10 ms·
Kali Linux 2023.1 introduces 'Purple' distro for defensive security
- criddell 4y agoDoes this distro have modern application sandboxing? For example, can I say which applications have access to my photos, email, location, microphone, etc...?
- nostoc 4y agoKali was running everything as root up to a few years ago, I'd be very surprised if this had application sandboxing.
- wkat4242 4y agoIt'll be very difficult getting most pentesting apps to work in a sandbox anyway. It was difficult enough to move away from root and a ton of things will still need sudo. But it's ok, this is not the kind of distro where this matters. It's not for general work and targeted at users that really know what they're doing.
- ChuckNorris89 4y ago>can I say which applications have access to my photos, email, location, microphone Kali distros are not meant to be run bare metal as your daily driver, but as VMs. They usually have very lax security setting as to not interfere with all the networking and security related apps provided. This makes them quite insecure by design versus mainstream distro like Ubuntu/Fedora. So don't put any personal data on them. We always spin them up as disposable VMs in their own VLAN, and nuke them after every encounter is over.
- wkat4242 4y agoI don't but when it comes to pentests we only do them internally and not very often either. I like keeping custom scripts and installed apps/python scripts because we'll usually need them again next time. Of course if you do constant engagements to external clients cross contamination is a big risk but we don't have this concern.
- ChuckNorris89 4y ago>I like keeping custom scripts and installed apps/python scripts because we'll usually need them again next time. You can make custom Kali images with your own tools. Or you can just put those tools on git and pull them every time.
- wkat4242 4y agoI know and if you're a full time red team pentester that would make total sense :) Our team is a little bit of everything which makes it harder to justify that overhead.
- criddell 4y agoThanks for explaining. I misunderstood what Kali was for.
- hitpointdrew 4y agoIf you are looking for a "pen testing distro" to use a daily driver check out Parrot Linux. https://parrotlinux.org/ https://parrotlinux.org/
- lucideer 4y agoProbably of less broad appeal but another option to add to the mix for anyone who happens to be running Gentoo is the Pentoo overlay https://github.com/pentoo/pentoo-overlay https://github.com/pentoo/pentoo-overlay The Github repo is also a nice browseable categorised directory tree of security tooling, including nice readable plaintext ebuild files listing the src urls for building each.
- 0x1f606 4y ago> but as VMs Agreed on all points but this one; Occasionally I'll run it bare-metal on an SBC like a Raspberry Pi as a dropbox or similar, though the SD-Card gets nuked shortly afterwards so I guess it's treated in a very similar "disposable" way as VMs are. I know that's being pedantic about your wording, but I thought it worthwhile mentioning that there are use-cases for it running outside of a VM.
- stirfish 4y ago>Kali distros are not meant to be run bare metal as your daily driver, Oh. I was looking for something that had some radio stuff preconfigured, saw Kali was basically a xfce debian, and have been using it as a daily driver for years. Should I not do that?
- neodymiumphish 4y agoKali devs know that people do this, so they've modified their processes to address it. If you know what you're doing with Linux, you're likely fine.
- sylens 4y agoKali is not really meant as a general purpose desktop OS. Everything runs as root, IIRC (been years since I was pentesting).
- bombcar 4y agoYou might be interested in Qubes instead - https://www.qubes-os.org https://www.qubes-os.org as this is more of a toolkit for security testing.
- shp0ngle 4y agoQubes is not Linux really. I mean it technically is Fedora apparently but the main thing really is Xen and hypervisor. You don’t really install apps on Qubes, you install entire operating systems as apps. If normal linux is giving you too many hardware headaches, Qubes has some next level issues.
- fsflover 4y ago> Qubes has some next level issues Speaking as one daily driving Qubes, the opposite is true. Whenever I have problems with Linux, Qubes allows to backup and restore it in a few clicks. It doesn't matter that Qubes is not really Linux. It runs Linux apps fine.
- lucideer 4y agoI've used Kali Linux quite a lot but, as a Linux user, I wouldn't recommend it to anyone who knows Linux. It's mainly good for: 1. Students studying an OffSec course (the creators / maintainers of Kali) as the course material is designed with Kali in mind. 2. Mac/Windows-using security professionals running Kali in a VM (or light/casual Linux users doing the same - i.e. users without a deep Linux knowledge/comfort*) For anyone more Linux-savvy* I would recommend simply installing the tools Kali bundles that you want to use. It can be helpful to have Kali as a VM if you want to trial/explore the curated software library, but for professional use people typically start to get to know the set of tools they're comfortable with / interested in. * Aside: for anyone surprised security-professionals wouldn't be Linux-savvy, knowledge is specialised. Even if you are working in Linux-specific security (& not just using Linux cli tooling to access MS networks or decompile MS binaries), areas of security focus can still be quite compartmentalised.
