Detection Dispatch (Alex's Version)

Red Team Wrote a Book on Evading You. Literally. feat. Dennis Chow & Michael LaSalvia

Alex Hurtado Season 1 Episode 7

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 1:04:25

Dennis Chow (Detection Engineering Director, back for round two) and Michael LaSalvia (red team lead) join Dispatch to talk about their new book, Evasion Engineering: Building Custom Red Team Tools for the Modern Defenses, and what happens when a blue teamer and a red teamer decide to write the playbook together instead of against each other.

In this episode we get into:

  • Why off-the-shelf adversary emulation repos are dying, and why building your own evasive tooling, not just running someone else's, makes you a fundamentally better detection engineer
  • The trusted advisor model: bringing blue teamers inside red team ops so trust replaces the us vs. them dynamic
  • The unmodified Kali header in a packet that blew a six month long campaign
    Shared fate as an operating model, borrowed from cloud providers, to stop punishing one side for the other's success
  • Go (open-source programming language aka Golang supported by Google) and cross platform payloads: why Windows only red team frameworks have difficulty in keeping up with cloud and identity based attack paths 
  • Their favorite chapters to write: low and slow exfiltration, and the hybrid packer that finally got past an EDR that wouldn't quit

Follow Dennis & Michael's work on:

  • Evasion Engineering: Building Custom Red Team Tools for the Modern Defenses — available for pre-order on Packt and Amazon https://www.amazon.com/Evasion-Engineering-Building-Custom-Defenses-ebook/dp/B0GKDC57S8
  • VM setup for adversary emulation & testing: https://github.com/Orange-Cyberdefense/GOAD

Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.

SPEAKER_01

Welcome back to Detection Dispatch, the show where we get some real people in the space to actually talk, some shop with me and with, in our case, today, each other. If you've been here for a while, you know today's first guest, Dennis Joe, has been on the show before talking about automating security engineering or automating detection engineering, basically building, you know, treating detections like the software CI CD process. And today he's back with a little bit of a different angle. And he brought his co-author, who's been on the other side of the fence are our friends over on the red team side. So welcome, Dennis. Welcome to the show, Michael. No, welcome back, Dennis. Welcome to the show, Michael, co-authors of Evasion Engineering Building Custom Red Team Tools for the Modern Defenses. Thank you guys for coming on. Hello again. How are you both? We could do a bit a bit of a popcorn intro and then and and we can get right into it.

SPEAKER_02

Cool. I'm doing all right. I mean, it's summertime. I've got my my uh trolling shirt on just for all of you. Ooh. And yeah, you know, ripper rifle. So, you know, you can get a nice, nice uh Hawaiian shirt with little guns inside, and it's pretty funny.

SPEAKER_01

Oh, wow. And it's looking very Hawaii. Although I don't I I don't think I've ever seen anyone in Hawaii with a gun. Hello, Michael. How are you doing? How's your summer?

SPEAKER_03

I'm doing pretty well. Summer's going uh good. Some family trips are raised, that's a good thing. And just uh trying to get back into swinging things. We just got back from vacation, so ooh, where'd you go? We go down to uh here it's ocean city, New Jersey, so it's a local beach here. Spent a week down with our family cheer, so it's been pretty good. And I'm just getting back and swinging things at work and trying to catch up on stuff.

SPEAKER_01

Nice. And first of all, I think some congratulations are in order for you both. Congrats on co-authoring a book. Uh Dennis, this is your second one. But Michael, is this your first book you've officially published?

SPEAKER_03

Yeah, it is. I gotta say, if uh if it was anyone other than Dennis, I might not have done it.

SPEAKER_01

Oh, so it sounds like he got you to do it.

SPEAKER_03

Well, he reached out to me. I was like, hey man, this is a great idea. And I I never realized how much work goes into it, especially when you're writing about something that doesn't really exist yet out there. Like anyone could really write on a topic, like, for example, like how to configure a IPS IDS or how to configure Cobalt Strike, but when you're actually developing something out of the air that doesn't exist and how you try and circumvent stuff, it it added a whole level of challenge in the whole writing style.

SPEAKER_01

Yeah, no, and and I mean it's perfect timing too. You're right, you're you pretty much hit it. It's there's not a lot out there on this purple aspect of it all. But you know, we're always trying to have the red and the blue team side really cross over and really build true uh adversary emulation type of defenses and detections, like and I I just don't see much out there. Uh so I think you guys really hit hit the hit the ground running in with in the momentum as well. So, of course, I want to hear more about how you got into the space leading into the red team side. What was that journey like?

SPEAKER_03

Yeah, so uh been doing it for close to 20 years now. Um kind of started off in the whole system admin side, did a little bit of the blue side for a bit uh when I worked for a company called Garnet, who was eventually bought up by Varassign. So I got the experience of work with those like Fortune 500 companies and seeing all those attack vectors coming in. It really made me think to myself, like, hey, I want to know how this is occurring. I kind of want to be able to do this. Seems pretty exciting. So I started pivoting at that point in time in my career, started focused more on the offensive security side, eventually getting to like the web pen testing, network pen testing. Then that cool word red teaming came about and uh started pivoting over to that and really focusing myself on that side of the house, developing teams, programs, tooling, stuff like that. That's been my uh passion now for the last few years.

SPEAKER_01

Awesome, very awesome. And where I'm trying to see where where did you meet Dennis along the way?

SPEAKER_03

I think we originally met some weird way on the internet years ago. Oh, internet friends, yeah.

SPEAKER_01

So not through gaming, not through your your games. No, not really gaming.

SPEAKER_02

It wasn't AOL. What was it? It was like I think it was IRC. I think we were like battling some sort of like rooting some bot or something together. Yeah, and then we stepped on each other's toes.

SPEAKER_03

Yeah, and just became one of those things like went from an internet thing, and then eventually, like years later, we worked together at uh KPMG. Um so it's like the first time I ever got to meet Dennis face to face, and my wife's like, You're actually meeting Dennis after all these years? I'm like, Yeah. So that was kind of cool. And then we just stay in contact with each other. I took a trip to San Antonio about about two years ago now.

SPEAKER_02

Oh yeah, I forgot about that.

SPEAKER_03

My wife actually hung out with him during the week while I was in class.

SPEAKER_02

Oh wow.

SPEAKER_03

So it was kind of cool um being ball to have the family meet each other too after all these years.

SPEAKER_01

I love I love I love meeting internet friends. I I did that uh from my gaming world and then also from meeting like internet friends from LinkedIn and or even Reddit. I I've been I've been con in con in a feed with uh with with in DMs with a with someone on Reddit for like at least probably like seven years. And I've never met with that, I've never met with her in person, but we're just sending each other, sending each other feeds. But it's it is a beautiful thing, but it can also go very sideways as well. Like I met someone who we hit it off online, but then on in person, I I just could not stand, I could not stand her.

SPEAKER_03

Yeah, I think my first DEF CON trip ever, I try to share a room with some people I met off of IRC. Yeah, it was a very scary and interesting decision on my part. Um yeah, that is brave, but the other one was just like the weirdest person ever. I remember locking my uh my my room at night to like make sure no one get in while I was sleeping.

SPEAKER_01

Oh my gosh. Oh my god, I'm so sorry.

SPEAKER_03

Yeah, so after that, I kind of started screening people.

SPEAKER_01

Let's start screening and doing background checks and OSINT checks on them.

