Skip to content
CBT Nuggets
DemoBook a Demo

Attack Methodology Frameworks

This skill covers various attack methodologies and frameworks used in cybersecurity to enhance defense mechanisms. It delves into penetration testing techniques and the importance of structured attack planning. Key frameworks discussed include the MITRE ATT&CK Framework, the Diamond Model of Intrusion Analysis, and the Cyber Kill Chain, each providing unique insights into understanding and mitigating cyber threats. The skill emphasizes the importance of adhering to organizational policies and industry standards while conducting these tests.

Full skill from CompTIA SecurityX. Preview the IT training 23,000+ organizations trust.

51m

Skill 14 of 32 in CompTIA SecurityX

Understanding the Attack

It’s important for us to remember that most attacks against information systems are planned out. Even if the plan is simplistic from a script kiddie with the intent of causing chaotic damage to a system, there’s a beginning, middle, and end to that attack.

For us though, the attack phase is a bit more thought out. And that’s where this skill comes into play. We’ve mentioned pen testing a few times already and walked through the pros and cons of it, but now we’re going to review attack methodologies. The examples of attack planning we go over in this skill allow us to properly test our defenses in a controlled environment.

Knowledge Check

Our cybersecurity defenses and the policies that look over and guide them are generally outlined by which entity in our organization?

MITRE ATT&CK Framework

MITRE ATT&CK Framework is a cybersecurity knowledge base that outlines the tactics and techniques used by adversaries in cyber attacks. It provides a structured mapping to help cybersecurity professionals understand, categorize, and analyze threat actor behaviors throughout the attack lifecycle.

The framework enhances threat intelligence, detection, and response capabilities, aiding organizations in strengthening their overall cybersecurity defenses by staying informed about evolving attack techniques and threat landscapes.

There are ways to conduct recon and the other steps of the ATT&CK Framework without even using fancy tools. Let's take a quick look at a simple observation.

Knowledge Check

When we utilize the MITRE ATT&CK Framework model on their website, which column would we refer to when researching techniques for pivoting?

The Diamond Model

The Diamond Model of Intrusion Analysis is a cybersecurity framework developed by the same folks that developed the MITRE ATT&CK Framework. It uses a diamond shape to represent the relationships between adversaries, their capabilities, targeted infrastructure, and victims.

This model helps analysts understand and respond to cyber threats by providing a comprehensive view of the interactions among these elements. It aids in identifying patterns, understanding tactics, and enhancing overall threat intelligence, making it a valuable tool for organizations aiming to bolster their cybersecurity defenses.

Knowledge Check

Using the Diamond Model, we've recovered logs from the SIEM our organization utilizes. We've discovered the repeat usage of "1=1" within the logs from our SQL database. Which step of the Diamond Model are we on?

The Cyber Kill Chain

The Cyber Kill Chain is a cybersecurity framework that dissects the stages of a cyber attack, from initial reconnaissance to achieving the attacker's objectives.

By breaking down the attack lifecycle into distinct phases, it helps organizations develop proactive strategies to detect and thwart threats at various points, enhancing overall cybersecurity defenses.

The Cyber Kill Chain steps

  • 1 - Reconnaissance
  • 2 - Weaponization
  • 3 - Delivery
  • 4 - Exploitation
  • 5 - Installation
  • 6 - Command and Control (C2)
  • 7 - Action on Objective

Knowledge Check

Each of the models we've reviewed have to be utilized by themselves.

Challenge

In this challenge, we’re going to play a game of choose your own adventure. Being that there were three different frameworks that we covered in this skill, I’ll present a scenario to you and let you decide how you want to proceed. Remember, there really aren’t any wrong answers to this. We want to examine the scenario and objectively pick a framework that works best for our situation and/or work environment.

That being said, it’s also ok to pick a framework you’re more comfortable with and supplement from the others as needed. So long as you’re within the regulations and policies set by your organization or jurisdiction, you’re good.

Solution

Knowledge Check

Which framework model did you prefer?

This interactive assessment is available in the full learning experience.

Want to answer questions like this yourself?
with no purchase required. Already have an account?

View Transcript

Understanding the Attack

0:00What's going on everybody in this skill we're taking a look at how to attack

0:04and I know we've been waiting for this point

0:06Especially if you've been in previous courses with me and you know that I love

0:10getting to this part

0:11But first let's go over some rules

0:13Because this skill is going about how to attack in the name of pen testing to

0:17strengthen our defenses

0:19Making sure that nothing's open over here that got me head to head edit the

0:23last couple of skills

0:25But we're gonna be taking a look at three different models in this skill and

0:29those are basically methods on how to attack and plot

0:32Everything out for that attack now the reason that we do this is to make sure

0:36that we're following

0:37Proper guidelines and edicates and those edicates are usually or and the

0:42guidelines are usually set by our organizations

0:44SOP or standard operating procedure and or policy

0:48So the CIO the CEO the C ISO that C suite upstairs is gonna be able to help us

0:54map out what our left and right limits are and

0:57Basically this comes down to we don't want to wreck the organization

1:02We want to test to make sure our defenses are really good

1:04but not so much to where we actually

1:07inhibit ourselves from being able to communicate or provide services that our

1:11organization is utilized for and

1:13Even though there are different frameworks that we're gonna be going over here

1:18and they have their own flow

1:19They all generally point to the same direction and outcome and

1:23Understanding our organizations cybersecurity defenses and learning how we can

1:27approve it is at the center point of all three of these

1:30Now I do want to go over one little thing real quick you and your organization

1:35out there

1:35It may already have your own way of doing this and that's okay

1:38because the use of a different model is not necessarily out of this world as

1:43far as you know a taboo or anything like that

1:46because that helps you understand your defenses that you have in place for your

