uh, the, the workloads themselves, um, we're correlating all of this context together into something we call a composite view of the threat or composite risks.
And these composite risks are very, very high fidelity. And this is what the team is gonna show you today. My teammates are gonna go through some scenarios that start to take, uh, maybe information that doesn't necessarily in and of itself indicate a threat.
The, the individual signal doesn't. But when it's correlated using, uh, really the very complex, um, machine learning processes that we have to correlate all that signal into something meaningful, we present that to the operator at their time that it, we have confidence in what that means. This is a threat, or this is a benign anomaly, and we can differentiate that.
And so at that point, we present it to the operator as actionable. So really what we're doing is taking a lot of signal, um, that doesn't necessarily mean a whole lot, uh, and then we're making it operational. We're operationalizing the threat intelligence.
And so in practice, you know, if you were an operator looking at a dashboard, it might be a simplified view like this where, uh, what I've highlighted is how we, uh, break down a particular threat into the details. We do pre investigation on behalf of the operator. And then even if I need to provide the operator with additional information, I have an assistant, an LLM that can start to provide details on what that attack chain was possible remediation steps of things to guide them into their next actions.
So we really take a view on, you know, this underlying, uh, artificial intelligence machine learning concepts to, uh, distill the, the signal into something meaningful and prioritized. And that's context. And then we further assist, uh, the operator with, uh, a, you know, a helper to say, this is what this means in more detail.
And by the way, here's what you need to do next. Can we jump in with a question here? Love your questions, please.
Cool. Uh, so this is, this platform is just a single place for everything from software composition analysis to SaaS to, I have a CV in my Kubernetes cluster, like the, the whole scale. Well, this particular part of our portfolio, yes.
Now, what we like to do is, um, we like to enrich signal across the, uh, uh, the security estate. So, um, and if you were just to use this platform, yes, you would have the SAST inspection, um, uh, code, uh, uh, the composition analysis. And, uh, you can even apply things like dask with, with, you know, some adjacent capabilities.
Um, and then you can look at your pipeline, uh, pipeline inspection for CBEs and packages, and then get into actually infrastructure monitoring, seeing how all of these objects are, um, related to one another in the context of, you know, I have, uh, workloads that exist in DPCs and security groups and so forth. And then that is the, you know, the workload protection, uh, platform protection aspects of it, um, that is packaged neatly together. Where we like to extend that is in, uh, the ability to provide customized, automated, uh, uh, functions and, uh, operator support.
So think of being able to take everything I know here, um, tying that into other signal I have, maybe in a sense or other signal I have in a, a, a network detection and response platform. And then being able to, uh, do very, very complex high with high confidence, very, very complex automated responses. So that's where our story is actually going.
Did it, did I answer your question? Yeah, for sure. Uh, and just one more quick question about it.
So this is one platform to do it all, or is this like, I gotta buy multiple licenses and connect everything within this platform? Yeah. Um, so the capp, the four to CAPP platform is self-contained.
You can just use that. Uh, some of the adjacent capabilities and and integrated capabilities that we like to show really are, uh, meant to be almost vendor agnostic. And, and we understand it that the customer is going to come with investments that they've already made, uh, ecosystem providers that they rely on and trust.
And the goal isn't in our demonstrations to say, Hey, like, you gotta have all the Fortinet things. We do show you a lot of Fortinet things, but the goal is actually just to have better security, right? And lower risk.
And so we will show you Fortinet things, but in some regards, you can take what you already have in your ecosystem and plug it into what some of the things that we have. So while, so I guess the point of what I'm trying to say is we'll show you Fortinet stuff, but we could also support non Fortinet stuff. Got it.
Okay. So if I'm, I'm, if I, you know, I have a security pipeline, and that security pipeline is using SA das, SCA with tech off, for example, I can integrate all that into, not integrate the pipeline itself, but integrate the tooling that I'm using into capp. Okay.