SPEAKER_03

Yeah, yeah.

SPEAKER_01

Okay, Dennis, this one's for you specifically. I so last time we were talking about our alerts sucking and do your alerts suck and and and all of that. And I gotta say, has you know, you obviously you've spent most of your career on the detection side and and the automation side. Like, what made you want to flip around and start thinking about the offensive side? Was it the alert sucking piece?

SPEAKER_02

A little bit, just a little bit. Uh so you know, you know, uh I I don't know, Mike, I don't know if we've been known each other from the internet side, like for at least 10, 12 years or something? Probably more than that by now. Maybe, yeah, maybe more. So I have, you know, just like everyone else, you you start in the interest of security by maybe doing script kitty stuff and then eventually graduate to some sort of like junior pen testing like skill set. And so I kind of like wanted to go back to those roots. And you know, I like trolling the industry, so you know, why would anyone want to listen to a detection engineering director talk about red team tools? And I just kind of did it. I think Mike say, hey, you know, I'm using them as my guest in check. You know, is this still operable on the red team side? Is it, you know, is it really awesome? And then of course we continue this stuff. So that was part of the reason for this book.

SPEAKER_01

I I yeah, you will till this day, I will say that that episode, like, do your alerts suck, that's still one of my highest performing episodes, by the way. And you you're right, people know you as you know, Dennis, the detection engineering director, right? And uh, and and there's not a lot of, like you guys were saying, content out there, even on detection engineering alone. I think the first one was like Megan Roadie and Gary Katz, they they wrote their the like detection engineering. I don't I don't remember which oh I I forgot.

SPEAKER_02

It's like a lot of the elk and yara type creation and stuff like that, right? Yeah.

SPEAKER_01

Yeah. No, I mean talk about versatility. Like we we love to see it. I was not familiar with your game of being able to do both sides. It's almost like uh an ultimate flex is already knowing how to circumvent the detection that you just built.

SPEAKER_02

Yeah, I think I think also like we you know, we just love building tools on the Ospect side. I mean, Mike loves it, I love it. I think it's funny, you know, when you try out your experiments for the first time, you don't see the alert on like Windows Defender or CrowdStrike, and you're like, yeah. And then you keep it to yourself for a little while, and then you're like, okay, do I burn this payload somewhere else? And then then we thought about this for a little longer. We're like, maybe we need to like build things that are gonna be resilient even if you burn part of it. So that was also a part of this book as well.

unknown

Yeah.

SPEAKER_01

And and I'm seeing I'm seeing like, so you pretty much went on uh miter, the miter, what is it, the ingenuity, uh, adversary emulation, GitHub, and you were like, nah, none of none of this shit works. Like, I gotta build my own thing.

SPEAKER_02

Oh, absolutely. You know, I think everyone's using Cali, there's some sort of cobalt striped bootleg somewhere out there, and you know, it just doesn't feel right. I think in the spirit of just having fun and uh, you know, like I said, a little trolling the industry. Wouldn't it be laughed out loud if you just didn't use Lolbins at all? You just created your own tools and you had like the most Mimi Cats type capability without having to run Mimi Cats. You know, maybe it's Neoncat as your as your next tool, and then you created it yourself instead.

unknown

Yeah.

SPEAKER_03

Remind me of uh we were at a uh Spectre ops conference and uh someone renamed cat to dog and did the same thing that cat did, but it was just dog because he wanted just to troll and be different.

SPEAKER_01

I isn't isn't this what this all this is all about is just trolling and just figuring out something and then randomly you just come across it.

SPEAKER_02

Oh yeah, yeah, for sure. I mean brittle detections.

SPEAKER_01

Exactly. Well, that's a good that's a good point. Well, looking back on book one versus your your second book, not that it's a sequel of any sort, like they're they very much can operate standalone and you know they is they don't build upon each other, at least I think. But it's still, you know, your same brain, different hat, right? Did writing the offensive side change how you're thinking about the detection and automation work, like that you described in book one, would you say?

SPEAKER_02

Oh, absolutely. I mean, there's a lot of still good core fundamentals from book one. Detection is code, everyone knows CI pipelines down. I think it's kind of like a known foundation for Gee E people.

unknown

Yeah.

SPEAKER_02

Um, but then now I'm like, oh man, we have to be really accelerating how we experiment and create, you know, robust detections. And it's no longer just really good red expressions, it's no longer just good, really good machine learning and regression. Now you have to build whole genetic systems, which we've done, but then we have to build those uh at the same pace as Michael was creating payloads and exploits. And so, like to be able to build that is something I think we also need to be working on in the in the industry at large.

SPEAKER_01

Yeah, no, totally. I I want to get into the the why now as well, because I think you you you brought up that good point about now the agents are in the mix, and I think this also gets into that. Uh, question for both of you. The book specifically, the whole premise is you know, your your tooling is public, it's already known. Where did that idea kind of click for for each of you to start basically doing it now?

SPEAKER_03

Yeah, I I think for me, it had to be probably my last job, more so than any other jobs previously. Uh up to that point, I think a lot of our our blue team side, our sock side guys in previous roles were not as advanced as they are now. And I think as that as those roles have increased and the teams have become more well defined, has made our lives harder and harder. Then you bring in AI as well. So AI is now quickly identifying a lot of these items. Uh, you have behavioral analysis as well. So I download a file, I execute it within a minute, 10 minutes later, they're like, hey, those are two bad things, and what should I do about this? It was probably sitting there banging my head against the desk because we were using Cortex EDR, and no matter what we did, it constantly like, no, you're bad. You're bad. I'm like, dude, seriously, I just ran the who am I command? Like, that's the why you say I'm bad. But then it was basically saying, hey, five minutes ago, you went out to this website and you did this. And I was like, all right, so how do we overcome this and how do we start looking more like a normal system and not as an attacker? And how do how do we become more be able to hide better within the system there? But at the same time, as we were developing these tools and being able to hide and overcome, it took us a few months to really figure it out, like how to write these tools, how to start hiding, how to make them adaptable. But once we did, it it caused a whole nother problem. The idea of us versus you became a big issue. And we had to come up with a way, how do we keep our blue team, our purple team engaged and keep them educated as we go about this, but still not burn these tools at the same time. Um, because as soon as we burn that tool, we're back to the drum board, we're rewriting stuff. So as we started developing these tools, we had to make them flexible to be able to quickly change them to be able to do the next op if they burn those tools during that time frame. But at the same time, we didn't want the purple team guys to say, hey, this is not fair, or we don't want them to have that black eye. We want them to be our business partner and work with us through this.

SPEAKER_01

I think you touch on a good topic, actually, and that's red teams and blue teams are very commonly disincentivized from working together because you know, like on the red team side, you're thinking about it like, oh, well, if we share, you know, what we're about to do, then the blue team already knows kind of how to build the right detection. Whereas on the blue team side, your success often means it's their failure. It's like, oh, well, why did they get it past you guys? Right. So it it's it they should be working closer together and yet they're disincentivized. They're they're hesitant to fully disclose everything that you're doing because you're gonna you're gonna constantly try to circumvent each other. So I'm so it makes me so happy that you wanted to partner together and really kind of create this dance of the blue and the red better to to hence create purple. Yeah.

SPEAKER_03

Yeah, we created uh what we call trusted advisors.

SPEAKER_01

Okay.