1:50organization and that's okay

1:52But we all want to make sure that we have a general understanding of the three

1:56frameworks that we're gonna be going over

1:57For a couple of reasons one

2:00It's proper defenses and testing procedures for those that may not be familiar

2:06with what's actually going on

2:07Let's see the next reason would be let's see

2:10It's for the comptious certification. We're studying for so hint hint nudge d

2:14utch wink wink on that one

2:15And then we also want to make sure that we're within industry practices

2:19Now when I specifically point out industry practices and I this is probably the

2:24last time you hear me bang on about this in this particular skill

2:27We're talking about in the previous skills when we went over specifically ISO

2:3127001 and ISO 27000 too now if you're a little bit of lost on what's actually

2:37going on there and

2:38Along with those in this standards

2:40I would encourage you to go back and take a look review a couple of those

2:43skills

2:43Just to make sure that we're all on the same sheet of music

2:46Because even though we're studying for a certification here

2:49We're gonna pass it and then after we get that certification and we are sitting

2:53in the cyber security analyst position

2:56We need to make sure that we don't break any rules or regulations just in case

3:00for an organization that has a tightened sense of

3:03Let's see

3:05Responsibility towards those laws in case like financial industry or anything

3:09like that or government work

3:10And it just so happens that one of the frameworks is for that

3:14Government contractor out there. So if you're in the DoD you'll be really

3:19familiar with this one

3:20So let's go ahead and do it to it and get familiar with our three framework

3:24references and start to understand how we can start doing some

3:27Pentesting on our own. Let's go

MITRE ATT&CK Framework

0:00Great to the point, the meter attack framework is basically a spreadsheet and

0:05documentation

0:06for us to use as a reference to figure out how to plot out an attack.

0:11Now keep in mind when I'm going through this and talking about attacks, we're

0:15talking about

0:15internal pen testing within our organization to strengthen our defenses.

0:20We're not actually sitting here and making it to where I'm encouraging people

0:24to actually

0:25go out and attack stuff.

0:26That's not the case.

0:27So please don't go out and attack stuff and if you're using what we're talking

0:31about here

0:32to be able to do your own pen testing, please make sure that you have full

0:35permission from

0:36the system or network owner to be able to do this.

0:39I want to point out one last thing before we go into the attack framework

0:43models and that

0:44is if you're testing in your own or let's say home and you have a regular ISP

0:49coming

0:50in for your internet service, you can only do some of this within your own

0:55household.

0:56Once that attack traverses the gateway of your router slash modem for your ISP,

1:02then we start

1:02getting into some legal issues where we need permissions, usually in the

1:06express written

1:07consent form.

1:08So please keep some of those things in mind as we start going through this.

1:12Now that takes us to going through this and the first step that we do or our

1:18partake in

1:19is threat awareness where we're staying informed about the individual threats

1:22that are out

1:22there to our particular systems.

1:25And we need to make sure that we're always accounting for the different systems

1:28types

1:28of hardware types of software and the utilization of those different platforms

1:34that we have

1:35within our organization.

1:37And we do this by going to different resources such as O Wasp and the meter

1:41attack framework

1:43link that I have right above this video that we'll be getting into momentarily.

1:48And that leads us into asset protection where we just talked about knowing

1:52everything within

1:53your organization.

1:54And we've been over inventory a good bit already, but asset protection is

1:58making sure that we

1:59crucially identify and protect those critical assets with our security measures

2:05.

2:06And then we get into the actual vulnerability management.

2:09And this is where we start actually getting into some of the legwork for pen

2:13testing.

2:14And if we're doing a good job on vulnerability management and making sure our

2:17systems are

2:18up to date with all the relevant security patches and policies that we

2:22implement within

2:23the organization, then we can start building out our research for what we're

2:27exactly going

2:28to be pen testing with.

2:30And we hinted on this in previous skills where we're using Nessus to be able to

2:35do vulnerability

2:36analysis against a particular system, this host that we were using.

2:41And we will come back to that.

2:42But when we do all this, this allows us to be able to go in and properly

2:47measure how it

2:48is we're going to be able to attack things.

2:51And then we get into incident response.

2:53Now as we're doing our pen testing, we're going to make sure that if our

2:56organization

2:57has an incident response team, that they're keeping track of everything.

3:01And if they catch us doing it to see and make sure that they're utilizing

3:04proper incident

3:05response procedures or protocols that we've laid out within our organizations,

3:10this is

3:10specifically getting into developing plans to detect and respond to the intr

3:14usions that

3:15are happening, whether they be from us or outside threat vectors.

3:20And then when we're going through our pen testing and attack frameworks, it's

3:25also enforcing

3:26the access controls and the security education of the organization.

3:31Access controls being anything to implement strong authentication or

3:35authorization mechanisms.

3:37We're talking like AAA models here, radius, TAC-X plus if that's within the

3:42organization

3:44and also logging into different systems, whether they be local logins or domain

3:50models like

3:51Kerberos inside of Windows.

3:53And as this is happening, let's say we're sending out emails to test the

3:56environment,

3:57that's where that security education comes into place.

4:01And then we have to research and develop plans on how to attack for pen testers

4:05, the endpoint

4:06security workarounds.

4:09So as we've seen in skills past that semantic on this particular host system

4:13likes to light

4:14up like Christmas tree because the definitions are up to date.

4:18When we start actually getting into pen testing this particular box later on,

4:21we're going

4:22to see where that endpoint protection will come into play and potentially some

4:27of the

4:27other policies and services that we have inside of here.

4:31But that all leads us to the reason that we're doing this and that is making

4:34sure that our

4:35defenses are strengthened to be able to stop outside attacks from happening

4:40along the lines

4:41that we're plotting to do things out with.

