3 ms·
I disagree with this. In my experience we saw the red team use graph techniques to plot paths to high value assets over and over, where defenders were not even
by beardedwizard 2y ago
I disagree with this. In my experience we saw the red team use graph techniques to plot paths to high value assets over and over, where defenders were not even thinking about this approach. As soon as they did, they identified potential attacks before the red team launched them.
Smart teams will immediately adopt the red team technology that, for example, crawls AWS as a graph looking for paths to from low to high value accounts.
Its not a zero sum or sea change thing, but defenders absolutely can think more like attackers and leverage attacker tools more often in the act of defense.
- uberman 2y agoHow do you define and track high values assets? Perhaps in a list?
- Jerrrrrrry 2y agoHigh values can exist on different dimensions. The CEO is worth more in some ways than the HR lady. The HR lady is worth much, much more than the CEO in other ways. This added dimension turns the 1D list into a 2D map, or a graph.
- deleted 2y ago[deleted]
- soulofmischief 2y agoThis is why I think having separate red/blue teams or roles in a cybersec outfit is best, allow each individual or unit to fully utilize each technique most effectively and synthesize the results.