SPEAKER_03

If you are part of the blue team, you found us, or you think you found us, and you can provide us some reasonable piece of data set, a log, a trigger, something, we will let you know if it was us or not, of course. But then you became part of our team too. So you joined the calls with us, you sat there, you had inside knowledge of what we were doing as we did it. So you could be our point of contact to feed it up the chain. So if alerts did pop up, you were their main point of contact. So that gave them that empowerment to say, hey, they trust me enough to do this, and I did a good enough job to find them. Let's go from there.

SPEAKER_01

Yeah. I I can't stress enough too, and and uh Dennis, you you probably feel this as well. Like I think any type of prioritized output is much more, it's better in the backlog priority than just someone, I don't know, re someone just gut from a gut instinct or looking at the news saying, okay, let's let's add this new detection. I think we would prioritize any kind of red team assessment over just headline chasing per se.

SPEAKER_02

Oh, absolutely. You need to involve it too, right? The whole point of time, right? PI plus DE is threat informed. This is the ultimate threat. And it's because we can prove it too. Not just prove it from a pen test perspective, but red teamers evade and prove it. I think I want to touch on like Mike's point there, which is the and your point as well, the incentivization of red and blue together. Some cloud providers have gone to shared fate. I think we adopted the same thing over here at UK, where our symptoms are aligned based on the total remediation and the understanding of that remediation as a collective. So we're not punished because Mike found so that bypassed us, or Dennis was able to stop Mike in this one instance. These are operational KPIs, but they're indicators, not root causes for anything else. And so we will look at shared fate instead, adopting that cloud model instead for that. I think for us, but this book was also about just accelerating. So as as Mike mentioned, like education, partnering, and whatnot, I feel like we have the culture already, but we needed to upskill quite a bit as we built a gentex stock from our last episodes. What else do your stock analysts do? And so you have to upskill them for like the solid year and some change to get to these new sets of foundations and tech stacks. And and so to challenge them further, build the CPS and continuously learn, evasion engineering was really our key to make sure that they really knew their stuff and detection engineering knew their stuff. So that's why we also kind of chose like the purple lish path as well.

SPEAKER_01

I love that. You're constantly every time I hear you, you're constantly upskilling your people. Like that that's just that just shows, you know, how great of a leader that that that you are. Uh I I do want to touch too on the moment when you realize like that those off-the-shelf frameworks that the the red teamer, the red teamer's you constantly make for like there is a lot of per uh, I would say, adversary emulation GitHub repos out there. Like what would you say is what's that mistake that you constantly see them making when trying to model after real life threats? Because not everything is gonna be to the T exactly how it's going to be in the real world, right, with these GitHub repos. So would you say that you'd you're building something that's more realistic to what a real threat behavior would be? Like, tell us a little bit more about like what you wanted to go fix, like that that the off-the-shelf shit wasn't doing.

SPEAKER_02

And I'll do a point reverse on the purple bluish side.

SPEAKER_04

Yeah.

SPEAKER_02

Well, we see people doing that, especially that's how you get caught in the pen test world. We see the red teamers getting lazy and they'll like not modify or do something, and they'll like run it through their agented harness, like claw code or something, and they're like, okay, let's see how far we can get. Well, you're not red teaming at this point, you're pen testing.

SPEAKER_04

You're pen testing.

SPEAKER_02

And so they they just kind of blast it all out, and it's just AI slot testing at this point. And so that's one major mistake that we see people doing now, at least on my side. And then they don't use they don't use AI to actually help them make informed decisions or informed decisions based on thread intel. And so they don't, they just take things off the news and go, this sounds like a good vulnerability pairing, let's let's go for it. And then they they rush into it. And so instead of taking their time and inspiring the computational power issues of the technical engineering teams, they're they're trying to get as fast as possible at the biggest thing as possible, and they're not focusing on those foundations needed to actually evade anything. So that's what I'm saying. I don't know about you, Mike.

SPEAKER_03

Yeah, I I think one of the big things there is you mentioned about the AI stuff. I feel in the rate team side, the offensive side of the house, we had like handcuffs on us for a while now, right? And I think in the last year, maybe year and a half, that's really come off on the offensive side because there's been a lot of uh concern about putting client data into any type of AI tooling to find vulnerabilities or address vulnerabilities where you guys are taking logs and stuff like that, and then using that to help you guys with signature detections, which I think was a little more okay with companies at the time. We're starting to see that those handcuffs come off in our field. Nice. We're starting to be able to take a lot more advantage of that. Um recently I started working for a consulting company where we have a lot of red tape about where we can use AI, where we can't use AI, which parts of AI are allowed versus not allowed. But as Dennison mentioned too, now that with AI, it's been making life so much easier to modify tools, to come up with new attack vectors, to build these applications on the offensive side to become quicker, smarter, more undetectable. So it's definitely greatly enhanced our capabilities. But to give a good example, you were mentioning about taking stuff from GitHub reposts and stuff like that. One of the good examples I noticed was we went undetected on this uh campaign for a good six months. And I was like, why haven't they found us? And like, we're basically uh tunneling our traffic through a VPN that was publicly available at the time, and we're just going and going. I was like, man, this should be throwing up a red flag, right? We're in a 10-dot network, we're sending 192 traffic out to the internet, and no one's seen any concern yet on this. And one day one of the team members came back to me on the purple side and said, Hey, we're seeing a Kali header inside this packet, and we did all this invasion just for that Kali header not to be modified in that host name string to give us away. And I'm like, How like where did you come apart that little piece? And it's just basically taking that off-the-shelf tool and not modifying in it that led to our detection. So I think when you're building your own tool sets and you're really understanding what you're doing, that's where it's allowing you to really think outside that box and circumvent a lot of these controls because a lot of the controls are looking for known signatures, known hashes, known actions where it takes that special soccer analyst there to say, Hey, this may not be bad, but when I'm digging into this, I'm noticing something a little bit out of the norm, and they can start digging a little bit further. And I think that's where that human side is probably always gonna outweigh the AI side of the house. And I think that's where we we have to kind of more uh understand it and use it as a tool versus have it replace people. Um I agree.

SPEAKER_01

I also find that those off-the-shelf frameworks are not surviving out there because they're predominantly Windows based. And like Dennis mentioned earlier, like if you're you're bringing more. Much a much more modern cloud focus on how to circumvent cloud controls and valid accounts and credential access, now that identity is like the perimeter, right? Versus versus just your Windows Meterpreter, Cobalt Strike, the the you know what we're used to.

SPEAKER_03

Yeah, actually Dennis um challenged me when we were starting to write a lot of that code. He's like, hey, as you write this code, it has to work on all operating systems.

SPEAKER_01

Yeah, thank you for that. Thank you for that. On Mac OS with the ESF framework. I know. I know.

SPEAKER_03

That was the funny thing too, because I was so used to using the Intel on my Mac, and then all of a sudden I got the new Mac, and I'm like, dude, nothing's working no more. I'm like, this sucks. So coding all that, thankfully I had a Mac, I could test it. I I think I was throwing my executables at Dennis, like, hey, run this on Windows for me until I went out and bought a cheap.

SPEAKER_01

You can virtualize a Mac. You can virtualize up to two Macs for free without licensing.

SPEAKER_02

Nice.

SPEAKER_01

Yeah.

SPEAKER_02

He he wanted to test to see if I was still awake or alive. And I think it was just a I think it was just punishment to me. Well, you learned a bunch of Go, didn't you? So don't complain at me.