4:43And that requires continuous monitoring and compliance to the protocols that we

4:48have within

4:48our organization.

4:50So with all that being said, let's go ahead and take a dive into the meter

4:54attack framework

4:56that I have the link for again right above this video.

4:59And I wanted to point out how to be able to flow through this and utilize the

5:03attack framework

5:04for our benefit inside of pen testing for our organization.

5:16So here we are.

5:17We have it pulled up on the screen right over there.

5:20And we're looking at a kind of a squinshed down view because I'm only able to

5:24capture

5:25so much of my screen without making it look entirely weird.

5:28So let's go ahead and start walking through these one by one with a very brief

5:32bullet

5:33point on what they are and how we can utilize these.

5:36And the first thing we have on the far left, let me make sure I can zoom in for

5:39you here

5:39is reconnaissance.

5:41Now we've no we know generally what reconnaissance is and we utilize tools

5:45already throughout

5:46this course to be able to do reconnaissance.

5:49And the one that we go to the most is usually Zinn map, which is the GUI

5:53equivalent of

5:54in map or we use Nessus to do asset inventory and a lot of other things.

6:01And here inside of the reconnaissance tab, you can see that there are different

6:05options

6:05for how to participate in that reconnaissance.

6:08And that will be the growing theme of the meter attack framework as we utilize

6:11it to go through

6:12the different areas that it has.

6:15Now inside of reconnaissance, the first one that we have in the techniques and

6:18let me zoom

6:19in here, you can see is active scanning.

6:22And that's generally what we've been doing with Zen map to be able to go

6:25through and get

6:26host information for what it is that we want to plot out our Pintas for.

6:30Now they have other stuff in here as well too that you could definitely utilize

6:34for your

6:34reconnaissance, but in the reconnaissance phase of gathering everything up for

6:39our attack,

6:40it's getting information more than anything else to make sure that we are able

6:46to utilize

6:47any kind of exploit to be able to Pintas.

6:50And if we can't, that's even better because that means the defenses are where

6:53they need

6:53to be.

6:54But when we do our scanning, like we've done in Zen map before, this right here

7:00is an outline

7:01of how to do proper asset management and vulnerability assess.

7:06Now as an example of the actual reconnaissance phase, we're here using Zen map

7:09again against

7:10this particular host.

7:11You could see that we have a lot of ports opened up.

7:13It gives us a lot of information about the actual host itself and the services

7:18that are

7:18running within.

7:20Now this lines up with the meter attack framework.

7:22Let me open that up here for you and see if I can get it for you.

7:25There we go.

7:26And you can see him in here inside of our reconnaissance that this falls within

7:30the active

7:30scanning and also gathering victim host information.

7:35Now I'm going to go inside the victim, gather victim host information to give

7:38you a little

7:38bit more clear and concise way of understanding this.

7:42And when we go inside of it, you can see that when we first open it up, there

7:45are sub techniques

7:47listed below too, because when we talk about the actual victim host, we're

7:51talking about

7:52the system itself and not necessarily any particular hardware software answer.

7:56And that's where the sub techniques come into play at here, where we have

8:00hardware, software,

8:01firmware and client configurations.

8:03Now does Zen map give us all of this?

8:05No.

8:06It gives us a general idea of network and hardware information to be able to

8:13start utilizing

8:14for a pen test.

8:17But as we go down inside of here, we can look at not only the possible methods

8:22and ways

8:22of conducting a reconnaissance on a particular host or network, but we can also

8:28look at some

8:28mitigation as well too, and how to do proper detection.

8:36And that allows us to be able to not only be able to conduct a pen test, but

8:40also give

8:40cybersecurity defenses a good resource of information as well.

8:46So understanding the meter attack framework is not just for attacking only.

8:50It's also for being able to build those proper defenses.

8:53Now if we go back to our framework here on the screen, we can see that this is

8:57done for

8:58many different areas.

8:59And bear with me, I'm going to have to slide my screen over left and right, but

9:02I will

9:03zoom in for you.

9:05So zooming in here, we can see that after reconnaissance, we have resource

9:08development

9:09with its sub techniques listed underneath, same for all the others, the initial

9:14access

9:14and we're actually getting inside the system itself to gain access for that

9:19initial foothold

9:21execution to be able to start our way into the system to make sure that we're

9:25actually

9:26going through and looking at what we need to.

9:30And also this gives us a different command options and kind of techniques for

9:34being able

9:34to do this.

9:36And then persistence, that's where we're talking about maintaining access to

9:40that individual

9:41system inside of our Pintas itself, because just because we get inside of a

9:46system doesn't

9:47mean that the defense folks aren't already trying to kick us out.

9:51And then we through the other attack methods, we go into privilege escalation.

9:55And this allows us to not only see things as a user, but also to grant further

9:59access

10:00into other resources that we may be able to utilize on the actual system

10:05overall and do

10:06that pivot in order to be able to move into other systems.

10:11Now once that escalation happens, we move into defensive evasion to make sure

10:15that we're

10:16not being targeted by the cybersecurity blue team.

10:20And the reason for this is we don't want to be caught because if we're caught

10:25and booted

10:25out of the system before we can implement that farm foothold and start doing

10:29our pivoting,

10:30the whole point of this exercise, if we're an attacker, is done.

10:35And for Pintas team purposes, this tells us that our cybersecurity defense

10:39teams are doing

10:40their job in proper actual detection and utilization of resources.

10:45And by our powers combined put together, we can build those better defenses

10:49because up

10:50to a certain point, we were able to gain access theoretically.

10:54And if we were, we still need to report this, log it, make sure that everybody

10:58is aware.

10:58So that way, even though cybersecurity defenses were able to boot us out before

11:03we did any

11:04harm, we were still able to get in and we can prevent that in the future.