- Arch-TK 4y agoCan confirm, as a security consultant I just use debian(ish) with an archlinux container (or sometimes VM) with all the stuff I need. This is far more sane for me than dealing with the bizarreness of kali. All my coworkers who are windows users are happy with it though.
- lucideer 4y agoI'm really grateful for distros like Kali / Parrot / Pentoo as they act as a (much more selectively) curated list of tooling akin to those "awesome lists" on Github, as well as being a rallying point for the maintenance of those same tools. But yeah - the tools are available individually & this is how I typically use them.
- archi42 4y agoOn Arch there are also the Black Arch sources.
- lucideer 4y agoA new one on me, thanks!
- AbraKdabra 4y agoIf you have photos and personal stuff in a Kali installation you're doing it wrong, Kali isn't supposed to be a day to day OS, some time ago your default credentials were root, so yeah, they changed it some versions ago but still, that gives you a look as how it should be used. EDIT: If you want a daily driver OS but need some Kali tools without installing it as a second boot or VM you can use the Kali Bundles which are repositories ordered by type of tools.
- antmldr 4y agoYeah, it's an unfortunate titling of the HN post. Defensive means something different in this context - it's meant for people working within the defensive roles of an organization's infosec department. Kali are a little to blame here for that confusion as well - "We are making enterprise grade security accessible" - is open to misinterpretation of what they are presenting.
- unethical_ban 4y agoThis looks really interesting. If nothing else, it lumps a lot of cool tools together so that I can research them! Also makes me think of building a proxmox datacenter at home just to play around. or trueNAS Scale... any experience with that for hyperconverged labs?
- candiddevmike 4y agoWhat is your definition of hyperconverged? How many physical servers are you talking about? You can get really, really far with just libvirt.
- yjftsjthsd-h 4y agoIsn't hyperconverged just when you put compute/storage/network/whatever in the same box(es) and virtualize it all together? There's no inherent scale to that, it's just a structural thing.
- yabones 4y agoYeah, it's a word that just describes using Ceph or DRBD with Libvirt on top and connecting the machines together with good old fashioned VLAN trunks.
- wkat4242 4y agoYeah that happens too much. Just marketing. When MDM (mobile device management) expanded to also include Windows and Mac most vendors loved branding it as UEM (unified endpoint management) as if it's a totally new thing and theirs is so much better than the competitors. But it's the same stuff just applied more widely and even vendors still referring to MDM are supporting these platforms. I hate it when marketing people through up hot air like this.
- unethical_ban 4y ago"hyperconverged" is easier to pronounce than "data+network+storage running on the same software stack on commodity hardware"
- PenguinCoder 4y agoWhats the difference compared to something like SIFT workstation? Seems like this is geared more towards training images and enterprise level aggregation vs being a DIFR type workstation with analyst tools.
- unixhero 4y agoDoes there have to be a difference?
- bee_rider 4y agoHow do BSD and Linux compare on the defensive in 2023? Has the larger community finally spent enough eyeballs to catch up with the better foundation?
- wkat4242 4y agoLinux obviously gets a lot more attention but it's also more fast with new features and possible exploits. BSD maintainers are fast fixing known exploits but has the drawback of older tech like X11. Wayland works on FreeBSD but still doesn't work with KDE on it.
- thewataccount 4y agoTBH Wayland is rocky on linux too from my experience. It's really hit or miss with applications especially electron ones. I think electron natively supports wayland without adding a flag now? The issue is most applications don't use that version yet. Both me and my friend installed wayland on a fresh arch install and we both had issues with random "black boxes" on electron applications. Games are also very hit or miss. IDK it's just felt very half baked. And this was with Gnome which my understanding should have very decent wayland support?
- freedomben 4y agoInteresting, I've been running Wayland (Fedora) for years now and the only issues I've ever had were application compatibility (rather than bugs). Screen sharing is the big one. Which GPU do you have? Wayland on nvidia is definitely more buggy than wayland on AMD and Intel, so if you run nvidia that could definitely be a factor.