SPEAKER_03

Actually, and that was the funny part too. Like using Golang, right? Golang's been out there for how long now? Years, right? But not everyone's using it. So just even a simple Go language executable is going undetected because no one's really writing stuff in Go.

SPEAKER_01

No.

SPEAKER_03

So like the fact that we could write something so basic and 99% of the ABs out there say, Oh, you're good to go. I'm like, that that's weird, man. So I when you pro when you presented that and I noticed that I was like, dude, this is somewhere to go. And I use Go to this day. Uh love. All the additional tools I've been writing and that I've been pushing out to my GitHub, all been Go-based because very little modification to go undetected by a lot of the EDRs and AVs out there.

SPEAKER_01

So it's it's still crazy. I'm still thinking about what you said. Like, how are they still finding Cali and then an environment? Like, don't we all know that don't we all know about Cali by now?

SPEAKER_03

Yeah, you would think so. But I I think it comes down to how those environments again spun up. I I think on my side of the house, I think as I I grew up and it came through all these different organizations, I'm just starting, I think, to hit those areas where we're starting to see such a well-defined, well educated uh SOC, right? I think a lot of the jobs I worked in in the past, they were still very immature, where simple things like that were just going undetected. And I think now we're starting to see this whole push. I'm seeing a lot of the stuff as Dennis is talking about, the uh powering his sock guys, stuff like that, where we're starting to see these larger scale operations, uh a lot more smarter people out there, a lot more focus on that side of the house. Back in the day, everyone wanted to be uh a red team or offensive security guy. Now we're seeing a lot of guys want to be, I want to be a defender, I want to find these guys, I want to figure out how to do this. And I think that's building these stronger programs out there where it's making our lives harder, and they're able to find us faster.

SPEAKER_01

Yeah. And I mean, because you've you've built out the red team, uh, you built out the red team at Fidelity and KPMG, and you've been in Pharma, you're you're at Protivity now. Like you've you've seen so many different size organizations, different makeups of teams. And even today, I just I was just speaking to someone recently, name, name, like literally household name, food, food and manufacturing, and they were saying how they manage eight different sentinel environments, and they they roll the same config to all seven of them. I'm like, but there's no way, like, there's some of them were kind of inherited through acquisitions. Everyone has a different makeup, like a different environment, different threat landscape. Like, how do you roll out the same config or based like I'm talking detection content rules, network hierarchy, like specific sim-specific stuff to all seven? Like, there's no way. And this is just like normal, normal operations. And I can imagine that's the same. You see you see, you see it's the same on the red team side. Old school companies that still operate very, very old school, I guess I should say.

SPEAKER_03

Yeah, it's amazing how many times we get on an engagement and you look and you're like, how does this still exist in this environment? Or yeah, it's really the question should be, why does it still exist in the environment? And then you look at it, like especially healthcare, right? You gotta understand, like healthcare, they're so regulated that a lot of stuff can't be updated for one reason or the other.

SPEAKER_01

Yeah.

SPEAKER_03

Or it may impact the patient or something along those lines. So it always comes down to not only are we being we're finding all these vulnerabilities, but how do we work with them too to help protect them? Because sometimes they just can't change them. And how do we then give that data over to the the SOC teams to say, hey, we know this can't be changed. What can you guys do with your tooling to make sure that attacker can't get there in the first place?

SPEAKER_02

Mike, I think you I think you bring up a great point on that, on the remediation portion. I feel like in the off tech spike, you remember this time too, when I was there. Most people didn't do a good job providing the remediation recommendations. They would give a one or two line blurb. We always think they were red team or pen testing, and they wouldn't give those nitty-gritty details, like admin on keyboard details of how to give them the both things for their book. Insert IPS here as your virtual patch. Like, who does that anymore? So I feel like we got to do a better job to harden and provide open source solutions whenever possible for this.

SPEAKER_03

Yeah, and I think that's one thing I'm starting to see a lot more too, now that I'm activity, is as we present our reports to our clients in our remediations, it's no longer like, hey, you need to implement uh least privilege, right? It's how do you go in there from a cloud aspect or AD aspect, and how do you actually configure that to provide that level of uh security configuration for that client? So uh we're starting to see that become more of a norm versus more of a more of a norm these days than uh what it used to be in the past for the level of details.

SPEAKER_01

Totally. Dennis, your your video cut.

SPEAKER_02

Let me rejoin. I think the Mac tried to update itself, so maybe Mike got into my system and didn't tell me.

SPEAKER_01

Um Mike, was that you?

SPEAKER_03

I figured he was playing with his kid or something.

SPEAKER_01

Damn, talk about headless operations because I didn't even see you typing.

SPEAKER_03

I send it to him on my phone.

SPEAKER_01

That's another another big topic. Um I'm I'm trying to connect uh my telegram to to to my Mac mini to my open claw, and I'm getting a bunch of detections firing saying like nothing should be connecting to Telegram. Um which I understand, but not unless you're unless you're prompting. Yeah.

SPEAKER_03

Nice. We're about to do a huge uh AI test for uh chat coming up in our next cycle, which is gonna be pretty interesting. So it's gonna be the first time we're really doing a lot of AI-based uh testing. So it's gonna be interesting how that works and trying to tie Atlas into it and everything else. So I'm hoping something cool comes out from that testing, like at least tooling-wise, when we're done.

SPEAKER_01

Well, selfishly, Michael, I I so I'm working on a detection right now that I'm I haven't really tuned, gotten it to a good tuning performance. Um so it's basically this it's subsequent access to the credential stores within a within a short amount of time, which is I'm trying to model info stealers on my Mac, but that's also what Claude is doing because Claude is accessing my credential stores in in a very short succession. And I and it's getting really tripped up by not knowing if it's Claude versus if it's an info stealer. Yeah, how how would you how would you go about that?

SPEAKER_03

I have no idea. I think if I was writing a tool around it, like at least for the detecting, that defeats the whole purpose to that point. I am not sure.

SPEAKER_00

It's good. It's like it's that's it's it's really good.

SPEAKER_03

It's a good one of the things we've been doing in our tooling, like to help the the stock side of the house too, to quickly determine if it's us or not, is we've been putting hidden signatures or hash in our tool so they're able to detect if it's us or definitely confirm it's us to do in the like unlikely that we're both on the same machine, like a true attacker versus us, that you could tell who did what.

SPEAKER_01

Yeah.

SPEAKER_03

We've been trying to hide some hashes in our tools to do that. So I would double check to see if maybe Claude has some type of hash or some type of signature that may be leaking to see that to separate the two.

SPEAKER_01

But yeah, I am not it's I will say it's it's been it's been a fucking wild ride trying to extrapolate rules out of the Claude Otel code versus Claude Otel co-work feed. Because it's it just gives you all this nonsense information about token usage, it doesn't really give you any anything prompt related because you're trying to uncover prompt injections and what people are prompting it. But Claude Otel is just so it's like the data feed is so shit.

SPEAKER_03

I need to look at that more. That and co-work, I gotta look at more. I just I recently just gave in and bought a Claude license, to be honest. Oh, wait, oh yeah, and I don't know why you didn't do a CNR. I kept asking myself, is it worth the money? Because I would hit the threshold and I would wait in it.

SPEAKER_01

It's worth the money. I'm telling you now, it's worth the money.

SPEAKER_03

No, ever since I paid for it, and like my wife's now, she's like, You paid for it? It's like, yeah. I was like, it's checking my emails, it's cleaning this, it's doing that.

