jymcheong / OpenEDRclient

Open Endpoint Defense & Response
Other
0 stars 1 forks source link

Deceptive Internet Kiosk #8

Closed jymcheong closed 3 years ago

jymcheong commented 3 years ago

What & Why

What Why
Limited Functionalities
eg. purpose-built terminals like Info-boards/signages, hospital-terminals running web apps...
Consistent use-case profiles
Eg. check emails, surf/use web-apps, printing & so on
Auto-Recovery (reboot to a clean state) Reduce remediation effort
Free, low-resource & turn-key Deception Deter Malware (20% are Sandbox aware) & APT actors alike

Let's turn the table!

How

Install OpenEDR Backend & Frontend

Install Reboot-to-Restore Tools

Turn Internet Kiosk into a "Malware Analysis Sandbox"

  1. https://github.com/NavyTitanium/Fake-Sandbox-Artifacts
  2. https://github.com/Phoenix1747/fake-sandbox

is-that-a-human-no-dont-worry-its-a-scarecrow-55630801

Careful adversaries who bothers with Opsec will check, the question is with what techniques when foreign executable-files are denied.

Outcomes

Improve Signal-to-Noise Ratio

I pioneered in a number technical deployments of larger-scale (a few hundred Ks Events-Per-Sec) Security Ops-Center for my workplace. Many SOCs that are stuck with "SIEM 1.0" are still wasting time with "noise".

I have done some profiling for various MS-Office version-applications, have yet to see Word, Excel & Powerpoint creating a child process. Only Office setup/licensing process was sighted to create child processes.

Living-off-the-Land Techniques will Stick Out

Let's say Advance-Persistent-Threat Actors get into the endpoint & establish C2, all without touching the disk...

ITCrow

Sense-making is not just about products but methodology & tooling to provide clear awareness of your assets' profiles.

What's Next

What if you really like this idea but don't operate a fleet of "kiosk"? What about non-technical office or even remote work-force?

Next up, how to adapt Sandbox for non-kiosk use-cases!

jymcheong commented 3 years ago

Will usually reserve such fun projects for Interns. But COVID has made such arrangements challenging.