- petepete 4y agoEven screen sharing is mostly solved now. I do it daily without issue on Fedora with Wayland. The only thing concession I need to make is running Slack in a browser tab instead of the app, because the app comes with an older version of Electron.
- veganjay 4y agoI'm a little confused as to running the Suricata, Zeek and the Elasticsearch stack on Kali. I think of these tools run on a server, rather than a desktop. And it seems like SecurityOnion scratches this niche. I do like the idea of Kali Purple though - curious to check it out.
- _8j50 4y agoYeah, very unusual. Purpleteam is usually over some prod or prod-like environment. I think they want you to put this in your purpleteam lab not as your actual defensive stack. Might work for some folks but imo, the logging/detection/alerting part should alway be your actual prod stack but you can simulate attacks in a lab environment. What I have seen in the industry at large is a lot of purpleteam excercises are done in production, a red team excercise blended with a blue team investigation and response.
- milkshakes 4y agoThese tools (-elasticsearch) run on a server that's usually connected to a network tap that collects traffic from endpoints and servers alike. Running them locally, a tap, and a server are unnecessary.
- mr_toad 4y agoIf you have local logs and you’re not in an enterprise environment it makes sense to analyse the logs locally.
- wronglebowski 4y agoIMO this is lowering the barrier of entry to newbies. I work in this space and often users coming out of boot camps that want to set up their own labs for learning have a steep learning curve. Such is the difficulty with entering cybersecurity without an IT background, for better or worse.
- lorenzo95 4y agoFrom what I can tell they call it a soc in a box. They have a wiki on how you are supposed to build it (on proxmox). Here is a link to their architecture diagram for it. https://gitlab.com/kalilinux/kali-purple/documentation/-/raw/main/pictures/Kali-Purple-03-Architecture.png https://gitlab.com/kalilinux/kali-purple/documentation/-/raw... It is intended mostly for training purposes. I think it looks pretty neat for a start. We'll see where the community takes it over the next couple of years.
- cjbprime 4y agoThis looks good! What do people use for fast indexed search of pcaps? (Contents, not metadata.)
- aviditas 4y agoI like Arkime (used to be called Moloch). My only pet peeve is that the documentation for the search bar is not separated from the tool. Their site docs tell you to go to the tool instead of just having the information mirrored. But for large scale pcap analysis that still lets me look at individual packet data.. it's my first choice.
- cjbprime 4y agoThanks, do you recall how to do e.g. a full TCP payload text search across all packets? Didn't find it with a quick search.
- tepitoperrito 4y agoIn the defensive security space there is also Kicksecure[0], which serves as the base for Whonix (a hardened linux distro that tries to provide strong privacy/anonymity via the Tor network). They have a wiki that goes over the desktop hardening features and tweaks that go into it. [0] https://www.kicksecure.com/ https://www.kicksecure.com/
- Ecio78 4y agoWhat about Security Onion[0] ? Can anyone comment/compare? [0] https://securityonionsolutions.com/software https://securityonionsolutions.com/software
- jdironman 4y agoWhy would the ISO for this be unbootable on vmware vsphere? I've verified the checksum that all looks good. Attaching it to a VM and setting it as connected on start up etc and it still cannot find a bookable device. Frustrating because I really wanted to try thos out. I set VM hardware to Linux Other 5.x 64-bit too.
- elboulangero 4y agoWhat version of VMware sphere? Are you talking about the installer for Kali Purple, or the installer for "standard" Kali Linux? Please open an issue at https://bugs.kali.org https://bugs.kali.org to keep discussing it. Thanks!
- jdironman 4y agovSphere 7u3k (both esxi and vcenter). And it was the ISO installer for Purple. I tried downloading both via torrent & direct, uploaded to datastore, attached to a newly created VM and nothing. I'll try attaching it to an already working Linux box and see if it shows up there to rule out environment issues if possible. I'll open a ticket as well. Thanks!