11:08And that's moving into credentialed access, discovering more systems and also

11:13lateral

11:14movement, which is that pivoting I was talking about while ago, the actual

11:18collection of information

11:19where we start doing technique for techniques for capturing information,

11:24whether they be

11:25like it says right below man in the middle or getting into files and data

11:29collections,

11:30and then command and control to be able to maintain access even further and

11:34utilize the

11:35system.

11:36And we can do something like using a hash cat to be able to reverse shell into

11:40the other

11:41system on the other side.

11:43And then exfiltration, as I scroll down here and move this all the way over to

11:46the right

11:47for the last one, is making sure that we can get all of that data off the

11:51system that we're

11:52actually looking for for any potential information or intel to let us into

11:57other systems resources.

11:59And we're not just talking about actual systems themselves.

12:02It could be that we're looking for financial gains like bank account numbers, P

12:06II, etc,

12:06etc.

12:07And then once it's all said and done, what was the overall impact of what it is

12:11that

12:11we were doing?

12:13Now yes, this is a lot to take in on the meter framework, which is why I'm

12:16about to

12:16wrap this video up because this is getting kind of lengthy.

12:20But the point that I wanted to make is that the attack framework that we have

12:24here is a

12:25good guideline for us to be able to follow through the steps of doing proper

12:28pen testing

12:29and defenses together in a joint environment and having different resources to

12:33be able

12:34to go through here and understand not only what they are, but learn about

12:38techniques

12:39to be able to properly utilize some of these attack methods.

MITRE ATT&CK Framework

0:00- No, no, no, no, no.

0:01- I did them.

0:02- Yeah, I wanted to point something out to you real quick

0:04as far as reconnaissance goes.

0:05And the meter attack framework website

0:07actually has a great example for this.

0:10So when we talk about reconnaissance,

0:12we're not just talking about learning information

0:14from resources like ZenMap.

0:16We can get information from just about anywhere.

0:19And this is the perfect example

0:21because their website here at attack.meter.org

0:24and I hope I'm saying that correctly.

0:26If you notice, let me zoom in and see if I can show this

0:29to you as HTTPS.

0:31But if you look on this particular page right here,

0:34we have the exact same site.

0:35Let me see if I can zoom in for you.

0:38We have HTTP and it's not secure.

0:41Let me bring that down real quick.

0:43You can see right here, let me, there we go.

0:45There's the HTTPS, there's HTTP.

0:48And when we do reconnaissance,

0:50that tells us that there is a possible attack method

0:53through port 80 versus port 443.

0:56And if we know our tools, we can utilize things like Metasploit

1:01to be able to come in and use Burp Suite against port 80

1:05because we don't have any encryption

1:06for that data in motion.

The Diamond Model

0:00Of the same folks that brought you the meter attack framework and everything

0:03that we just did

0:04in the previous couple of videos up above, we have one of my favorite named

0:08models, the diamond

0:10model. Now, so like this one, because it's a little bit more clear in what the

0:19steps are in

0:20understanding the actual flow of an attack and the defenses that go with it.

0:24And to be able to

0:24demonstrate this, I'm going to put it up on screen for you right now. So we're

0:28taking a look here

0:29at the diamond model, broken down into five steps, and you'll notice that we

0:34have the four pillars of

0:35the diamond starting down on the bottom with the victim, because whenever an

0:39attack happens to our

0:41organization, that system and the owner of that system, whether it be the

0:45individual or the

0:46organization overall, is the victim. And then we move on working clockwise with

0:51infrastructure

0:52being next, because the infrastructure is the system or systems and network

0:58that is associated

0:59with that actual victim. And we're not talking about just one particular system

1:03, it could be inside

1:05of the entire organization, especially if that attacker gains a little and is

1:09able to pivot through

1:10the rest of the systems with elevated credentials. And then we start to kind of

1:16ID who the adversary

1:18is based on different logs that we'll get into in just a second, and then wrap

1:22it up with their

1:23capability to see if it's something that we need to have more help or

1:28assistance with containing.

1:30All right, first and foremost, down on the bottom right, where victim is on the

1:33right

1:33side of the diamond, you can see where it says number one, victim discovers the

1:37compromise. Now,

1:38this could be the cyber defense cell, looking at different alerts that come

1:42through the different

1:43systems that we have in place to be able to notify us of different things like

1:47logs and whatnot,

1:48or it could be even the actual individual user on the system within the

1:53organization that says,

1:54hey, this may not look right and this doesn't smell right for whatever reason.

1:59So that can

1:59lead us to being able to discover the actual compromise itself. Now, could the

2:04compromise be

2:05something like hashcat taken over the system and starting to send wonky

2:09commands could be,

2:11or it could be something as simple as we notice a little bit abnormality in the

2:15way that a program

2:16operates versus how it's supposed to operate. Regardless, it sends us up to the

2:21capability

2:22of the actual attack that's actually going on. Now, I know I just said

2:25capabilities last. I'll

2:26swing back around to that in a second. But that's why I have the arrows here as

2:30well too. Now,

2:31this is my rendition of the actual diamond model and a simplification of what

2:35it actually is.

