BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Purple Teaming for Auditors and the Business\n   Whe
 n: Sunday\, Aug 14\, 11:30 - 11:59 PDT\n   Where: Flamingo - Sunset-Scenic
  Ballroom (Adversary Village) - [1]Map\n\n   SpeakerBio:Alex Martirosyan \
 , Senior Penetration Tester\n   Alex is a Senior Penetration Tester at Wol
 f’s IT Assurance Services\n   group where he’s responsible for coordin
 ating and conducting\n   penetration testing services for clients in a var
 iety of industries\,\n   including financial\, healthcare\, and software. 
 His expertise consists\n   of internal and external network penetration te
 sting\, threat emulation\n   exercises\, social engineering\, vulnerabilit
 y assessments\, cloud\n   security assessments\, and Active Directory secu
 rity reviews.\n   Additionally\, he has experience working with standards 
 from the\n   National Institute of Standards and Technology (NIST)\, the C
 enter for\n   Internet Security (CIS)\, and leveraging the MITRE Adversari
 al Tactics\,\n   Techniques\, and Common Knowledge (ATT&CK) framework. Ale
 x has over\n   three years of experience performing security assessments a
 nd holds\n   certifications from industry-recognized organizations such as
 \n   Offensive Security and Global Information Assurance Certification\n  
  (GIAC).\n   Twitter: [2]@almartiros\n\n   Description:\n   Security teams
  are often tasked with building a layered control\n   environment through 
 a defense-in-depth approach. Audit and compliance\n   teams may even requi
 re these controls to align to a specific benchmark\n   or framework. Unfor
 tunately\, the scenario often arises where these\n   controls are only put
  to the test when a real attack occurs leading\n   teams confused when res
 ponding to an incident. Assumptions are made by\n   all business units abo
 ut the operating effectiveness of the\n   environment. Remember when we al
 l relied on the perimeter firewall for\n   security a decade ago? We now h
 ave the same problem with heavily\n   relying on default configs within ED
 R’s. Business leaders may be\n   lulled into thinking that these tools w
 ill prevent sophisticated\n   attack chains by nation state adversaries an
 d meanwhile get burned by\n   lazy PowerShell tradecraft that goes undetec
 ted. These assumptions are\n   rarely validated through active testing or 
 standard day-to-day\n   activity due to the complexities of a behavior or 
 technique. From an\n   auditing perspective\, this is a critical hidden ga
 p that creates a\n   cyclical problem. We are maybe the only industry that
  provides\n   technical solutions that still requires customers to continu
 ously tune\n   and validate they are working as intended. Although the con
 trols may\n   align to a specific need on paper\, significant gaps go unno
 ticed\n   allowing attackers to achieve their end objectives. A purple\n  
  team/threat emulation exercise can help prevent this. However\, most\n   
 businesses are often unequipped to know where to begin.\n\n   Many of us a
 re not speaking the same language as the business when\n   attempting to i
 ntroduce the enterprise matrix from MITRE ATT&CK().\n   Further\, we have
  now entered an unfortunate reality where every\n   vendor\, tool\, and th
 ird party reference the framework. As an industry\,\n   we need to be able
  to use this framework in a concise and repeatable\n   manner. We also mus
 t be honest with the short comings of ATT&CK and\n   what it cannot be use
 d for. It is extremely enticing to fall under\n   several traps when attem
 pting to use the framework and perform\n   simulations internally. This in
 cludes playing bingo and not truly\n   understanding how techniques are em
 ulated in an environment. This talk\n   proposes an approach for how to us
 e existing free tools including the\n   Atomic Red Team library\, Prelude 
 Operator\, and Vectr to begin tracking\n   adversaries and testing control
  resiliency in an environment. This\n   talk will educate all business uni
 ts about the MITRE ATT&CK framework\n   and how it can be incorporated wit
 hin their assessments. To\n   proactively defend against cyber threats\, w
 e cannot rely on individual\n   experts alone. Many of us have been expose
 d to the ATT&CK framework in\n   some capacity. However\, as an industry w
 e do not have a clear way to\n   abstract specific detail from the framewo
 rk and align to our\n   businesses primary mission. The business from the 
 top-down need to be\n   able to understand how to conduct these types of t
 ests and why they\n   matter. Strong relationships between audit\, complia
 nce\, third-parties\,\n   IT\, and security lead to the most secure enviro
 nments. Everyone\,\n   whether on the blue team or red team\, plays a role
  in executing these\n   tests\, remediating\, and communicating results ac
 ross the business.\n\n   As assessors we build test procedures to identify
  gaps\, remediate\n   issues\, and retest just like any traditional audit.
  When examined\n   closely\, we are effectively quality assurance for cybe
 rsecurity. We\n   have specific playbooks of what adversaries attempt upon
  achieving\n   initial access. Think about the Conti Playbook that was rel
 eased and\n   translated earlier this year. We can leverage existing tooli
 ng to\n   emulate the identified behaviors in our environment creating a\n
    “data-driven” and threat informed test. Equipped with this\n   know
 ledge\, we can layout controls that allow the business to operate\n   and 
 provide assurances that an attack chain is mitigated. We have rich\n   and
  continuously improving public cyber threat intelligence reports\n   that 
 must be used in our programs. Public annual reports from Red\n   Canary\, 
 Microsoft\, DFIR Report\, Scythe\, and countless others all can\n   be use
 d to tune our controls against a specific threat. Security\n   professiona
 ls can emulate adversaries for cheap all the while\n   expanding budgets a
 nd showcasing their work to executives. My hope is\n   to be able to bridg
 e existing understanding of ATT&CK and provide a\n   path to reliably use 
 it regardless of size or complexity of an\n   institution.\n\n   '\n\n   1
 . https://defcon.outel.org/consolidated_page.html#FlamingoThirdFloor\n   2
 . https://twitter.com/almartiros\n\n\n
DTEND:20220814T185900Z
DTSTART:20220814T183000Z
LOCATION:AVV - Flamingo - Sunset-Scenic Ballroom (Adversary Village)
SUMMARY:Purple Teaming for Auditors and the Business
END:VEVENT
END:VCALENDAR
