Cybersecurity Penetration Testing – Karl Sigler, Trustwave Spider Labs
Karl Sigler, senior security research manager for Trustwave Spider Labs, explains how cybersecurity penetration testing is being used for both good and ill.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Carl Sigler who is a senior security research manager at trustwave spiral Labs. That's a handful of a title, but and we're gonna be Talking about how the bad guys are using penetration testing tools and what that might mean for folks because it seems like the tools themselves are getting better. And so the question is is how to respond Carl.
Welcome the show Thanks so much. I appreciate you having me today. Bad guys, of course have been using penetration testing tools for a while.
They cut both ways. Just like any other tool but the question is is are these tools becoming more sophisticated are we seeing advances in that space and are they being used more aggressively for evil purposes? That's a good question.
I think they're definitely more advanced a lot of the tools that we see coming out today for. Both good and malicious purposes tend to have a lot more features than we've seen even seen even in the past five years 10 years. So yeah, definitely more features involved whether or not they're being used more now than previously it's hard to say.
I think that Criminals have always hand-rolled their own tools sometimes and sometimes rather than Reinventing the wheel. They go with the common tools that we all use back in the day. This was things like nmap to scan networks for reconnaissance purposes and find out what was live out there.
Metasploit was a huge tool for both good guys and bad guys back in the day these days. It seems to be more Cobalt strike, which is very flexible toolkit to allow persistence and footholds and lateral movements throughout a network after you get that initial foothold. So we're seeing those used by again both good and bad guys.
Is there some way to detect those tools because essentially if you see them that's a reconnaissance mission that somebody's on and it's clear that they're going to look for something. So can I follow their Trail? Absolutely.
Yeah. So, um, you'll often see that the Cobalt strike pool or really any of these pieces of malware now, that's the good guys know about them. We've developed detection logic and detection guidance for how to find these malicious exploits both on the network.
If you're using things like IDs or a Smart Switch or something like that to monitor your network segments or even on the endpoint if you have endpoint protection anti-malware Solutions things like that, there are definitely signatures available that can flag this for you. I think the problem that some organizations get into is that again, these are used for both good and bad purposes. So if you have a complex organization or you don't have good clear communication across the board, you may find that these signatures the protections that you put in place to prevent cobols, right maybe triggering on valid activity.
It could be your IT staff that is doing a scan to make sure you're not vulnerable to specific things. It could be. Work administrators that are doing an nmap scan to make sure there aren't any Rogue hosts that are out there.
So you need to have clear communication in-house for what to detect and what to allow on you know, and allow list to not trigger on those types of false positives. How will penetration testing evolve or should it evolve and I'm asking the question because historically somebody would run one of these tests and then they issue some sort of report and they pat themselves in the back if they pass but yeah, it environment would change substantially within days. And so whatever I was testing for is no longer completely relevant because the landscape has changed the number of endpoints of increased the way they applications behave has changed.
So do I need to evolve this into something that feels more like a continuous process? 100% it's it's never just a set and forget it like you say our networks are Dynamic. They're constantly changing and I generally see Penn penetration testing done in conjunction with other types of security Consulting things whether you're doing it in-house or whether you're using a third party typically There's not too much that penetration test can find that just a standard vulnerability assessment scan couldn't find right.
So you're looking for holes in your network. You're looking for hosts that maybe you forgot about or people set up as test systems and left on the network. You're looking for patches that aren't in place things like that and you're standard vulnerability assessment tools out there nests from tenables a good one open bass as open source and free.
There's a lot of tools out there that you can use to scan your networks and make sure that you're as tight as you can be now we're penetration comes into place is where you're putting a lot of human knowledge experience and intelligence behind looking at your vulnerability profile your risk profile if you will and penetration tester might be able to see how to take maybe some really minor vulnerability that the company didn't even consider of vulnerability or decided was not worth hatching because it was so minor and take that one single little and then Added into a more robust breach. So the two things have different purposes. I don't like to see a penetration test sold to find out what You're vulnerable to I like to see penetration tests sold more is like a red teaming environment where you're looking to see how your overall information security structure in-house is responding to a threat and responding to complex chain attacks on the bad guys.
So they continuous process as well. It seems to me they would pick a Target and just start monitoring that looking for opportunities and doesn't take them too long to strike, right? absolutely, absolutely, and we're seeing a lot more of that where Again, even a decade ago.
We were seeing a lot of opportunistic attacks, you know, throwing a wide net and seeing what you can pull in especially for financial purposes. A lot of times. It's a cheaper to launch those types of attacks versus the return on your investment for all of the money you've stolen from that wide net that you throw out there these days we're seeing a lot of different motivations.
We see nation state motivations corporate Espionage things like that where the goal isn't necessarily strictly Financial or even if it is financial the word the criminal organization has decided that they might be able to get more money if they are more careful with how they attack the organization in which case they will set up an entire stage of reconnaissance. They will comb through your organizations public information your public website. You're LinkedIn Pages all the employees the LinkedIn Pages map out an orc chart based on all of that who has public Twitter profiles Facebook profiles.
They're gonna build a literal booklet about exactly how your organization works. Who's on top who's on bottom and who is the most likely Target for attack and then start those attacks from there from that specific point and depending on the again the motivation and what they're looking for on the other side of the equation a lot of times those more careful planned attacks have a lot more results coming out. are the also starting to use Ai and are we involved in some sort of arms race involving AI in this space?
And what does that look like? That's interesting question. I have not seen any of the Cyber gangs that we have been following looking at using AI specifically but we are seeing adoption of AI machine learning deep learning Technologies across the board.
I imagine that a lot of cyber groups out. There might be using AI for figuring out exactly how to what the best deviation techniques are for instance against specific anti malware products. So where today if a malicious actor wants to make sure that the malware their custom creating isn't discovered by, you know, antivirus Fender number one, which is what their target is using.
They're going to load it up in virus total and see if there are any detections for it. I think that that type of procedure which is right now manual for a lot of criminals could be performed by setting up a big training pool of various malware's and then antivirus vendor once a signatures and just letting that deep learning Engine train itself on what is the best deviation techniques for that specific piece of malware. Again, I've seen that I am just speaking hypothetically, but I absolutely believe that I could happen and we're definitely using it on the good guys side.
And in fact the research team on my in my company just came out with a machine learning engine that spots phishing URLs and emails. So we actually supplement our you know, experience detection guidance that we set up with that train machine learning engine that has been trained on Billions of phishing URLs to properly detect one and eliminate ones that would cause false positive so adoptions definitely out there. I haven't seen it on the bad guys agenda so far at least openly on their agenda so far.
I I'm sure that will happen now. We continue to see what's going on in Ukraine, and there's clearly a whole cyber warfare component of that. Are we starting to see more of a democratization of pen testing because there are more people at least learning the skills or trying to learn the skills for various activities good and ill and so will the pool of people who are capable of using this tool for both Hill and maybe even hopefully good start to increase as a result.
Absolutely. My 100% that is happening. We're seeing a lot of organizations.
They're being forced to either train their people for to protect their networks and are taking cybersecurity seriously and that cat and mouse game of we're putting Protections in place and good guys are bad guys are finding out how to evade those detections. So we put new blocks in place and and that's sort of back and forth races The Experience intelligence and skill level of everybody involved and so far. It's it's been a lot of back and forth.
I think we've seen a lot of really good stories coming out of the Russian Ukraine situation. We've seen a lot of specific attacks from Russia who is very very well versed in a cyber activity actually blocked by Ukrainian cyber protectors and that's sort of account and mouse game the the skill level and seeing how they're able to set up these attacks instead of protections against these attacks as definitely become a lot more complex than it used to be, you know, a lot of the Protection advice that we give is the same advice that we've been giving since the late 90s, but the complexity of those attacks has definitely increased quite a bit. Once you're invest advice to folks then what should they be thinking about?
What should they be putting in place today are their best practices? That should be employed to kind of? A defeat or at least thorough these reconnaissance attacks and then be for them to use the capability to protect themselves.
Sure. Sure. A lot of the advice that we've been giving we're still giving first patching is so important a lot of these initial attacks that we saw specifically in the Russia Ukraine conflict.
We're targeting vulnerabilities that had patches available up to 18 months prior to the attacks. People are still not patching quickly and that's leaving gaps in your networks for Bad actors to come on in and we repeat this advice a lot and a lot of Administrators get beat up for not applying patches properly or quickly and a lot of people don't realize just how difficult that process is how complex patching can be especially if you're you're most valued systems the ones that are going to really heighten your risk profile are also the systems that have 99 five nines of up time and you can't really bring them down. There's really the availability protection needs to be so high that you can't take a risk of that.
Screening because of a 40 patch or a specific implementation that you have so, you know administrators have to be very careful and how and when they push patches out so it can seem like a really overwhelming process and obviously it is because a lot of organizations still are not doing it properly but I think anyone who's involved with a IT team or an administrative team that's listening to this revisit your patching policies and revisit them now before any of those vulnerabilities get exploited. That's definitely probably the biggest thing. I see people not getting patches in place properly and I do understand the problem, but we need to address that problem and it's going to be unique for every single organization.
So the better, you know, your organization the better you're going to be able to solve that problem for your organization specifically. In addition to that I would say also. not to cut you off the Fishing attacks are probably the number one entryway that a lot of these attackers get in that greater than 90% of compromises and breaches.
We see come from an initial foothold of a fishing attack a lot of times that'll be a spear phishing attack targeted using this reconnaissance techniques that we just talked about. But if your systems are Patrick properly and there's no other way to get in they're gonna stop attacking software and operating systems that are going to start attacking the people behind the keyboard and they'll use very convincing social engineering scams to convince that person that's looking at that email to either click on a link or open an attachment. And again, that's probably the biggest method of Entry both in the Russian Ukraine conflict and across the globe historically for for well over a decade having ongoing security awareness training for your users so that they know what the new fishing techniques are that are out there what sort of new techniques are being used against them how And see and that sort of making sure that it looks legit.
They're getting a lot better at that. So we need to make sure that security awareness training matches that challenge. All right as is often the case in life.
The only thing worse than getting tested is not getting tested, right? Okay, Carl. Thanks for being on the show.
My pleasure. Thank you so much for having me. All right back to you guys in the studio.