SPEAKER_01

She's like, me you will never look back, you will never look back from it now. Like your life is much better now. Yeah, yeah, yeah. You don't want to get me started on Claude, Claude Code, Obsidian, Notion, like my setup there. It's wild.

SPEAKER_02

Oh man. If you're doing a Gemini, get the developer a premium, get skill boost with it, and Gemini Plus with that. So you get all in one as a as a developer plus advice for their like different trainings and stuff like that.

SPEAKER_04

Nice.

SPEAKER_01

Well, we broke we broke the rule of non non-salesy products on the podcast. And here we are, evangelizing Gemini.

SPEAKER_02

You were talking about OTEL talking mess about that. Uh, we used it for uh telemetry to actually look at runtime security of a gym tech. How else are we gonna catch a mic, you know, injecting and slow, slow injecting our rag system?

SPEAKER_03

Actually, there was uh actually uh there was just a LinkedIn post the other day, uh, or maybe it was this morning, Claude going from a GitHub repos hit up to a reverse shell in like five prompts. I I gotta see if I can find that feed again this morning. But I was like, what? So it's like he prompts Claude to create his GitHub and then Claude reads a DNS packet or something and executes the values that are in it, and then it runs the back door. I'm like, Where half half the time I'm reading these things, like, where did people even think about doing this in the first place? Which then I question myself, like, am I even skilled enough to be in this field?

SPEAKER_01

Like when these guys are thinking about this, I'm like Well, GitHub is on a really fine line right now, like right with exposing exposing some of the some of their internal or some private repositories, but also they just have not really been all that good of sharing of like the actual permissions and sharing and and what people are doing with their authentication and and and access, basically. I know that Julie Agnes has has written a lot about this, and I she's even like in talks with like the with GitHub support on on this, trying to push for for this or a request for enhancement. But it's true. Another thing too is I just can't imagine all the vibe coded projects out there that are living on GitHub, like you know how GitHub IO, you know how you can make some HTML sites public now without any kind of access token or anything. Like you can just literally make a GitHub public. And the all the the amount of vibe coded projects out there that have so many holes and vulnerabilities is I wow, like can't imagine.

SPEAKER_03

Well, it reminds me of the old days of uh like there's uh what was it, uh planning source code and stuff, or any of those like ask sites like hey, I need help writing this SQL PHP page, and everyone starts the same bad code, so everyone's copy and pasting the bad code, populating it across all their applications. It's I mean, is it the same thing, right?

SPEAKER_02

Is it any different than Stack Overflow and then Stack Overflow became the new Claude in this case?

SPEAKER_03

Yeah, yeah, that's why I was referring to Stack Overflow. I couldn't remember the name of the site, but yeah.

SPEAKER_01

Yeah, I feel like if you don't know what you're doing, like if you're just like basically just saying, yeah, allow, allow, allow, allow Claude to do everything, you're like pip installing all these packets that you don't even know it just just to just to get you to the the final piece of it, right? Because you know you have the end goal in mind. Claude has been really great at taking an idea to production, great, but if they don't fundamentally understand all the recs, they're just accepting all this like brew install things that they don't know about. Um and uh and and I don't know, like if you don't really know what all that entails, you should be building your vibe-coded apps in something more secure, like a like like a lovable, or like uh what what is the other one, Vercell or something like that? Like they they handle the security for you as opposed to just co cloud coding everything from start to finish.

SPEAKER_02

Yeah, I think they're but then they aren't these modern platforms that try to get those guardrails just agent as judge, so you have another LM judging you based on another LM's output, so it's like the whole recursive problem.

SPEAKER_01

Yeah, it it's true. It's true.

SPEAKER_03

That's why I like Procks. They don't give a crap what you type.

SPEAKER_01

Okay.

SPEAKER_03

If you want to know guardrails, go there.

SPEAKER_01

Wow. Why should blue teams care? So, like, I the think of this this segment of the podcast as like the purple team pitch. Why do we need you to still pitch purple team? I there's some there's they're still acting very siloed. So would you say that this book is technically shelved as a red team book? Like, is it more for the red team side or was it made more for the blue team angle? How can we make a case for why a detection engineer, which is a lot of this audience, should be reading it too?

SPEAKER_02

All right, I'm I'm learning because she's whack at this. You you can't you can't detect what you don't understand. And you certainly can't up your spiel unless you're going beyond, you know, the Fisher Price, my first regular expression of payloads and dirty word lists, right? There's only so much compute you're gonna reference over there. So you gotta learn your data science, you gotta learn scalable application of security, you have to understand the compute horsepower that goes beyond what we're doing in these strategies in this book to make yourself a highly resilient protection engineer. Otherwise, you're just copy pasting from the minor attack framework, and that's just you know, that's dumb sound there.

SPEAKER_03

Yeah. I think from our side of the house, from the offensive side of the house, is it was very important for me to understand how the blue team operates, how how you guys look for stuff, how your tooling works. I find myself a lot of times sitting there during uh debriefs or even during assessments, crash my head, like, hey, why isn't this running or what's going on? And then I would reach out to our counterparts, say, hey, what are you guys seeing here? Like, this is what this should be doing. Are you seeing any alerts or is this tripping somewhere? Can you help me troubleshoot what's going on, right? Like I can do a TCP dump all day long and look for it. But if your tool is doing something to the packet or it's not even getting there in the first place because something else is blocking it, like I need to understand that so I can better myself as well. So I think it's really important for organizations to realize we we gotta work together. And yeah, unfortunately, I feel a lot of times it's what you said earlier, right? It's us versus them, them versus us. And I think that really falls on leadership too. Like the leadership needs to realize, not to penalize one side or other for how detections occur or how the right team gets access, but celebrate as a whole, right? Uh there's no blame at all throughout the process.

SPEAKER_00

Yeah.

SPEAKER_03

And at the end, we all come together and do a full debrief, a full breakdown of what worked, what didn't work, how can we better it and go from there?

SPEAKER_01

Yeah. No, it's true. And a follow-up for you, Michael, like for someone that's only ever run someone else's framework, like Cobalt Strike and Metasploit, how how can we manage their expectations before they take a crack at this book? Would you say?

SPEAKER_03

So, like people that have only ever used those tools, you're saying.

SPEAKER_01

Yeah. Yeah, exactly.

SPEAKER_03

I think the biggest thing is moving away from the known uh hashes, right? The the known detection signatures, because that's not going to exist as people start developing their own tools until it starts getting burned. I think the biggest thing is starting to ask yourself why, or why do I see this, or why is that happening? And I think those who are really versed in like uh the admin side of the house, or those have grown up through the what I like to call the proper steps, right? Like you started off like help desk, you went to like the right of passage, yeah. Yeah, like you work your way up to these type of roles and you really understand what's going on. I think those are the people that's gonna really still excel at this because they're gonna be like, hey, I know this should be functioning this way. I know this is not what should be happening. Why is that? And then I always say, like, in our field, like it's easy, I can teach anyone how to hack, but if you don't have the mindset to do it, you're not gonna succeed at it. And I think that's all the same for uh your side of the house, right? If I'm digging into alert, I could teach you how to read Splunk, I could teach you how to run all these detection tools, but unless you have that will to say, hey, this doesn't look right, how I go about digging into this, what else do I have at my disposal to figure out what's going on here? And I think those are things that people need to start thinking about, not always just relying on the tools, that inner feel of say something's wrong, and going from there.

