opsec-fails.md (4126B)
1 --- 2 title: "OPSEC" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/evasion/opsec-fails.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/opsec-fails.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # OPSEC 12 13 ## Infrastructure 14 15 * Use generic name for DNS, avoid company names 16 * Use wildcard (*) when issuing certificates to avoid leaking internal name 17 * Do not use the default certificates embedded in your C2: [elastic/Default Cobalt Strike Team Server Certificate](https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/network/command_and_control_cobalt_strike_default_teamserver_cert), [zeek/zeek_default_cobalt_strike_certificate](https://detection.fyi/sigmahq/sigma/network/zeek/zeek_default_cobalt_strike_certificate/) 18 19 ```cs 20 (event.dataset: network_traffic.tls or event.category: (network or network_traffic)) 21 and (tls.server.hash.md5:950098276A495286EB2A2556FBAB6D83 22 or tls.server.hash.sha1:6ECE5ECE4192683D2D84E25B0BA7E04F9CB7EB7C 23 or tls.server.hash.sha256:87F2085C32B6A2CC709B365F55873E207A9CAA10BFFECF2FD16D3CF9D94D390C) 24 ``` 25 26 * Disable staging endpoints or restrict the access 27 * Do not upload your stealthy binaries to VirusTotal or other online scanners 28 * Guardrails your payload to trigger for a specific user/domain/computer name 29 * Use a redirector, don't expose your C2 TLS stack to the web 30 31 ## Behavior 32 33 * Avoid calling commands such as `whoami` 34 * List your kerberos tickets 35 * Look for the owner of the process that spawned your beacon 36 * List your environment variables: dir env: and dir env:USERNAME 37 * Use a beacon object file (BOF) to bring your own whoami 38 * DCSync (Replication) is always done between domain controllers 39 * DCSync from machine accounts look more legit than with a user account 40 * You don't need to dump the whole database, the account krbtgt will grant you every access you need. 41 * Kerberoasting must use the correct encryption, RC4 is often the default in offensive tool instead of AES. 42 43 ## IOC 44 45 **Gophish**: 46 47 * Default `RID` parameter: [gophish/campaign.go#L130](https://github.com/gophish/gophish/blob/8e79294413932fa302212d8e785b281fb0f8896d/models/campaign.go#L130) 48 * Default `X-Mailer` header containing the `ServerName`: [gophish/config.go#L46](https://github.com/gophish/gophish/blob/8e79294413932fa302212d8e785b281fb0f8896d/config/config.go#L46) 49 * Default `X-Gophish-Contact`: [gophish/email_request.go#L123](https://github.com/gophish/gophish/blob/8e79294413932fa302212d8e785b281fb0f8896d/models/email_request.go#L123) 50 51 **Impacket**: 52 53 * smbexec.py is using a service to execute commands. In the earliest version, it was named `BTOBTO` but it has now 8 random characters. Change it to 10+ characters to break other correlation rules. 54 * psexec.py is based on a well known service released on January 2012: [kavika13/RemComSvc](https://github.com/kavika13/RemCom) 55 * wmiexec.py every command will be prefixed with `cmd.exe /Q` /c : [impacket/wmiexec.py#L127](https://github.com/fortra/impacket/blob/master/examples/wmiexec.py#L127) 56 57 **NetExec**: 58 59 * NetExec uses Impacket library, it shares the same IOC 60 * Kerberoasting search filter query all accounts: [NetExec/ldap.py#L931](https://github.com/Pennyw0rth/NetExec/blob/5f29e661b7e2f367faf2af7688f777d8b2d1bf6d/nxc/protocols/ldap.py#L931) 61 62 ```py 63 (&(servicePrincipalName=*)(UserAccountControl:1.2.840.113556.1.4.803:=512)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(!(objectCategory=computer))) 64 ``` 65 66 **AWS**: 67 68 * AWS cli is using Boto3 library, it sends a User-Agent containing the operating system version in every requests 69 * Kali Linux OS is raising an alert: [PenTest:IAMUser/KaliLinux](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-kalilinux) 70 71 ## References 72 73 * [DLS 2024 - RedTeam Fails - "Oops my bad I ruined the operation" - Swissky - January 15, 2024](https://swisskyrepo.github.io/Drink-Love-Share-Rump/) 74 * [Five Ways I got Caught before Lunch - Mystikcon 2021 - cyberv1s3r1on3 - November 24, 2021](https://youtu.be/qIbrozlf2wM)