“She doesn’t even go here!” Using Denial, Deception, and Adversary Engagement for Defense

Presented at ShmooCon 2022 Rescheduled, March 26, 2022, noon (60 minutes).

With the growing supply of valuable network-accessible data, network intrusion remains a cheap and risk averse way for threat actors to conduct operations. We can raise the barrier to entry with defense-in-depth, but what happens when we poison the supply? In this talk, we’ll discuss adversary engagement and how we’ve used it to regain the defensive advantage.

MITRE, whose adversary engagement operations go back 10+ years, has joined up with HSBC, who started running operations in the last two years. We’ll introduce the concepts behind adversary engagement and talk about how you can start running your own operations with open-source tools and MITRE’s new adversary engagement framework, Engage (engage.mitre.org). Together, we’ll walk through operation run by HSBC where we engaged with criminal threat actor FIN7, how we aligned the operation against MITRE Engage, and what we learned in the process.

We want to make adversary engagement an accessible and pervasive cyber defense strategy for all. The more adversary engagement operations we run as defenders, the more we collectively raise the cost and reduce the value of operations for our adversaries.


Presenters:

  • Karen Lamb
    Karen Lamb is a Cyber Intelligence Lead Analyst at HSBC where she leads the intelligence team’s development efforts, malware analysis, and adversary engagement operations.
  • Gabby Raymond
    Gabby Raymond is the Capability Area Lead for Adversary Engagement at The MITRE Corporation. She has helped define and mature MITRE’s AE work in research, operations, and tool development.
  • Maretta Morovitz
    Maretta Morovitz (@mmorovitz) leads the MITRE Engage team and has helped shape MITRE’s adversary engagement work for the last two years. She was recently named as one of the AFCEA 40 Under 40 Awardees for 2021.

Similar Presentations: