Hack the SIEM and Win the War Many Thanks to the Following... All - - PowerPoint PPT Presentation

hack the siem and win the war many thanks to the following
SMART_READER_LITE
LIVE PREVIEW

Hack the SIEM and Win the War Many Thanks to the Following... All - - PowerPoint PPT Presentation

Hack the SIEM and Win the War Many Thanks to the Following... All the people that taught me this stuff Who the hell is this guy? In The Beginning... And Now And The Hits Keep On Coming What is a SIEM? I dont know either but Ill sell


slide-1
SLIDE 1

Hack the SIEM and Win the War

slide-2
SLIDE 2

Many Thanks to the Following...

All the people that taught me this stuff

slide-3
SLIDE 3

Who the hell is this guy?

slide-4
SLIDE 4
slide-5
SLIDE 5

In The Beginning...

slide-6
SLIDE 6
slide-7
SLIDE 7

And Now

slide-8
SLIDE 8
slide-9
SLIDE 9

And The Hits Keep On Coming

slide-10
SLIDE 10
slide-11
SLIDE 11

What is a SIEM?

I don’t know either but I’ll sell you 2 of them

slide-12
SLIDE 12
slide-13
SLIDE 13

Why is it Weak?

Have you ever tried to patch a SIEM?

slide-14
SLIDE 14
slide-15
SLIDE 15

Because this is your consultant

slide-16
SLIDE 16
slide-17
SLIDE 17

And this is their company slogan

slide-18
SLIDE 18
slide-19
SLIDE 19
slide-20
SLIDE 20

Why Target It?

slide-21
SLIDE 21

Because it has its hands in everything

slide-22
SLIDE 22

Seriously, how many servers does it take to make a SIEM?

slide-23
SLIDE 23

Now let’s abuse it

slide-24
SLIDE 24

The Attack

Recon Exploit Collect

slide-25
SLIDE 25

Recon

Check the Vendor Site

Under the customer section you will have all the targets you ever need

Documentation

You need the tech specs, specifically the API ports.

Check the Forums

Super strict member policy

Go to a Conference

Because we all know hotel wireless is frickin locked down.

Sales Engineers

You can spear phish or find them at a bar, it all amounts to the same thing.

Get a Free Version

Maybe...but you have to ask nicely

slide-26
SLIDE 26

Say What????

slide-27
SLIDE 27

Exploit / Collect

Cred Reuse

This is always a thing

Default Creds

Cause Admins are lazy

Um….Lots of Stuff

Seriously, a metric F*** ton

API

CURL, CURL, CURL

Interface

Nothing to see here, just another user...

But Do You Need To?

Probably Not

slide-28
SLIDE 28

DEDEMO

slide-29
SLIDE 29

THANKS!