Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1
And we'll go back to another episode on How to Hack.
2
So today we'll be discussing about this cyber attack chain.
3
The reason why we have to understand about a cyber attack is because there are a lot of questions about
4
what goes on in the penetration testing, how our security assessment being carried out.
5
And the best way to actually describe that is to look at cyber attack chain.
6
So in this case, cyber protection is, of course, developed by Lockheed Martin, and it is to help
7
us understand and visualize the step by step process of how hackers actually go after specific individuals,
8
a particular enterprise that they have been hired to go after, or if they are state funded hackers,
9
state sponsored hackers, and they have a particular agency in mind and they are supposed to go after
10
them.
11
So there are so many tutorials and so many different kind of hacking videos available.
12
But the whole idea is doing what you have or you're doing a penetration testing.
13
It's important to follow this step by step process and it will really help you be able to control and
14
manage how far you're going into cyber attack chain and how far are you going to penetrate the testing.
15
So on the left side, we actually have the different phases and of course, we have seven phases.
16
So here we go, reconnaissance, which is about finding out information on publicly available websites.
17
And of course, we are weaponization is number two.
18
So this is about how we can create the payload, whether it is a fully undetectable payload, a microwave
19
cell.
20
It's about how we can weaponize it and delivery.
21
Are we going to use a USB?
22
Are we going to send a phishing email?
23
Are we going to send Seabass?
24
So again, those are the delivery mechanisms that we'll be using in terms of putting the weaponization
25
or the weaponized payload into the system.
26
And of course, we have our exploitation.
27
So exploitation is a way for us to actually attack into the system.
28
So we will execute you will execute the particular exploit that we have created in number two, which
29
is to weaponize of payload and number five installation.
30
So we'll install the malware into the system, into the mobile device or any assets that we have on
31
hand on.
32
And this is when we go into number six, where we have command and control.
33
So whenever you're looking at the tutorials, you're looking at that display framework as the command
34
and control center to manage and control many of these devices.
35
And of course, the final thing is on actions and objectives.
36
So this is what are we trying to accomplish?
37
Have we achieve our goal?
38
What was the goal?
39
Was it for personal data?
40
Was it for credit card information?
41
Was it for financial data?
42
Was it for state secrets?
43
So, again, all these are the things that we're looking at in terms of the cyber attack chain.
44
So, of course, we discussed the cyber security Kuching.
45
So it's really important what you're talking about, the chain of cyber attack chain, because many
46
enterprises or users can be victimized by many of these cyber breaches.
47
And over here we can see the different companies that have been compromised.
48
And again, it all follows the same steps.
49
So if you read up about the hacks that have happened, you'll recognize that many of these hacks that
50
have happened follow this specific step.
51
So if you manage to get a detailed report on it, you'll be able to see how the hackers actually attack.
52
And it is very similar to what you see in a cyber attack chain, all the cybersecurity cuchi.
53
So the first step is about reconnaissance, a reconnaissance is about finding publicly available information,
54
using who is using domain name servers, information, lookout on your servers, and be able to find
55
out what data they have using Net Kroloff using all these different kind of publicly available information,
56
including also on Google searching to find out usernames, passwords, more tanks of all the domains
57
going into dark web, finding accounts, data or passwords of this particular enterprise and getting
58
those data.
59
So, again, the characteristics of this, it could range from minutes all the way to weeks and months
60
trying to find out all this data.
61
And because a lot of users have social media accounts.
62
Again, those are good places to also start all that to find out more details about enterprise, about
63
individuals working in the enterprise.
64
So this is what we call passive reconnaissance.
65
We are trying to file all publicly available information, not directly interacting with the enterprise.
66
So do not on debt.
67
And of course, this is where we have the active reconnaissance, so active reconnaissance means we
68
are probing the system.
69
So whenever you'll look at and map that we have been using in a number of the tutorials, we are trying
70
to get details about the services of the systems and servers.
71
They're available in site, that particular enterprise.
72
So we are actually trying to prop directly into the system, looking at fingerprinting, reconnaissance.
73
We are working and we are pinging the system to find out more details and data.
74
So this are information that we can find out immediately from.
75
So again, active reconnaissance and passive reconnaissance are very different in terms of trying to
76
find out all these details.
77
So, of course, this is where we go into the weaponization stage, so the weaponization stage would
78
actually allow us to see what kind of payload we can create sort of first and most use is actually using
79
Emmis of venom, or you could actually use a different kind of tubes to create a payload so you could
80
write your own script or your own malicious software if you know C programming and so on, or you want
81
to put it up on the shell.
82
You want to get a reverse shell on it, you want to get a seashell on it.
83
So again, all these are available as part of weaponization.
84
And in terms of weaponization, we are also thinking about how can we make it fully undetectable so
85
that we'll use encoding matter to use different kind of Métis to mask the capability from detection
86
by antivirus systems.
87
And of course, ultimately this would bring us into the delivery stage.
88
So in the delivery phase, this is the part where we're thinking about how are we going to deliver the
89
payload into the user's machine?
90
So, again, over here we go to social engineer has seen a number of tutorials.
91
So it's about website attacks.