SPEAKER_01

Yeah. Sorry, sorry, go ahead.

SPEAKER_02

I mean, I gotta say, thank you, Mike, for saying that because it applies to both sides. Please, as an industry, please continue upskilling, please be curious. Yeah. Without that, you're not gonna be any good.

SPEAKER_01

Yeah, agree. Totally.

SPEAKER_03

Eventually, like as you already know, eventually the tools we wrote in this book are gonna be burned if they're not burned already. There are some people out there that already had access to this. Um, so there's probably people that have been playing with it. I even know as we finished up writing the book in what December time frame, there was a couple of people that posted similar topics out on LinkedIn that I'm like, whoa, that's a little too close to home. Don't release, like, don't release stuff yet until our book comes out. I'm thinking in my head. Push it on no stars to say, hey, get this out sooner before this is no longer relevant. So things do get burned out there. So it's always gonna be a cat and mouse game. I think we have to start moving away from the signatures, the hashes, stuff like that. We're gonna be moving more into behavioral analysis, more of like why things are occurring to really detect anything that doesn't exist currently. And it's always gonna be a cat and mouse game. Like there's no way around that unless AI replaces all somehow.

SPEAKER_01

It's a cat and mouse game, but it is much more impactful and better use of your time to model after a true, like a real exploit rather than just building a detection based off a report, a CTI report that may or may not have been written by a sim vendor and then just like hoping for the best. Like this is like a more of a resilient detection. I I gotta ask, how was your favor what was your favorite chapter? Uh, what was like the the most fun about writing it? Do you guys each have like a different? I'm curious to see if like your favorite chapter was different than each other.

SPEAKER_02

I've got mine. I I love low entropy encryption. It's just it's passed so many data exfil or signature-based items, even the outliers, it's just hilariously funny.

SPEAKER_04

Ooh.

SPEAKER_03

Yeah. I would say mindspire around the the hybrid packer because that was a real real life scenario for us. It was that moment where we were like, hey, cobalt's not doing what we needed to do, or VDEX, or any other tooling we were using was constantly detected, and be able to write that uh script to get our payload to actually execute and uh bypass that uh EDR. We're like, oh my god, this actually worked and it's actually usable and we're running. So I was like, yeah.

SPEAKER_01

So that really then no, I mean that that's a part of something's not doing the job, you gotta write it yourself. Like you gotta write you gotta write it yourself. Other other than just keeping on researching, maybe something similar that someone else has written out there, and that time you look for it, you could have just already written it.

SPEAKER_02

Well, yeah, we had Matt Burrow test us thoroughly because you know, Microsoft Red Team side, and all these tools that you see here, the methodologies that we do are based on our battlefield items. So everything that we used was a method or a variation of that method in the actual red team mods.

SPEAKER_01

I love that. I love that so much. That bull question for you then. If you connect the dots for us, how does building like this evasive tool yourself, would that would that make you like I want to hear in your own words, like how does that make you a better detection author versus just you know how how you were doing it before?

SPEAKER_02

I think it's because you have to figure out every piece of artifact that makes sense and what's economically viable at scale to figure out how you're gonna detect this not just across one user, but from tens of thousands of users and resource objects. And so it really pushes you to understand every piece of the forensic chain that you create. And then if you don't create something, then you don't instrument well. And so that pushes you to the next level, which is you don't OS laws are not enough. Syspon is not enough. You need runtime, you need application, and so how do you economically figure out how to get those logs or do you pull it? And so that really makes the detection engineer as a much more resilient and robust person, as opposed to here's my regular expression signature, push the prod, we're good to go.

SPEAKER_01

Have you seen this? And you, I mean, this will hit home for you, Dennis. Like, have you seen this have an impact on your precision and and recall and false positive ratios? Because I mean, the more specific you're kind of building your tool, the more specific of a detection it is, and maybe it won't.

SPEAKER_02

Yeah, I think when you move to from indicator to TTP, and Michael knows this very well as well, you let go of precision in terms of recall, and then what happens is you see a bunch of stock analysts complain about so many alerts. Well, that's why you gotta get to become a better protection engineer. What do you do with those alerts? Turn them into events, just like the old days. Yeah. Just based on the analyst uh composite detections, true correlation, not just, hey, I saw something and make an alert out of it. You have to make an actual attack change happen. And so when we're using these types of tools, yeah, you get by a lot of default vendor policies and out-of-the-box things, even as is, or even if you only took about 50% away from this book and made the other portion your own modification, it takes you a long way. And so we really on the detection engineering side, we gotta catch up. So build your own agents out there and use this book as maybe part of the rag as we create net new things.

SPEAKER_01

I will say, in the macro level, I the red team side is disproportionately resourced rather than the blue team side. There's been so much more investment in the AI side as well, in the red team rather than us. I go think we're a little bit under-resourced in that in that regard. So I'm really happy that we're we're level leveling the playing field. What would you say is the um a good starter pack to get started in this more adversary purple emulation side or game to your detection? Like you need probably like your Kali Linux VM, you need a Windows Server 2025, you probably need a Mac OS environment, a Windows 11 environment, and then just like go going going crazy, loading up all of your tools on there and just going crazy.

SPEAKER_03

I would say like uh if you if you want to keep it simpler, um out of the box, uh uh what is it called? Game of uh game of ad or that game of throne spin-off with Active Directory. I don't know if you've seen that that virtual environment, but that mimics a lot of enterprise environments pretty well. Yeah. I had that spun up to run the payloads and stuff in the background to just see how it functioned within the environment. So I wasn't actually worrying about where the payload went when we were developing them.

SPEAKER_01

I will be linking those in the show notes.

SPEAKER_02

Nice. Did you guys end up doing the S-bomb where you kind of had just in time infrastructure and application configuration as code when you spun up your your uh your playground or sandbox for this? Is that to me, guys? Yeah, that's that's to you. I'm I'm just offering another point of view. That way we can like reduce resources further and have you guys faster for that. It also helps us on the selection side. Uh so we're not spinning up like gobs of resources when you don't or you won't have anytime soon, like say a MacDOS environment.

SPEAKER_03

Yeah, so a lot of times now, like uh where I currently work, we we have uh a guy that's on the team, he's amazing at automating environments for us. So like we have a whole selection form, we can go in there quickly spin up whatever type of environment we need. So it's nice. Um so I I guess in that that sense, our tooling stuff is already pre-configured, and we just go in there, request it, and within like five minutes, we have whatever tool we need up and running, and then we copy whatever file we need to that machine and we're up and running. Which is, I guess, also at the same time, uh we keep them until our assessment's over. So if we ever need stuff working with a client, we can provide them data set off that box. So we probably could give them like a forensics type image to uh look at.

SPEAKER_01

But this is what I mean. It's it's it's unsymmetrically, asymmetrically, what's I don't know what the right grammar is. Resource. Like I don't think on the blue team side, maybe Dennis, maybe your team is different because you probably make a fabulous case for it. But we don't always have like these unlimited resources, VPS, right? Virtual private servers to spin up and test at scale with unlimited windows and 365 Mac OS licenses, and and then testing them across many, many, many different versions of Mac OS, right? And and and testing and having it be reproducible, let alone fast. And it it sucks because I wish in a perfect world we would have this unlimited, clean testing environment where we have all these snapshots that we could, even if we break, we can just revert back to the latest snapshot and it has everything loaded and uh and all of these versions to test it and build these resilient detections. I think that's you guys are better off than us on the blue team side. I've never had an unlimited supply of VPS money to do that.