2:37I have some resources for you that I'll get to in a second. But the capability

2:42of the attacker

2:43is based on what it is that they're using to be able to access that said

2:47vulnerability or

2:48exploit inside the individual system, which moves us on to number two, where we

2:52start in cyber defense

2:54world, start looking at the logs of the exposed system and we expose the IP of

3:00the attacker. Now,

3:01could that be the overall IP of the attacker, you know, end all be all, no,

3:07they could be

3:07spoofing their IP address, but this starts to narrow down the hunt. And we

3:10start getting into more

3:12detailed ID S IPS logging from the actual perimeter of the network and intern

3:17als to the systems network

3:19or organization's network. And we could start to figure out where that actual

3:23IP address legitimately

3:24came from. Now, I mentioned all that because that leads us into the actual

3:31infrastructure side,

3:33where we start looking at the seem to show other network activity. See, it all

3:37starts to come together

3:39under the diamond because let me tell you, diamonds are forever. But the scene

3:44shows us the network

3:45activity of the attacker or attackers and to be able to ID some more network

3:50information from the

3:51attack itself within the infrastructure of the organization. And that leads us

3:56to number four on

3:57the top left of the IP points to the actual threats identity. And this could be

4:03that we do a who is

4:05or a reverse lookup or go into the icon database to be able to figure out who

4:10owns this actual block

4:11of IP addresses. Now that's specifically talking about IPV for there are other

4:16methods out there

4:17that we can get into later on about IPV six. I just want to give you the

4:20general idea right now.

4:21And that is using resources that are open source and even maybe some

4:26proprietary stuff out there,

4:28but more open source because I'm chief, to be able to find us who owns that IP

4:33block to be able to

4:34point to the where the attacker is coming from. Now why is this important? Well

4:38, in this phase

4:39right here, while we're trying to contain the actual threat inside the

4:44organization,

4:45we could also be working on access control list and other control methods in

4:50reference to the

4:51actual meter attack frame model that we referenced in the video set above

4:56because we want to try to

4:57incorporate both of these together. See, this is a generalization model that we

5:02're looking at here.

5:03And we would actually reference these different areas that we're looking at in

5:08the diamond model

5:10to the meter attack model to get more details as to what we can use in terms of

5:16techniques that

5:17is recommended for us to be able to leverage these different areas of the

5:23diamond model even

5:25better. And when we get the IP of the threats identity, we can start to build

5:32network access

5:32controls, better firewall rules to be able to block attacks from that

5:37particular system,

5:38or if we need to blacklist an entire block of IPs. But this gives us to the top

5:42of the diamond

5:43model of the actual adversary themselves. And as far as like getting a name to

5:48the actual attacker,

5:49that's detailed stuff for way later on, we're just looking for an IP and IP

5:53block at this point.

5:54But the adversary leads us to number five, which is the threat identity helps

5:59ID security threat.

6:01Now this goes into more of the understanding your attacker than anything else.

6:07And for those that

6:07have department of defense experience, especially in SIGINT, signal

6:11intelligence, this is very

6:14familiar to us because knowing who or what the attacker is builds more of a

6:18database as to what

6:20our defenses need to be, because if we have a known attacker or known attack

6:24method,

6:25then we can start building defenses out for that generalized attack method to

6:29bring it back to me.

6:31Now when I talk about threat identity helps, let me give you an example here.

6:35We're talking

6:36about script kitties in particular, because I've already brought them up, or if

6:39I haven't, I will,

6:40I promise. But when we talk about the attacker and we go into, let's say script

6:45kitties,

6:45let's say we've identified through our logs the actual string of text that they

6:49used to be able

6:50to gain access. It wouldn't be a bad idea to be able to take some of these

6:55commands or some of these

6:56outputs that we get from these commands and run them against Google or other

7:00known databases

7:01of known exploits. And the reason that is, is it may come back and give us more

7:05intel on what program

7:06is being utilized, let's say it's hash cat or let's say it's metasploit or let

7:10's whatever the

7:11case may be. And then we can get a better idea of how to round up our defenses

7:16against those

7:16particular programs, because script kitties are known to be able to utilize the

7:20Google or now

7:22with AI. And this is not a day get the CBT folks, I promise. But to be able to

7:28get us a quick and

7:30easy method to be able to utilize some of these programs that the script kitt

7:33ies may not truly

7:34understand their the full potential of. So when we start put piece in the

7:38puzzle together with

7:40different command strings that we gather from down at number three in our scene

7:44network activity

7:45logs and start doing the research on those, we may be able to cut some of these

7:49attacks off at

7:50the past. And that's why using a broken down version of the meter attack

7:54framework model

7:55in the diamond model gives us a standardized flowchart of what's actually going

8:00on and how to process

8:02and attack within the organization. Now the flip side of that is, is that as an

8:07attacker

8:07that's working on pentesting an organization with permission, we can utilize

8:12this model right here

8:13to be able to go through and use it for a visionary tactics. Now again, what

8:19takes us right back to

8:20the meter attack framework model up above to where we can start looking at a

8:24visionary tactics

8:25to be able to help us out in something like number two, where log exposes IP of

8:30the attacker. This

8:32is just a generalized idea of what we just went over in the meter attack

8:37framework model. This

8:39allows us to be able to simplify and understand the different more intricate

8:44steps in a broader

8:45sense to be able to give us an idea of how to not only do our defenses, but

8:50also do a proper

8:51attack for the purposes of pen testing.

The Cyber Kill Chain

0:00The last model we're taking a look at is something that is a little familiar

0:04inside the DoD world, especially once you start working with CyberCom or Cyber

0:07Command.

0:08And that is the Lockheed Martin Cyber Kill Chain.

0:11Now, this is a kind of a combination between the meter attack framework and the

0:16diamond model, where we go into seven steps of understanding the actual kill

0:21process to an attack.

0:23Now, I'm just going to run through these very briefly and kind of give an

0:26explanation to what each of these are.

0:28So that way we kind of understand what's going on here because I don't really

0:33feel the need to go too deep in the weeds on this and just want to introduce it

0:37to make sure that we're familiar with it, just in case there was a

0:40certification and ask about it.

0:42And step number one is reconnaissance and you're starting to see a theme here

0:45where no matter what we do, there's always the actual research portion of the

0:50attack or defense overall.