92
We want to create website hoster, particular payload.
93
Do you want to create infectious media generator put into a USB drive executed moment of user plug it
94
into the computer.
95
Do you want to have a payload?
96
You want a mass mailer to all these options are here inside a social engineer toolkit and we'll be exploring
97
a lot more later on.
98
So this is about the transmission of the attack.
99
How do we get the payload, a weaponized payload into the user's computer?
100
So, again, another key point in terms of sending out a face in order to talk about is also what kind
101
of payload are you doing?
102
Because some of these delivery mechanisms can be very different.
103
So, one, you could be using a lot of phishing emails that could be blasted out to millions of users
104
or two.
105
It could be a very targeted, very specific format of the email that is sent to one person where we
106
just want that person to click onto it so that we can go after that particular entity.
107
And this is on the exploitation stage, so this is what happens once you're weaponized, you've delivered
108
the user clicks onto it and you get a revised shell immediately.
109
So this is the detonation of the attack.
110
So once the exploit happens, we are in we are into the system.
111
And this allow us to have control of their environment.
112
So, again, this is all about gaining access, bypassing security mechanisms.
113
So this is the detonation of the payload.
114
And of course, once you hit a destination, this is where we go into the installation.
115
So this is where we want persistance inside the system.
116
We want to have the ability to persist inside the mobile device, inside the server, inside a computer
117
device.
118
So, again, this is what we call a payload again on the screen.
119
So this is a Microsoft disable.
120
Once the user click on enable content immediately will get access and we'll install a pilot into the
121
system and we will actually create persistance so that we can be able to latch onto the computer system
122
no matter how much the update to it.
123
And of course, this is the command and control and command control, we have a number of options in
124
sight, the channel where we discuss about how we can actually control the system.
125
So the first one that is most use a lot of time is using a supply framework and as of flow, of course,
126
on empire power shell.
127
So Ampara directly to manage based on the power shell scripting.
128
So and not a great way for us to manage many, many of these computers and systems.
129
So this is what we call the bots.
130
So any of these computers that have been hacked into, we call them to barter, we controlling them.
131
And on the top you can see we got a bot herders.
132
So the bot herder actually allows you, which is you to control what the bots will do as a result of
133
them being hijacked into.
134
So, of course, the focus can be very different.
135
So if you're a state funded hacker, chances are you're going for sensitive data, confidential data,
136
top secret data, top secret data, meaning they have grave danger to a nation.
137
So you're going after those specific data.
138
And if you are a cyber criminal who was going after for financial gains, then you have a very different
139
set of data.
140
You could be looking for credit card information, username passwords, doohickeys set on a dark web.
141
So, again, the purpose, the action and the objective can be very different across many different
142
kind of threats, many different kinds of attacks.
143
So, of course, the question will be, if I'm a defender, I'm going on the blue team and I want to
144
protect against this cyber attack, what can we do?
145
So the whole idea goes back into the concept of defense, defense in depth.
146
So defense in depth means that we must always have a way of slowing down the attacker.
147
So if a state funded hacker or someone who is persistent in trying to get into enterprise, getting
148
a data, what we can do is to slow down the person as much as possible and keep changing to different
149
kind of security mechanisms or countermeasures that we have in place.
150
That will take a very long time for the hacker to go after you.
151
So if you're managing an enterprise, you may have thousands of computers and point servers and so on.
152
So what you do is you will actually make sure that you have antivirus systems, you have a security
153
monitoring platform, you have a web application, firewall database, firewall and many different of
154
these security mechanisms in place that will slow down your hacker.
155
So the hacker want to get in to you to USB and you realize that all of your end points have the USB
156
disable, then a hacker have to try something else in order to gain access into a system.
157
And this would take longer and longer for them to persist through in order to gain access into your
158
sensitive data.
159
So defense in depth is going to be a great way for you to actually stop many of these potential threats.
160
So, of course, there are some potential flaws with the whole idea of the cyber attack chain and of
161
course, thinking about a cyber Accutane is that the hacker has to go through every of this single phase.
162
But the reality is that that's not the case because the hacker could perhaps be able to get all your
163
usernames and passwords directly from publicly available information due to all the data breaches.
164
And from there on, they could immediately get access into many of your accounts and credentials.
165
So that could be a very quick way, because on point number two or seven steps must be successful for
166
a successful cyber attack to occur.
167
But that's not always the case, because once you got usernames, once you got passwords, you could
168
morph your attack into other ways or other objectives in order to gain other kind of sensitive data.
169
So, of course, on the finer point, the defender has seven opportunities to break the chain and minimize
170
data exfiltration.
171
So if you're playing blue team again, you recognize that you do have the advantage.
172
If we are trying to conceptualize playing defense in terms of trying to stop the hacker from gaining
173
full access or completing the full cyber attack chain.
174
So once again, I hope you learned something valuable in today's lecture.
175
So if you have any questions, feel free to comment below and I'll try my best to answer any of your
176
questions.
177
So we're going to, like, share subscribe the channel so that you can be kept abreast of the latest
178
cybersecurity Tiriel.
179
Thank you so much once again for watching.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.