4 ways your organisation can be hacked · • the ways your organisation can be hacked • how...

37
4 Ways Your Organisation Can Be Hacked Kennet Johansen Solutions Engineer Netwrix Brian Johnson Security Enthusiast / Podcaster 7 Minute Security

Upload: others

Post on 21-Sep-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

4 Ways Your Organisation Can Be Hacked

Kennet JohansenSolutions EngineerNetwrix

Brian JohnsonSecurity Enthusiast / Podcaster7 Minute Security

Page 2: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Housekeeping

• All attendees are on mute

• Ask your questions!

• Questions will be answered during

the session or at the Q&A at the end

• You will receive a copy of slides and

webinar recording in the follow-up

email

• Duration: Up to 60 minutes

We hope you enjoy!

Type your question

here

Click “Send”

Page 3: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Agenda

• Introduction

• The ways your organisation can be hacked

• How Netwrix can help to detect the attacks

• Q&A session

Page 4: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Who’s this guy?

Security engineer for 7 Minute Security

Podcaster Not famous Tiny movie star

Page 5: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer
Page 6: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

The story

Evil Eric Gordon got fired from Madison Hotels, Inc.

and he want revenge!

Can Netwrix help save the day?

Page 7: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Eric Gordon is angry…

Laid off for bad behavior

He wants revenge!

Can Billy defend the Madison Hotels network?!

VS

Page 8: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Eric’s hacking playbook

Attack the wifi!

Log into my old Active Directory account

Password spraying attacks

Try to add a new local admin account

Plant malware

Mousejacking attack!

Get domain admin access

Cover my tracks

Page 9: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Wireless attack – try old wifi password!

Page 10: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Wireless attack – get Wifite

Page 11: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Wireless attack – capture/crack handshake

Page 12: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Login with old account

Page 13: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Detected: Login with an old account

Page 14: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Eric’s hacking playbook

Attack the wifi!

Log into my old Active Directory account

Password spraying attacks

Try to add a new local admin account

Plant malware

Mousejacking attack!

Get domain admin access

Cover my tracks

Page 15: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Password spray attack (domain account)

Page 16: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Detected: Password spray attack (domain account)

Page 17: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Password spray attack (local PC)

Page 18: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Detected: Password spray attack (local PC)

Page 19: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Eric’s hacking playbook

Attack the wifi!

Log into my old Active Directory account

Password spraying attacks

Try to add a new local admin account

Plant malware

Mousejacking attack!

Get domain admin access

Cover my tracks

Page 20: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Plant malware

Page 21: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Detected: Plant malware

Page 22: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Detected: Plant malware

Page 23: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Eric’s hacking playbook

Attack the wifi!

Log into my old Active Directory account

Password spraying attacks

Try to add a new local admin account

Plant malware

Mousejacking attack!

Get domain admin access

Cover my tracks

Page 24: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Mousejacking attack

Page 25: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Mousejacking attack

Page 26: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Lets stop for a minute

If someone gained Domain Admin on your Active Directory right now…

Would you know?

Are you logging for it?

Could you respond quickly?

Page 27: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Undetected: Mousejacking attack

But…

Page 28: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Undetected: Mousejacking attack

But…

Page 29: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Undetected: Mousejacking attack

But…

Page 30: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Undetected: Mousejacking attack

But…

Page 31: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Mousejacking attack cleanup

Page 32: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Eric’s hacking playbook

Attack the wifi!

Log into my old Active Directory account

Password spraying attacks

Try to add a new local admin account

Plant malware

Mousejacking attack!

Get domain admin access

Cover my tracks

Page 33: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Conclusion

Netwrix alerts us to key events happening in our AD environment:

Password spraying

Login attempts to disabled accounts

New local accounts added to key systems

High privilege group membership changes

Malicious user behaviour – complete with video proof!

Page 34: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

About Netwrix Auditor

Netwrix Auditor is an agentless data security platform that empowers organisations to accurately identify

sensitive, regulated and mission-critical information and apply access controls consistently, regardless of where

the information is stored.

It enables them to minimise the risk of data breaches and ensure regulatory compliance by proactively reducing

the exposure of sensitive data and promptly detecting policy violations and suspicious user behaviour.

Netwrix Auditor

Page 35: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Useful links

Free trial: Set up Netwrix Auditor in your own test environment

netwrix.com/auditor9.8

In-browser demo: Run a demo right in your browser with no need to install anything

netwrix.com/go/browser_demo

If you want to learn more about Netwrix Auditor, register now for the upcoming Product Demo!

Page 36: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Questions?

Page 37: 4 Ways Your Organisation Can Be Hacked · • The ways your organisation can be hacked • How Netwrix can help to detect the attacks • Q&A session. Who’s this guy? Security engineer

Thank you!

Kennet JohansenSolutions EngineerNetwrix

Brian JohnsonSecurity Enthusiast / Podcaster7 Minute Security