SPEAKER_02

I don't know if that's the case. I think I think the red team side, they have to go watch their budget too. I think, I think it's fair now that we have cloud and you know uh Gin AI helping the blue team. So I think those are great reset for a lot of the cases. I think the reason why it felt like that asymmetrical resource issue for so long is that red teams and pen testers at a whole have to figure out how to be really resourceful with their stuff and they're very, at the minimum, very good at writing reports and communicating. Not so much when you looked at traditional SOC at the time. And so they never built, they never necessarily had to go and figure out how to do constraints. They bolted on a tool for many years, and now we're seeing that shift where they're building their own tools, they're experimenting with things, and they're bringing that knowledge back into things like detectionist code, and it's easier now, right? GitHub runners with ephemeral minutes are you know free for X amount of time. Cloud, even in the free tier, right, is is is pretty good. So I don't know. I think we're in a good reset stance now. We just have to shift that mentality instead of just saying, buy the latest and greatest awesome stuff, and then let's make massive compete for no reason. I think that excuses out the window nowadays.

SPEAKER_01

Okay, that and we're ending, getting towards the end of the show with on a positive note. I I like that. I like I'd like to do a little bit of a lightning round for between y'all both. So I'm just gonna like quickly go through kind of this or that, or and you just one by one tell me just basically answer the questions. Okay. First one is one that you would love to see operators retire for good.

SPEAKER_02

Still, stop using that. What I was gonna say. That was actually like getting brainwaves to you and just filling your ideas right there.

SPEAKER_03

Yeah, that was my favorite go-to tool back in the day, especially for downloading and circumventing uh like file uh like basically you're able to download files from anywhere with that thing because it was a trusted tool. And now as soon as you type anything cert you tell, even if it's a legit command, A B's like, no, you're not doing this. Damn. Trying to think of another good one. Uh I don't know, like when you could say a PowerShell LB uh LL soak in the invoke web expression. Well, yeah, I uh yeah, you know it's gonna get flagged as soon as you do it.

SPEAKER_01

Yeah.

SPEAKER_03

And let's move on.

SPEAKER_01

Schedule task. I'm surprised this one, this one's the one I always hear about.

SPEAKER_03

Actually, one of one of my favorites back in the day, what was it called? It was NFS or something. Uh it was a simple flag. You were able to hide data within a text file, not in the file itself, but it was like overshadowing the alternative data stream stuff. Yeah. Yeah. I can't remember. Oh man, I don't want to remember this now because we used to use all the time the CCDC to hide our executable in that and then basically copy the machine and then basically extract it out and always go undetected.

SPEAKER_02

Oh man, no, I'm gonna have to look this up now.

SPEAKER_03

I think it died though in '98. I don't think it can do it no more from what I remember.

SPEAKER_02

But yeah, well, it happened to be the same, it has to be the same file system as your destination. So if it was NTFS, you know, you have to worry about that going back through. Um, and then it was already serialized. Apparently, you could just use the redirect carrot and a colon.

SPEAKER_03

That's what yeah, basically that's what we were doing. Yeah, you were cycling the file into the file.

SPEAKER_01

Another one that's dying, I think, uh, is the macro enable, like the fuzzy, like when it shows up fuzzy. Yeah.

SPEAKER_03

Bring back paperclip.

SPEAKER_01

Right, clippy. Okay, second, two out of three. Most satisfying time that you've got caught mid-engagement.

SPEAKER_02

Anyone wants to admit that?

SPEAKER_01

Yeah.

SPEAKER_03

I would say it was satisfying in the sense because the drama that occurred from it afterwards.

SPEAKER_01

Politically, like politically turmoil, I see.

SPEAKER_03

It wasn't even political turmoil, it was like the fact that like the guy was so upset that he broke down and had to take a day off of work. Oh god. From it. We were in a social engineer engagement and it was like midnight, and we literally printed out fake IDs on pieces of paper. So, like a Florida fake ID, we copied the face in our faces into it because to get the help desk to reset your password, you had to hold your ID up to your camera. Now, help desk is over in India, like they don't know what our IDs look like, really. So we got a hold of someone's creds. We needed to reset the cred. So we called them, it was like 12 o'clock at night. We held it up. As they're resetting our password, the guy just happened to be awake at that moment in time, got noticed, he called in. There was an argument between the help desk guy, him, and us, like a triangle going on of who's the real person. Eventually, they did reset it for us, not believing him. And in the morning, there was a whole like uh SWAT call, like, what the hell happened last night? And he wasn't on the call, and we're like, where is he? And the CEO was like, Listen, he had a mental breakdown, he couldn't come to work today. And I'm like, seriously, over this, like it was just like one of those classic moments. I'm sitting there, I was like, I don't want to laugh, but I need to laugh. And my boss was looking at me, he's like, dude, what did you guys do? And I like I debriefed them beforehand. He knew what we were gonna do that night, but like when we explained exactly what happened on the call, everyone was laughing so hard, which made me feel even worse for the guy. But yeah, it was just just the perfect storm that happened at that time frame. And he was like our ace of spades, like his access was key to the kingdom at that time.

SPEAKER_01

Oh my god. I mean, I will say I've crashed out for less lesser things before. But can you imagine? Like, so Claude Tag just came out last week, right? Where now you can prompt it within a shared channel, and it can even you know write to you guys too. Imagine all of this dialogue happening in the shared channel with Claude Tag.

SPEAKER_02

Like flipping off Silicon Valley is some horrible thing that would come from that. Literally.

SPEAKER_01

What about you, Dennis? Most satisfying time you've you've been caught. Because you you spend some time on the red team side, which I which I'm sorry I didn't know about. I really thought you you've you've mainly stayed blue the whole time.

SPEAKER_02

So that was like I've come in now. You know, Mike Mike just shakes his head every time I switch over to the different sides for no reason. I don't I can't beat historias, so it's not gonna be nearly as fun, but it's comical in a in a really funny sense, in this fat sense. So I also did hospital pen testing for a long time too. But got in, and this was this supposedly PCI type of test engagement. Got in there, just wrecked the hell out of this parking garage system. I kept opening and closing the gate, and then I was doing uh changing of a credit card information, and supposedly it was non-product, turned off to be prod by accident, which is partially the reason why I got caught. And and uh the SQL logs were being spooled. The only reason why I got caught was because some DLP was turned on, you know, what that was unannounced, and they were skipped doing scans. And so they weren't, by the time the spools of these SQL files would go out and back up to these different NAS arrays or even the SAN systems, they were doing these scans before it actually compressed and encrypted that zip file or whatever they were doing with those tarballs. And so like I get caught in the most stupid way possible with just like piece of the idea going across the network that seems like you know, um stolen credit card data, and they eventually sit there and I'm like laughing out loud, sitting on the other side of the building uh, because I already compromised their cameras with default passwords and stuff, and I'm watching myself like open and close the gate, and these poor cars are trying to get out of the garage. I'm cracking the hell up. And so they're like, where the hell is the pen tester? And and they someone from security eventually finds me and he's like and they're like zooming in to my screen because I didn't have a privacy screen. And they're watching me do this shit in in person. They're like, and of course, the the security team is like, Yeah, we got him, we got him real good. This is what he was doing. I'm like, Yeah, only with IT's help and physical security's help did you get me. Otherwise, we had no laws for this.