Got it. Yeah. A a classic example is a SIM customers have, you know, huge investments in SIM platforms.
Um, and they're like, Hey, I've, I've got all this signal in a sim, I want to integrate it through, uh, an automated response capability, right? But I need to enrich that with this other data that I'm getting from my platform, my cloud platform management, uh, or monitoring. And so they're, we're pulling in that data, we're pulling in sim data, and we're creating very, um, granular if thens on terms of, you know, what is the action or the thing to do if we see this type of combined signal.
Um, so yeah, we can get, we can get very specific to the organizational needs. I think that's the best way to describe that. Cool.
Thank you. Yeah, thank you. Okay.
So what we will ultimately look to achieve in our security operations is in, in terms of the demonstration that we have today, is we're gonna show you how we ingest signal. We're gonna show you how we take that signal. We analyze it for context, we will deduplicate it, we'll, uh, prioritize it and, and correlate all of that information into, to define whether or not the anomaly is malicious or if it's benign.
But ultimately, what we, the outcome of our demonstration is showing that how we can empower the people who are in the seat, the security operators who are very talented, but oftentimes are encumbered with, uh, low value activity, right? So we wanna remove the low value activity, take the talent, amplify the talent, so they're focused on high priority, uh, security actions. That's ultimately the goal of modernizing the security practice.
So with respect to Fortinet, we have a, a, a broad range. This goes back to the question that, uh, that you asked. Uh, but some of the things that we will be showing today really, uh, cover the range of security, uh, protections that we provide in and specific to the cloud.
Um, now we're not gonna cover all of these, but if you look at the capabilities that we pull into cloud security specifically, we're focused in really in three areas. Network security, uh, platform security, and application security. We're gonna be focused on, uh, platform and network today.
But application security are things like, uh, a web app and API protection services. But we can take information and and intelligence from all of these different, um, segments of, uh, the security, uh, practice, pull them together, uh, into something that is more, more actionable and meaningful to the business. Now, a little bit, uh, on Fortinet, if you don't know us, uh, we're, we're, we like to claim, um, leadership and innovation.
And one measure of doing that is to, to demonstrate through, uh, the intellectual property that we have. We generate more patents than, uh, the three or four nearest competitors in our space. Um, so constantly looking to push the paradigm on what can be done with security.
Um, so we have a, a very talented staff. Uh, I'm, I'm, um, very proud to be a part of that. And, uh, generating lots of, lots of security, um, uh, you know, patents now, a lot of the, the patents that we have are around how we manage threat intelligence.
And we've been doing, uh, we've, we've provided a platform for, uh, machine learning and really driving the AI paradigm for more than, uh, a decade now, almost 13 years. And that's really been out of necessity as customer zero, you know, hundreds of analysts were, you know, trying to understand what threats were persisting, generate signatures, and then feed that down into customer appliances and, and software. Um, and it didn't scale.
And so we started building this before anybody was talking really about AI and ml. Um, but it's grown to a platform that handles trillions of daily events. Uh, it's a, uh, has, you know, tens of billions of features.
Um, and, uh, so it really is looking at threats as they evolve in real time, pushing those updates to our, our family of products in near real time. And so it, it really provides an opportunity to do something, you know, different, it changes the conversation. We often get asked, Hey, like, do you have this list of CVEs in your database so that we can be protected against those?
And really the question is like, are the, the conversation should be or is, uh, we, we wanna focus on the threats that aren't CBEs yet. And so we can start protecting you against, like, things that will be CBE tomorrow or next week or next month. Uh, for Guard has really enabled us to take a leading position in this.
And we're, um, we're very proud of it as a company. Uh, we count, uh, more than 800,000 customers in our customer base. I mentioned the patents, uh, uh, but, uh, you know, we're roughly 14,000 customers, uh, spread globally.