- jdironman 4y agoJust an update, submitted it: https://bugs.kali.org/view.php?id=8222 https://bugs.kali.org/view.php?id=8222
- ar9av 4y agoWhy are they calling it purple if it's really blue? Also, elastic is one of the worst siems you can choose for threat hunting and analysis. The language is incredibly limited, the parsing is confusing, there's no no built in aggregations that make sense, you can only search over one set set of data at a time (no joins). And it's even more limited through the search bar in the kibana GUI. Lastly, it uses techniques that estimate data results for the sake of speed. It does not guarantee full accuracy when returning data. Arkime full packet capture? Full packet capture relevance has faded greatly since the early 2010s due to encryption. It's all about host based logging like EDR, sysmon and windows event logs, while shored up by specific cloud-based app logs, or pulling forensic artifacts with osquery (or similar). People aren’t writing or looking at suricata rules much anymore, unless you're lucky enough to have an environment being proactively man in the middled, which is rare. This is a pretty interesting distro, but don't expect to be up to date with modern threat hunting, soc analysis, incident response or threat detection. It could be a nice intro in college, but you'll want to get modern data sets into real siems or DBs asap. The final thing I have to say is that purple team is not a set of tools. These are all blue teamer tools. Purple team is when a red teamer works directly with a blue teamer to create an attack and watch how the blue team systems and people react when it's happening. It's a drill that captures misses.
- ZeroSolstice 4y agoArkime full packet capture? Full packet capture relevance has faded greatly since the early 2010s due to encryption. It's all about host based logging like EDR, sysmon and windows event logs, while shored up by specific cloud-based app logs, or pulling forensic artifacts with osquery (or similar). People aren’t writing or looking at suricata rules much anymore, unless you're lucky enough to have an environment being proactively man in the middled, which is rare. I have to disagree here. Meta data on an actual session is useful for statistical inference and can be used for pattern matching at a larger scale on the network. IP addresses and file hashes are going to change frequently and be abandoned so sending out block lists to all your EDR software is more reactionary than proactive. Malware delivery/interaction observation through session data such as protocol, packet size, timing can all be used as features for detection. Additionally Suricata rules can be stacked using flowbits to provide correlation and actionable alerting on observed traffic outside of just the payload, url, etc. Lastly, having a data point outside of the end point device within the network is useful in the event of an incident, after all how can you trust logs and events being reported from a system that has been compromised. Arkime also can utilize the eve.json log file from Suricata to tag the same observed traffic allowing you to search by SID. Exporting data is probably one of the bigger features as that allows you to aggregate and analyze the data externally in something like Jupyter notebook. You should check out FloCon put on by CMU. https://resources.sei.cmu.edu/news-events/events/flocon/index.cfm https://resources.sei.cmu.edu/news-events/events/flocon/inde...
- mavam 4y agoThe heavy lifting of this is CISA's Malcom [1]. Unfortunately the blog posts only provides a non-linked bullet to it [2]. Seth Grover, the main driver behind Malcom, put a lot of effort over the years into creating a turnkey soc-in-a-box distro that works especially well for an network-first approach. Endpoint isn't neglected, but the focus on Zeek, Suricata, Arkime shows the primary visibility drivers. This is not surprising, because CISA also developed a bunch of custom ICS protocol dissectors that provide visibility (DNP3, Modbus, etc.). The list is impressive [3]. All of this is turnkey available by running Malcom. Especially for OT, where we have a lot more unmanaged black boxes and networks that you don't wanna actively scan (factories have been brought down this way), passively watching is a safe and powerful approach. It's a bit unfortunate that Kali didn't give the props to Seth's project (not even an outbound link). Perhaps this was just an oversight, or a spotlight blog post is coming later, but I hope that the history of this gets properly acknowledged, because it's darn clear where this comes from. [1]: https://github.com/cisagov/Malcolm https://github.com/cisagov/Malcolm [2]: https://www.kali.org/blog/kali-linux-2023-1-release/ https://www.kali.org/blog/kali-linux-2023-1-release/ [3]: https://cisagov.github.io/Malcolm/docs/protocols.html https://cisagov.github.io/Malcolm/docs/protocols.html
- cookiengineer 4y agoI wish there was also wazuh [1] included. That's where open source EDR is currently at. Sadly most EDR tools are just another ELK dashboard (wazuh included) and I think that has to change. [1] https://wazuh.com/ https://wazuh.com/
- dawson 4y agoIs there an ARM/apple silicon ISO available for Purple yet?
- michaelmcdonald 4y agoNo official release for that architecture just yet.
- anthk 4y agoFor security, a custom Guix spin with an ad-hoc configuration for pentesting would have far more sense.
- gorillamonsoon 4y agoanyone here using a mac have an issue downloading the iso and making a vm with vmware? every time i try to do so, i open up the vm and it stays on a black screen with a message stating, ">>start pxe over ipv4." any solutions to fix this?
- michaelmcdonald 4y agoUsing an Apple Silicon Mac? I'm seeing the same and my research is showing that it's an issue with the virtualization.