0:52And we want to make sure that we also include target selection, research for

0:57vulnerability identification and the like, because not only are we trying to

1:02identify the actual system itself, but also the vulnerability that we're going

1:07to be using to exploit.

1:08And where do we get some of this information from?

1:10Well, I'm glad you asked.

1:12Now, this should look familiar. We're inside of our NESIS terminal here, inside

1:17of the CaliBox, inside of our VM environment.

1:19And we're going to go back to our first scan that we ran initially in the

1:23previous skills and go back to our one medium vulnerability that we discovered

1:27on our host over here right over there and go into the explanation for it.

1:32Now, this is SMB signing not required.

1:35And I'm not going to get in the weeds because we've already beaten this one

1:39with the bat.

1:40And when we look at the actual reconnaissance phase for what's happening inside

1:45of our cyber kill chain, this is a big portion of the reconnaissance right here

1:49because not only does NESIS identify the vulnerability itself, but it also

1:54identifies the actual system and other information about the system because I

1:59can essentially go back and look at all the other

2:02infos that are on here. And this is where we get the reconnaissance for the

2:11system overall, for example, if I go down to our info that's about Windows, I

2:13can see here that we have DCE service enumeration and I got more info about

2:15what's actually happening inside of the RPC protocol itself to give us more

2:21information about the particular of what kind of windows we're running, what

2:25kind of information that we're getting for the actual services that are

2:29available on the system.

2:30And all sorts of different applications that are running as well.

2:34Now, this may seem a little bit jarble as far as the output is concerned, but

2:39this all ties into that research that we were just talking about.

2:42Step number two inside of our cyber kill chain is weaponization.

2:46I hope I'm pronouncing that correctly.

2:48And that is basically the creation of tools to be able to exploit what we found

2:53in our reconnaissance of load abilities and the system overall.

2:56So we've discovered the vulnerability. How do we want to exploit it? Well, this

3:01is where research comes in yet again, but we can also reference something

3:04pretty easy.

3:05And let me open that up for you real quick. The meter attack work frame model.

3:09I know it's been a while since we touched on this, but we can look at initial

3:13access for this particular phase of our weaponization, because we know it's SMB

3:20exploit.

3:20Well, how do we get research to be able to go in and tell us how to pop

3:25exploits for SMB? Well, what's SMB? Well, that's server messaging block and has

3:30a lot to do with file sharing.

3:32And if we look under the initial access, we can see that we have, let me move

3:36my mouse there for you for a second.

3:38Command, ejection, drive by compromise exploit, public facing applications.

3:42External remote services, hardware fishing, remote through removal media supply

3:47chains, compromised trusted relationship.

3:50That may be one right there, trusted relationship, because SMB is usually

3:55associated with some type of credentialing, and that credentialing is usually

3:59maintained by either the local system or a domain itself.

4:02Now, we could go into execution phase of the meter attack framework and be able

4:07to get more information concerning that. But this just gives you a general idea

4:12of the different steps that we're going.

4:14Number three, delivery. And once we realize how we're going to leverage that SM

4:19B attack, we're going to be working on delivery.

4:22Now, it just so happens that our man in the middle technique inside of our

4:28attack framework allows us to be able to do a SMB attack, not directly, but

4:35this is kind of pointing out and using that framework to be able to identify

4:39where SMB can be utilized to leverage a system in the name of pen testing.

4:42And it's under adversary in the middle, and there's a lot of different

4:47techniques that we could use here, and you can look at the sub techniques, but

4:52inside of our actual cyber kill chain.

4:55This is where we start moving into exploitation and using the attack framework

5:01model to be able to go in and kind of do our research.

5:05We move into, we move from a step three, which is delivery on how we're going

5:11to weaponize to the target itself. How are we going to do it in this case, I'm

5:16going to pick metasploit.

5:17And then the exploitation is actually utilizing metasploit to be able to attack

5:21. So to our Cali box.

5:23Now we get to do stuff a little bit of fun stuff. We're going to hit start on

5:29our metasploit, Cali box and type in metasploit. You can see it come up here,

5:33metasploit framework.

5:34Now when it first opens up, there's two things that's going to happen. First,

5:37it's going to ask for your pseudo password. And then right after that, it's

5:40going to fire up its database.

5:42Now, if you've opened up metasploit already while the system is running, you'll

5:46be able to skip this part right here, but this could take a minute or two,

5:50depending on the type of system you have, resources allocated to it, and the

5:54depth of the actual database that you've updated or configured inside of your

5:58metasploit.

5:59Experiences may vary, but here we are inside of metasploit and we're going to

6:04start trying to leverage SMB attacks against the actual host system itself,

6:08based on our Nessus report that SMB signing is not required.

6:13Now there's a few steps that we're going to go through. And first one is

6:17understanding that inside of our metasploit database, we're going to be typing

6:23search.

6:23And I'm going to put these commands below to make sure that we are following

6:27along at home. And that way, I can verify my spelling as well to slash SMB.

6:32Now inside of this right here, we're just getting an idea of what different

6:37options metasploit has.

6:39Based on the database that's installed for SMB exploits that are preloaded

6:45inside of our system here. Now you can see that inside of our different options

6:53here that we have the actual address or yeah address would be a good way to say

7:00it when we start doing the use command of the different types of

7:03vulnerabilities that we can potentially exploit against the system.

7:06So if you're ever in need of being able to search for something inside of metas

7:10ploit, this is option number one.

7:12So now we're going to see if we can use one of these and I'm using a UX and tab

7:18bing so you can tab inside of metasploit.

7:22And I'm going to type in scanner. If I could spell correctly here SMB and then

7:30SMB underscore version.

7:33Now if I scroll up, I'm going to highlight right here pop out and zoom in for

7:39you. You see this number 12 on our options here.

7:41What is this going to do for us? Well, it's going to identify the actual

7:45versioning of the SMB that's being used on the target.