Uh, and we account for, if you look at our, our, our genesis as a network security provider, uh, we account for about 55% of the global deployment of firewalls, um, and delivering on quality products. And, and that, uh, innovation, um, has led to the fact that, you know, when you look at the voice of the customer and the gar, the magic quadrants are really, uh, a good measure of customer experience because it's driven by customer feedback. Um, so just mentioning the, the, the Gartner Magic quadrants, we're in 10 of them.
Um, just our, our core 40 s operating system is, uh, part of, uh, five, uh, in and of itself. Uh, so we're, we're able to demonstrate a competency across a number of security, um, um, security, uh, specialties. Um, we're a very broad spectrum provider, so if you don't know us, uh, uh, uh, we, we have about 60 areas of focus across the security, um, landscape.
Uh, this really summarizes where our core areas of focus are in terms of strategic pillars, um, on behalf of our customers. So within, um, the network security space, uh, we're focused on delivering firewall, extending into the land and edge. Uh, and then on the SSE platform, this is really delivering, uh, capabilities such as, uh, se, uh, secure edge, um, zero, uh, zero trust access, really those as in service capabilities.
And then on the security operations side, we're, we're actually gonna spend our time in the demo today. It's about demonstrating what the modern SOC opportunity is, driving better automation, uh, getting better insights into the threats that are specific to your environment as a, as an organization, um, and how to get more out of your security talent. And so with that, uh, I'll tell you a little bit about what the architecture looks like.
So this is the demo environment that we've set up. Uh, we've deployed, um, uh, a number of VPCs here. Uh, but we're gonna do three things in our demo.
We're gonna observe, what we hope to see is, you know, when we're attacked, uh, we're going to work on demonstrating some ability to correlate, uh, the attack, uh, and look at that attack as it escalates through a number of, uh, types of attack vectors potentially. And can we just, uh, can we determine the chain of exploit? And then finally, how do we remediate it, you know, ultimately a measure of, uh, you know, our effectiveness is going to be, you know, what it, how fast can we respond?
Can we reduce the MTTR? Uh, can we reduce the, uh, MTTD, um, and can we do auto, can we support automation that is very low risk here? You know, we've run into the issue where we've seen customers deploy automation and that automation breaks things.
Um, and so what we want to do is avoid that. And so that's a big part of, uh, showing the efficacy of our, our practice. Okay.
So with that, it's, uh, demo time. I'm gonna hand it over to Julian Peterson. Quick question before, uh, we get into the demo.
Yeah, Thank you. How would you Characterize the various types of attackers? How would you bucket them?
And then how do you defend against them depending on what type of attacker tactics for each one, or, Um, can you define what you mean by type of attacker? Are we talking about like, Meaning, is it a, is it a syndicate or is it some guy in his base parent's basement? Is it, um, yes, the type of, so those type, and then do you that's me, uh, attack them or, uh, defend against them differently?
Um, I, I, I don't know that we defend against them differently. And, and I, Julian can help me answer this question as, as a, the threat analyst. Um, but I, I think we look at their, uh, t uh, TTPs, uh, you know, what, what are their tactics?
Um, what, what practices do they invoke? Uh, and being able to, uh, defend against those, you know, different types of exploits. Um, you know, I think whether or not you're the, the, the script kitty or you're the, uh, nation state actor, like the, the, we see a, a lot of, um, uh, uh, malware for hire, uh, or malware as a service.
Um, and so I, I don't know that the, the individual persona, um, is necessarily different, but we're focused on like what, what is the, uh, the type of attack, uh, the methodology, um, um, and the tactic used, uh, to execute that attack. Julian, do you, do you have a different perspective on that? Not necessarily different, but I think one key pillar is you have the script kitties, which creating a lot of noise on a network.
So, and a lot of, or like scanners, I mean, there are a lot of vulnerability scanners out there which constantly hammering on your application. And is it malicious? Not really, because quite often it gets, it doesn't happen anything.
