×

SecPgh's video: How to Frustrate a Penetration Tester - Justin Forbes

@How to Frustrate a Penetration Tester - Justin Forbes
JUSTIN FORBES Over the past several years, most penetration tests have shared several common steps in the attack path. These commonalities between engagements allow penetration testers quick access to critical systems and lead to full network compromise. Most penetration testers, and attackers, will work only as hard as necessary to complete the objective. By forcing them to work harder, organizations will either get a better report or discover they need a better pen tester. This talk will examine some of the typical ways in which a penetration tester might approach an engagement, including anonymized stories from real assessments. We will look at common initial access, privilege escalation, and lateral movement techniques. For each technique, we will look at how to detect an active attack. Additionally, we will apply the concepts of defense in depth to identify multiple overlapping, preventative measures which can be used to stop the attacks. By implementing the discussed detective and preventive security controls, a penetration tester cannot rely on the same techniques used in years past, ultimately forcing the tester to work harder. Justin Forbes is the team lead of the Applied Network Defense team at CMU/SEI/CERT. He has been leading penetration testing teams for the past five (5) years targeting federal, state, local, and critical infrastructure organizations. Justin earned his Masters in Telecommunications from the University of Pittsburgh in 2010 and his Bachelors in Information Sciences in 2008. His typical Primanti Brothers order is the ragin cajun chicken sandwich and a tall IC light.

4

0
SecPgh
Subscribers
260
Total Post
89
Total Views
479
Avg. Views
43.5
View Profile
This video was published on 2019-07-14 11:45:33 GMT by @SecPgh on Youtube. SecPgh has total 260 subscribers on Youtube and has a total of 89 video.This video has received 4 Likes which are higher than the average likes that SecPgh gets . @SecPgh receives an average views of 43.5 per video on Youtube.This video has received 0 comments which are lower than the average comments that SecPgh gets . Overall the views for this video was lower than the average for the profile.

Other post by @SecPgh