7:48And the target in this case is the actual host itself. So when we hit enter on

7:53this, you're going to see that our command line has changed from msf six to msf

8:01six auxiliary because now we have utilized an auxiliary command and subroutine.

8:07Now inside of here, I'm going to go show options. Oops, I wasn't inside the

8:15actual terminal or the VM type show options.

8:18And we can see here that where options are kind of limited. But more

8:22importantly, we're just paying attention to the R host.

8:25And that is what is the actual host that we're going to be doing this to. And

8:29that is the this system right here.

8:31Now if you'll remember, this is the kind of default gateway for our VM network.

8:36We're going to set our host to go to 192.168.247.1 and that's our our host.

8:43You can see right there, it has set the actual R host and making it to where

8:48that's our target. Now, as far as threads.

8:52I believe it current set current setting them one. And that's just basically

8:58how many times are how we're going to query the actual SMB of the target itself

9:04.

9:04Now, so we're just getting into the basics of how to do this. So now we're just

9:09going to simply type run.

9:10And it's going to run against the actual host system itself. And you could see

9:16that scanned one of one has completed at 100%. And right above that is our

9:21output.

9:22Now, this is telling us, if let me zoom in for you real quick, that we're

9:27utilizing SMB 3.1.1 on the actual system itself.

9:32So we have limited options on how we're going to exploit that. Now, why is all

9:38this important? Well, let me get down to it in that when we ran our Zen map

9:44slash in map and our vulnerability assessment inside of Nessus itself.

9:49We didn't really get a lot of information concerning the SMB versioning and

9:55information concerning the actual SMB protocol. All we got was is that SMB

10:00signing is not required and utilizing Metasploit to be able to scan that SMB in

10:06more detail tells us the exact type of SMB that we need to start leveraging for

10:13our exploitation step inside of the kill chain of the cyber kill chain.

10:18Sorry, I have a little bit of a stutter there.

10:21And later, we can start getting into more exploitative measures to be able to

10:27go to our next step of installation.

10:29And this allows us to be able to utilize information that we've gained so far

10:34to leverage, in this case, Metasploit, to go in and find ways to install tools

10:39and create back doors for our actual exploitation.

10:43Now, I do want to show you this for a second. Let me pop out and show you this

10:47right here. And if we go back into our meter attack framework model and we look

10:52at the adversary in the middle, which is going into our SMB relay exploitation

10:58here.

10:58Under our techniques, if we scroll down, we can go and look at procedure

11:03examples on how to actually go and leverage this particular vulnerability

11:07inside of the system itself and the different models and software suites that

11:12you can actually utilize as well.

11:14Now, right below that is some of the mitigation for this, which would actually

11:19help us out a little bit. You can see right here that we filter network traffic

11:22.

11:22That's always an option, but we can disable a remove feature program itself to,

11:27and we can even go in and configure to be able to non respond to that SMB

11:31version query to narrow down our options in the exploitation and installation

11:37portion of this.

11:38So where do we go from here. Now that I've properly figured out how to swap my

11:42screens here for a second, we move into command and control.

11:45And the reason that we move into that C2 aspect is to be able to understand

11:50that not only have we gained access to the particular system itself, but we've

11:55also gained command and control of that system to be able to give us

12:00administrative or elevated rights to that particular system.

12:03Because as a user, we may not have access to everything, especially like system

12:08files and all the like, but we have command and control to be able to gain

12:11access into that and potentially be able to pivot across the actual network

12:16itself.

12:16And this leads us into our final step of the kill chain model.

12:20And that is actions on objectives, and this is where we start to do extraction

12:26of data to be able to gain more access to start to all this over again into

12:31other systems as we pivot throughout the organization or different systems

12:36inside of a smaller network.

12:39So that's basically the ins and outs of that and how we utilize all three of

12:44these different models together if we want to.

12:47But overall, the meter attack framework is where we want to reference for more

12:53information if we ever get stuck like I do a lot.

Challenge

0:00Alright everybody, we've come to the end of the skill and we're

0:02going to be doing a challenge together.

0:04Now this challenge is going to be less technical than what we're

0:07used to, especially in the courses that you've had with me together

0:10in the past, and that's okay because this one is more of a

0:14choose your own adventure and thinking about how we would

0:17actually exploit something to attack it, defend against it, and

0:21basically build our attack frame model around it.

0:25So I'm going to put up on the screen now.

0:27Earlier in the skill, we were taking a look at an vulnerability

0:30that was found on our Kali box.

0:32Now I have on the left of this the

0:35actual Nessus plugin that found it if you want to do a little bit of

0:38research on your own as well.

0:39This is Nessus plugin 5.1.1.9.2

0:41that came up in one of our Nessus scans.

0:45And this is pertaining to an SSL certificate that cannot be

0:49trusted.

0:49Now the probability behind this is

0:52that it may be that the root CA certificate may not be in the

0:57trusted CA on the actual system itself.

1:01There could be a whole host of different reasons why this may be,

1:05but it is an exploit because somebody could potentially go in

1:08and attack the system based on that SSL certificate not being

1:12trusted.

1:13Now of course when we run our

1:15scans and find stuff like this, we have all the information on the

1:19system because we are already on the network and we have the

1:22information already from whether we run it through Nessus or we get

1:26the information of the system through something like ZenMap,

1:29nMap, or even Wireshark if we're sniffing the network.

1:34But in this particular challenge, it's going to be taking a look at

1:38the information that we have about this plugin and vulnerability on

1:42the system and deciding which framework we're going to be

1:46choosing.

1:46Now there is no wrong answer to

1:48this other than no answer at all.

1:51So this requires critical thinking

1:53on all of our parts to see what the preference actually is of the

1:58cybersecurity analyst that's going to be examining how to attack for

2:02the purposes of pen testing and better security.