It's just traffic which costs you maybe at the end some money. But what often happens is that there is that one single misconfiguration you did by accident on the environment, and then one scanner finds that, and that's one big problem. So it's not maybe that unpatched vulnerability in the environment, uh, or it's mostly that misconfiguration, which then allows a script kitty to, uh, attack and infiltrate your environment.
And finding exactly that, that this now has worked successfully is one problem and which we want, or which we wanna show you to solve. The second one for sure is you have no sophisticated threat. Speaking about nation state actors, they're usually not script kitties sitting in the basement.
Uh, they know what they do, they have a lot of preparation and a lot of money, meaning they have the time and intelligence to simulate like a common person or personality. But still there is usually some key pieces which creates like an anomaly to make them identifiable. And that's exactly where we dive in.
I just teed you up. That was What I was trying to do. Yeah, it's perfect.
Do you think Julian? Uh, I think maybe how we go about stopping the, the more advanced persistent actors is, uh, probably a, a, you know, a key difference here. Um, in order to keep up, uh, you know, that's where we're invoking machine learning, um, because you know, they're getting much better about avoiding, you know, some of the, the pitfalls that, you know, it may be a signature based detection, uh, methodology might employ.
Yeah. Uh, thank you for having us also from my side. Uh, my name is Julian Peterson.
Um, I'm your bad guy today. And I have two good guys with me and I already mentioned upfront, uh, we will try to play a bit cat and mouse today. Uh, we have two kittens and myself as a mouse.
And what I will do now is I will attack our friends' infrastructure and I will be some mix of script kitty and try to be a bit more sophisticated because from what we see is script kitty don't go that far because they usually only leverage automation tools. So it needs to be fully automated. Like there is not that manual efforts done, like doing privilege escalation and doing all the manual steps, script queues usually work at scale.
It needs to scale well. So, uh, to make the money out of that, that's the most goal. And what are we trying to do now today is I am the, the friendly guy with that hat and I will try the application, uh, my lovely colleagues have set up.
And that application is some somehow on purpose vulnerable. Um, because they said, well, it's too much effort to rewrite that application. There were too many breaking changes.
So it's running in a container, it's secure. That's, uh, one often seen mistake. What I can do is I can break out of that container and infiltrator or another environment.
And another part is, and that's quite often just like that, that pipeline of issues which happened because of maybe some missing configuration or missing communication, uh, between different personalities is I can go into your AWS and from there I can open myself a new door. Will this have the ability to detect, like to your point, right, if you're breaking out of a container, you don't have proper security context configured for your pod, will this detect that? We will, you will see that.
Cool. Let, oh, better, let's go that way. Let's see if my colleagues will see that.
That's not their part. So forget about that. They're in the room now, they don't know what we do.
So, and setting up the backdoor because we want to be persistent. And from there I sponsor malicious application because somehow I need some money. So I need to finance my operations.
And that's where we now dive in basically. So what we have prepared is we have the unhackable e-commerce store. Of course it's unhackable.
Um, it's pretty simple. We have some products, we have a nice page. You can log in, log out, you can play around.
And that's our goal. That's our target. And I've prepared already my techer machine.
Don't be scared, it looks super messy on the text. Um, let me simplify that a bit. What I've prepared.
So what I know that's a Java application and maybe some of you remember something with Java that was a lock four J fantastic locking tool helps you to do debug locking, for example, and knows there's something going on. And well, again, I said it's in container, it's secure that even if it gets hacked, right? I mean they cannot break out.
And I've prepared here an attack with the METAS framework. So I'm attacking data P address, which is, um, one, uh, public IP address where that application is hosted behind. Just to simplify it a bit, um, the vulnerabilities in the X API version header.
And at the end what I will do, I reach back to my CFDC two dot ftt left tech, uh, commanding control server. We need some LA port that's common forward, that vulnerability, we need an LA callback to inject. Then our payload position, which then gets downloaded and that payload is basically hosted on port 8,000.
