DEF CON 26 PACKET HACKING VILLAGE = Sen and Sinturk - Normalizing Empires Traffic to Evade IDS
1,710 views · Published 15 November 2018 · 21:42 · Indexed 30 September 2026
Channel: DEFCONConference · 2018 · Science & Technology
Perimeter defenses are holding an important role in computer security. However, when we check the method of APT groups, a single spear-phishing usually enough to gain a foothold on the network. Therefore, red teams are mostly focused on "assume breach" type of scenarios. In these scenarios, testers need to use a post-exploitation framework. Besides that, testers also need to hide the server-agent communication from NIDS (Network Intrusion Detection Systems). In this session, we will discuss one of the most famous post-exploitation tool, Empire's situation against payload-based anomaly detection systems. We will explain how to normalize Empire's traffic with polymorphic blending attack (PBA) method. We will also cover our tool, "firstorder" which is designed to evade anomaly-based detection systems. firstorder tool takes a traffic capture file of the network, tries to identify normal profile and configures Empire's listener in such way.
More from this channel
-
7:53
DEF CON 20 Documentary Bonus Clips - CDC muxed
-
47:43
DEF CON 20 - Raphael Mudge - Cortana: Rise of the Automated Red Team
-
43:15
DEF CON 20 - Peter Hannay - Exchanging Demands
-
25:01
DEF CON 20 - Ryan Holeman - Passive Bluetooth Monitoring in Scapy
-
48:14
DEF CON 20 - Xeno Kovah and Corey Kallenberg - No More Hooks
-
51:04
DEF CON 20 - Panel - The Making of DEF CON 20
-
50:01
DEF CON 20 - Josh "m0nk" Thomas and Jeff "stoker" Robble - Off-Grid Communications with Android
-
48:06
DEF CON 20 - Mark Weatherford - The Christopher Columbus Rule and DHS