2:05Now there are three that we covered in this entire skill and

2:09that would be the meter attack framework, the cyber kill chain

2:13and my favorite the dive and model.

2:15So I'm going to pop up on the screen real quick.

2:18Let's remember when we're using the meter attack framework that we

2:22can go through and have a step-by-step guide of how to

2:26actually go through and figure out how we're going to exploit or

2:30better protect against vulnerabilities such as the one

2:33found for this challenge.

2:34So as an example, if you're when

2:36you're in the reconnaissance step and you're doing your active

2:40scanning, it doesn't necessarily mean that you're done in the

2:43reconnaissance step.

2:44Now the same can be said in the

2:46actual cyber kill chain itself, which I have pulled up here on the

2:49side screen and I want you to note that whenever you go through each

2:53page of the cyber kill chain that is kind of like the meter attack

2:57framework except these are different preferences.

2:59And I'm going to come back to that in just a second as well because

3:02we also have the diamond model, which is still my favorite and we

3:08have more of a simplistic breakdown of how we would actually

3:12go through the different steps.

3:13Now if you'll notice here that we

3:15don't have the detailed sub steps or subcategories that are within

3:20the actual diamond model.

3:22This is just an overall guideline

3:24of which process step and the process that we are in for our

3:29attack framework.

3:30Now do you remember this is a

3:31choose your own adventure? So when we come back into the

3:34solution, I'll be taking a look at something that I won't prefer as

3:37far as going through and analyzing how we're actually going to

3:42possibly exploit the vulnerability found in the rest of the skill.

3:45So see you there.

Challenge

0:00Alright, it's solution time.

0:01So let's take a look at what the

0:03actual problem was in our challenge and we have here our

0:06NESSIS scan, which we had a vulnerability identified on our

0:10Kali system for SSL certificate not being trusted.

0:13So let's go into how I would take a look at this and remember this

0:17is one of many possible solutions in this choose your own adventure.

0:22You at home may decide to go about this a different way, but I want

0:28to co and utilize one if not more of the attack framework models.

0:32Now of course, since I've been saying it from the beginning that

0:35the diamond model is my favorite, that's what I'm going to be

0:38utilizing when I start building out a plan on how to attack this

0:42vulnerability potentially attacked this vulnerability.

0:44And as you see here on the screen, I have the diamond model pulled

0:49up.

0:49Now, first thing I need to

0:51identify is who the victim is and that's down on the bottom and our

0:55number one step in the actual diamond model itself.

0:58Victim discovers compromise.

0:59That's we discover a compromise on

1:02the actual victim's system.

1:04And then we move on to actual

1:06number two, which is right in the middle of it.

1:09And it says logs exposed IP of the attacker.

1:12Now, throughout the process of this, we've been using Nessus to

1:16identify that vulnerability.

1:17So we have a lot of the machine

1:19information or target information already available to us, such as

1:24the system name IP address operating system, and also the

1:29CVSS scoring and all this other great information.

1:31So that's taken care of by number two.

1:33Number three of this would be the scene shows other network

1:38activity.

1:38So in this particular case, we

1:40would actually be looking at logs from other security systems placed

1:45within the network and seeing if this SSL vulnerability has been

1:51identified elsewhere for different connections, different parts of

1:55the network.

1:56If this particular system that

1:57we're looking at right now has been going out and trying to do

2:01other connections across the network.

2:03Now, this particular vulnerability is the SSL on the actual system

2:06itself.

2:07So in this particular instance, it

2:09would be more of a connection going to that particular Kali box

2:14and not necessarily back out.

2:16But that's diving deeper into the

2:19report that you get from the actual vulnerability assessment

2:22itself.

2:22Now, of course, inside the diamond

2:25model, we have a very rough overview of how we would actually

2:29take a look at the attack phase or pin testing phase of this

2:33vulnerability on our Kali system.

2:35So my preference would be to clear

2:37up some of that vagueness.

2:38I would actually be going to the

2:40meter attack framework .

2:41Just for me, that's not a correct

2:43answer to wrap everything up.

2:45That's just how I want to do.

2:47Now, taking a look at the meter attack framework here, we know

2:50that we're past the reconnaissance and kind of the resource

2:54development, we're actually into the initial access of what's

2:57actually going on for this vulnerability.

2:59We would look at the different techniques listed under the

3:03initial access and start going through and trying to get some

3:08more information on how we would actually exploit this

3:10vulnerability for the purposes of pin testing.

3:12And then from there, we would really start building out not only

3:16how we're going to get into the initial access, but also the

3:20execution , the persistence and privilege escalation, basically

3:23just following through the different steps of the meter

3:26attack framework.

3:27Now, again, I want to close this

3:29solution out by saying that this is just the way that I would do

3:32it.

3:32There is no wrong answer other

3:34than having no answer at all for this solution.

3:36And as a cybersecurity analyst, it's up to us to figure out how

3:41the different methods of being able to go through and do a

3:46security assessment with the vulnerability side being tested,

3:50how we're going to be able to put all this together to be able to

3:54patch up at the end of the day, and make sure that outside factors

3:59and all the different organizations that are against us

4:04aren't able to penetrate that vulnerability or even see it at

4:07all if that's the case.

4:09So again, personal preference in

4:10this or shooter's preference, as we used to say in the Army, and

4:15just keep in mind that it has to be within the guidelines of the

4:19organization within the SOP and or jurisdiction that you're in,

4:22because sometimes you may not be able to use the diamond model,

4:25because the preference of our organization could be that we only

4:29use the cyber kill chain.

4:32So I hope this has been

4:33informative for you, and I'd like to thank you for viewing.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need CompTIA SecurityX?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo