Threat Emulation with Andrew Costis
Easy Prey11 Syys 2024

Threat Emulation with Andrew Costis

Security risks are dynamic. Projects, employees, change, tools, and configurations are modified. Many companies utilize PEN testers on an annual basis, but as quickly as systems are revised, you may need to implement threat emulation for regular monitoring.

Today's guest is Andrew Costis. Andrew is the Chapter Lead of the Adversary Research Team at Attack IQ. He has over 22 years of professional industry experience and previously worked in the Threat Analysis Unit Team at Firmware, Carbon Black, and Logrhythm Labs, performing security research, reverse engineering malware, and tracking and discovering new campaigns and threats. Andrew has delivered various talks at DefCon, Adversary Village, Black Hat, B Side, Cyber Risk Alliance, Security Weekly, IT Pro, Bright Talk, SE Magazine, and others.

Show Notes:
  • [1:14] - Andrew shares his background and what he currently does in his career at Attack IQ.
  • [3:49] - At the time of this recording, there has been a major global security panic.
  • [6:06] - There are many programs that we use on a regular basis that we don't always consider the security of.
  • [8:09] - Historically, companies would pay for an external pen test. Andrew describes the purpose of this and how they usually went.
  • [9:33] - Pen tests and threat emulation do not need to be limited to just once a year.
  • [10:45] - Andrew's team is in the business of testing post-breached systems. But they preach prevention.
  • [11:55] - Attackers are lazy in the sense that they will reuse the same strategies over and over again.
  • [14:13] - Many programs we use may be caught in the crosshairs of attacks and vulnerabilities in other companies.
  • [16:41] - Andrew discusses the frequency of really critical CVEs.
  • [19:01] - What do attackers go after when they've breached a system?
  • [21:04] - The priority for attackers is to get in quickly and make the victim's data unavailable.
  • [22:24] - A lot of people are under the impression of vulnerability testers. "Fire and forget it" is not a beneficial mindset.
  • [24:56] - If we run every test, the amount of data will be overwhelming.
  • [27:03] - In his experience, there has been client testing that has been overwhelmingly easy to breach.
  • [29:07] - There are also organizations that have done a fantastic job. However, vulnerabilities will still be found.
  • [30:18] - The red team is not going to be able to cover your entire organization.
  • [32:15] - Threat emulation and pen testing are technically the same thing. Andrew explains how she sees the difference.
  • [33:50] - How are vulnerabilities and tests prioritized?
  • [36:19] - Andrew describes the things his team works on and their objectives for customers and clients.
  • [38:34] - The outage at the time of this recording had a big impact. It gave a really good idea of what could happen if it were a real security breach.
  • [41:37] - There are a ton of free resources out there. The primary resource at Attack IQ is the free Attack IQ Academy.

Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

Links and Resources:

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(342)

Hidden Phone Tracking

Hidden Phone Tracking

Your phone gives off a surprising amount of information just by being connected to a cellular network. Things like your location, who you communicate with, and your daily patterns can all become part ...

23 Syys 45min

Ransomware Evolution

Ransomware Evolution

Ransomware has changed dramatically over the years. What started as criminals locking up individual computers and demanding relatively small payments has grown into a much larger operation involving s...

16 Syys 40min

The Counterfeit Economy

The Counterfeit Economy

A counterfeit handbag may leave someone disappointed. A counterfeit medication, airbag, or child's car seat can do far more damage. Fake products now reach into nearly every part of daily life, and ma...

9 Syys 43min

The Internet is Playing You

The Internet is Playing You

A convincing lie no longer needs to look suspicious. It can appear in a familiar social media feed, come from someone who seems real, or arrive as a video that looks almost impossible to fake. By the ...

2 Syys 44min

The Psychology of Yes

The Psychology of Yes

It is easy to say you would never fall for a scam when you are looking at the situation from the outside. In the moment, though, things can feel much less obvious. A request may sound reasonable, the ...

26 Elo 49min

Drink Spiking

Drink Spiking

A drink can be out of your sight for only a moment, but that may be all it takes for someone to tamper with it. Spiking can happen in bars, restaurants, festivals, and even among people who already kn...

19 Elo 35min

Love, Lies and Locked Up

Love, Lies and Locked Up

What sounds like the plot of a crime thriller was Sharon Armstrong's real life. An online romance drew her into an elaborate web of lies involving overseas contracts, invented emergencies, and several...

12 Elo 52min

The Recruitment Trap

The Recruitment Trap

Everybody is searching for ways to increase income. Unfortunately, MLMs often look like an easy way to start a business without taking on the cost of a traditional company. The pitch sounds simple. Bu...

5 Elo 51min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
vallattomat
aikalisa
politiikan-puskaradio
rss-viihde-media
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-vaalirankkurit-podcast
tervo-halme
otetaan-yhdet
rss-kaikki-uusiksi
rss-voi-venaja
rss-podme-livebox
the-ulkopolitist
rss-raha-talous-ja-politiikka
rss-asiastudio
rss-girls-finish-f1rst
et-sa-noin-voi-sanoo-esittaa
rss-seksicast
rss-50100-podcast