And our command then reach or reverse shell basically to interact with the system, reach back to port 80 80. Why? I mean, we try to be, to be stealthy and 80 80 is a common HTDP port, so it doesn't look that fishy on a network log or on the firewall.
So it goes a bit under the common communication and traffic. So let me run into that. Just let's exploit it and takes not that long, hopefully.
Fingers crossed You're hitting a public endpoint or is this under the assumption that you've already authenticated and got proper authorization into the cluster? I'm hitting The public endpoint. So what I did, I, to be honest, I skipped the, uh, domain, uh, for the reason because there are multiple IP address.
Yeah. Which would, cause then I have multiple shells back just to limit it a bit down. I picked one of those.
Gotcha, Gotcha, gotcha. That's the whole magic. Yeah, I was just asking 'cause I, because the other method I've, I've seen with this as, um, if you're using the, like there's a Kubernetes module in MetaPort that you can utilize to authenticate and stuff and that's why I was asking.
Yeah, That's right. Doesn't like me today? Nope.
Doesn't like me today. Let's give it a second try. If not, we have a bag video.
No, it doesn't like me, that's not a big deal. Put you're happy, you'll just live off the land for another, another hour or two and we'll, uh, we'll get back in. I think we may be stress the demo gods out this week too often.
Good. We do too many dry runs. So I guess that's now hitting us back, but it's not a big deal.
So, uh, we have a video, It's exactly the same, it's from uh, the last couple days again, we have that web application and switching back to the, uh, meta SPL console, uh, quickly heading over that, having that all prepared, it sounds really scary. It, it's not that it's relatively simple, setting that up there, other versions metas split makes it just relatively easy to uh, have a great environment set up for that. Um, if we move on a little bit further, so if we run the exploitation, you can see we're serving that code, uh, that that char file.
So it's like it's loading and Java archive and executing that within that Java server, uh, fruited lock for J Vulner vulnerability and the box and what we can see, we get a shell bag. So you see at the bottom that meta press session one has opened, which is for the attacker. Fantastic.
That's that moment where I can go to the weekend. That's your job is done. Um, for the good guys, it's pretty hard.
Now we have a reverse shell and what we can do is, let's see, you see we have a session in that meta preta context as a Java runtime and we're running as root in a container. Why a container? That name looks a bit like that to be honest.
Um, that's just a feeling you get after some time. That e-commerce website and that A UID is weird, let's get interactive, get a shell. So like an interactive command prompt on that, uh, host and make it a little bit more useful.
So Spaa Bash, you can see we are on a machine now we could steal the source code. Could be interesting depending on the application or maybe grab database entries, getting internal credentials and stuff that that's not where we want to go. While we know based on some research and also looking a bit on the disc mounts, we mounting in the, the host file system.
So that looks a bit like an unprivileged container. So what can we do with that? Well, we can mount our host operating systems disc from into our container.
We are root, so we have full root privileges over that and we can break out and that's what we do. So creating a folder on the under slash mt slash host fs. And basically what we do there is mounting our disc from our Kubernetes node, our work node into that container.
And if we look now after that mount command, what we have in there, um, in that slash mt slash hol, well there we go. We have a root falls system. What can we do from there?
Well, it's up to us. Uh, the point here is a relatively easy one is let's get a shell. Um, again for that what we can do, just load another meta binary, which we already pre-compiled and just set up a cr chop cron runs every minute.
Let's make use of that. We can write to the CR tab, which is also great because even if they find that binary in like terminate a session temporarily, well not for us, right? A minute later we got it back, which is fantastic.
So I'm downloading the payload file, um, over the network on that node fruited container on that node disk, um, making it executable. Um, it's a pretty quick one and just setting up the code. Um, you see in the demo we already had that crunch of set up, which uh, was a bad timing, but that's the command.
So we like static CR chop run every minute, just execute it binary. And if you're not connected, connect back. Um, we have the cell.