SPEAKER_01

Oh my god. And this is this guy's just out there just still walking freak.

SPEAKER_02

We're both we're both knocking on wood on some of our engagements. Yeah.

SPEAKER_01

Oh my gosh.

SPEAKER_03

Um, you almost got tackled. Oh, that was great. Yeah.

SPEAKER_01

Okay. I've never been in a physical altercation, but I feel like the the job sometimes sometimes calls for a little bit of violence.

SPEAKER_03

He's there poking at this printer and everything, and it's looking pretty shady. And I see the security guard coming up. I'm like, oh Jesus. And before I could even say, I see the guy like rushing home. I was like, oh god. And then it's like, no, no, no, no, I'm I'm part of the team. Don't don't hit me. And I was like, oh god.

SPEAKER_02

Oh man, yeah, it was great. We had a mutual client at that point, and uh yeah, we weren't allowed to stay at that hotel.

SPEAKER_03

Yeah, we were yeah, and it was empty too, but we couldn't stay there.

SPEAKER_02

Yeah, yeah, it was fun. Well, we got them, we got them real good. We got like all their phone calls and stuff, so yeah, yeah, we got some nice transcripts from that.

SPEAKER_01

Yeah. The closest drama that I've kind of encountered in person was when there was like a box of of I don't know, I don't remember if it was external hard drives or just USB files that no one could track who sent them. And for some reason somebody brought them in. And then all of a sudden, like I guess someone got caught wind of it and figured out they have no idea who it came from and it could actually have been malicious. All of a sudden, like 10 people show up trying to find it. They're asking everyone. People are running around the office trying to find this, like this box. It was later found just like in the in the freaking mailroom still. It was it wasn't taken anywhere because it didn't say to to anyone specifically. But yeah, they still don't know till this day who who sent those USB drives.

SPEAKER_02

So what you're saying is go and denial service, your your stock team, and just dropping USB flash drives in the parking lot.

SPEAKER_01

Yeah. But how did it even get into the into the mailroom? Like it must have gone through the post.

SPEAKER_02

There was a lot of that too.

SPEAKER_03

Are the stock deltas? Stick like Pwn Expresses and stuff in the mail and like ship it to someone we knew that was gonna be out for a week and running off a battery pack. So basically it's sitting in your mail room, attached to your wireless network beating it out to us. Oh man.

unknown

Yeah.

SPEAKER_02

Did you did you 3D print when 3D printers started coming out and being affordable, like a casing? So you'd like get an admin and like send him or her a gift, and then it'd be from like the boss, and then like they would plug it into a it has to be a USB-A right into the network in there, and you know it's it's it's gonna be ultimately powered like a Raspberry Pi underneath. Nice.

SPEAKER_03

No, I I just used packing peanuts, so you wouldn't want to even take it out of the package in the first place.

SPEAKER_02

Oh man, but isn't it the ultimate troll when you got something that's like painted and looks like it's supposed to belong there? Uh I don't know.

SPEAKER_01

Literally. One thing you wish, Dennis, one thing you wish you've known before writing a book, one that maybe made book two easier. And then for Michael, maybe this one is now, I guess. What would you what were your what is your second book gonna be like?

SPEAKER_02

I'll get my answer first.

SPEAKER_03

I I don't know. I I think I'm gonna need some time before I think about a second book. Would I do it again? Probably. I would need to really sit down and think it out better. Uh there was a lot of challenges in my head as I got into this that I didn't really think about. Uh, me and Dennis had a whole debriefing before I got into this, like because he knows my schedule's crazy. He goes, Are you sure you got time to focus on this? And I'm like, Yeah, man, yeah, yeah. And I'm like, what the hell is going on?

SPEAKER_01

Well, selfishly, can I make some requests? Like, I think you got you could really do an interesting social engineering angle. I think you could do a very interesting claude hotel telemetry angle as well. Behaviors that act like info stealers that also act like AI agents, pretty much.

SPEAKER_04

Yeah, yeah.

SPEAKER_03

Yeah, I think a fun one, like a laughing one, like me and Dan's always joked about like just war stories, like little blurbs, like short reads in a book of just war stories.

SPEAKER_01

You don't think that people are gonna know that it's them and they're gonna be they're gonna be really pissed off?

SPEAKER_03

You know, I'm getting to the age now where like within the next 20 years I should be able to retire. So it's like maybe it's like when I go to retire, it's like that and all just put it out there and walk away, mic drop and done.

SPEAKER_02

Oh man. You know, I'm gonna I'm gonna force you to make that now as you've put it out there, just to see what would happen from the response. One thing I wish I knew before writing book one that made it easier for book two. Uh have have actually an AI help you with extreme concise grammar and you know what your publisher's template is, and look at the other books and how they forced those poor authors to write.

SPEAKER_03

You know what it's funny you say that, Dennis? There's actually an AI now out there to his poor publishers. What one of the books I uh one of the authors I follow for uh my uh EMP type story, survival stories I like to listen to, was talking about this yesterday, and he basically uploads the format in there and it does it. And I'm like, where was this a couple months ago?

SPEAKER_02

Oh yeah. Well, I mean, we were to be fair, we were trying to in our you know third and fourth revisions, you know, be prepared for all that stuff. And then like they'll have conflicts between the different editors, and it's interesting. Uh, the other thing is, you know, stop using dark mode when you're trying to write a book, you don't need your eyes gonna be blinded because you can't most of the time their books are gonna be black and white, and so it's just gonna be dark mode if you do all these strings and stuff like that. So they're gonna force you to use like the burning light of light themes all the time, and it has to be this font, complete pain. So get yourself three setup with their template on your your laptop ready to rock and just prepare for the ride.

SPEAKER_01

That's that's so good to know. You know what I you know what I would also have you try, Dennis. I why don't you use Whisperflow and then just have just literally talk talk your book, text like speech to text.

SPEAKER_02

I don't know if you want that either. We have a lot of like absurd comments when we things work and sometimes when they don't work.

SPEAKER_03

It's funny because like when I'm talking to Dennis, if I have a speaker, my wife easily goes, is that Chow? Just because like some of the stuff he says, I'm like, yeah.

SPEAKER_02

I feel like your store knows who I am too. Like you have regular customers, and so like he'll they'll be like, Is that that that's that guy, right?

SPEAKER_01

The agents, the agents can already see you coming from miles away. Well, thank you so much, gentlemen. That's been the episode, folks. Evasion Engineering Building Custom Red Team Tools for the Modern Defenses by these two co-authors here that have graciously blessed me with their with their deep dive into what it all took to bring this book to life. If this is your first time uh listening to Dennis, you should go back and check out his automating security detection engineering and listen to that previous episode. Uh, Do your alerts really suck? Because that I think is a good follow-on episode. And it's and I'm I I really hope that today inspired you to bridge more of the dance between the red and blue and the collaboration and fostering that can happen when these two teams come together. Michael, congrats again on your very first book. You're always welcome back to talk about those horror stories. They're always well received. Links to the books on PACT and on Amazon will be available in the show notes, uh, available now to pre-order July 7th. And uh, and also I'll link that really cool. What was that? The House of Dragon VM as well.

SPEAKER_03

The permanent game of ED.

SPEAKER_01

Game of ED, yes. That VM. I will link that in the show notes. Dennis and Michael, thank you so much both to you both for being here. Detection Dispatch, we will see you.