So let's switch out and let's check again in the sessions. You remember now we have two. Before we only had that one of the Java, not a second one looks more like an EC2 instance.
So we are escaped out of that container and can now do whatever that Kubernetes node basically can do. Um, if we switch to the interactive mode there, same way here, let's set up a shell. And what is interesting we know is running an AWS and what is great on the cloud, especially from an attacker perspective, uh, before your computer wasn't really like an identity.
Now it is. And that's a, a bit of a problem in modern environments because when we look into the legacy environment, that was like a machine was mostly an IP address and it was there. Now it's a full identity, which you need to take care of and provide the right authorizations.
And that's exactly what we can use, uh, or will use especially. So getting a stable shell, uh, using Python for that, uh, tweaking us a little bit for the A-W-S-C-L-I. And after that we can look who we are.
Uh, because on AWS each instance knows the AWS command. So the tools are always there. And the good part here is let's use the living of the land capabilities because that's usually not that, uh, visible.
And we can see we are at an instance in a certain group and the EKS node group role. Great. So now what can we do with that?
Um, which roles or which policies do we have attached in that group? Um, figuring that out. We can use the A-W-S-C-L-I, let me quickly fast forward a bit.
We use the IM list attached role policies to our EK is not a group role. And the big problem here is something you did for debugging quickly. And after that works and you're always on a rush, you forget to change permissions and roles and maybe you've seen it on the top.
There's that EKS note group admin debug. Well fine, that's Holland and that's the problem. So when we look into that admin dba, well, okay, that's there.
Uh, that's the policy name. Cool. Which permissions do we have?
Anyone wants to give a guess? Darn Any, any allow Of course, Because we are admins, we deba, we know what we do and for sure we'll remove it afterwards. Yes.
No, I guess that's the the biggest lie always. And what can we do with that? Basically everything in that environment, right?
I mean, we can take over that whole full account and what we wanna do, we wanna be stealthy. And so let's take the easy way. We see that user, uh, deady, it's there.
That looks like it's user running, sitting in there. It's on service account with some other service accounts. Let's just create an access key.
You can do up to two. I mean monitors that, right? And that's awesome.
Let's impersonate on that. And with that access key, we have now a persistent backdoor. Even if they kick us out on that Kubernetes part and reset that whole environment, we are still in there.
And well, what is better than having a free cloud resource? You're not paying that. It's not your credit card behind.
We compromise the company. Now we can sell the access. That's one part.
The second part is as an attacker, we can now spin, spin up like crypto miner, it's free resources and crypto mining. Well, even if it's not that efficient, yes, in your environment, in someone else's environment, it's super efficient. Let's set out the AWS credentials in our environment on our attacker box because there we can control the tool sets and also we don't need to take care of the monitoring for sure.
We want to be a bit more selfie. So let's set it up, make us a little bit more persistent on our attacker machine. Now on the C two server, just validate that we are there.
Let's check again that the credentials are still, um, working. We are hopefully that that's a user account. We are awesome.
What we can do next is setting up our Kubernetes environment and just apply our malicious application and pretty simple as that. Um, uh, yeah, AWS helps us greatly with creating the Kubernetes config. Uh, we can even now, what we could do as well, we, I mean we could just, yeah, we could destroy like that whole web application or try to target it and do a denial of service, but it's a bit noisy.
So let's just run a crypto miner that's less noisy and is a bit more helpful for us and well, yes, that's where we are. Um, having a fantastic crypto miner in place and now we're making money. And with that little thing we have messed up the whole company and that less than 10 minutes.
So, and that's a bit where we want to go through. So what is that whole problematic piece behind this? Um, you have a lot of misconfigurations, which will make your life hard.
And it's not only maybe that guy who on that zero day and penetrated your environment or broke into it, it's sometimes just a little, we forgot that little Dan debug role, uh, which, which can, which allows 'em attacker. And now the problem here is how can you defend that.