Detecting targeted attacks
Our approach does not rely solely on recognising well-known criminal groups from analysis of their activity. It is considerably broader, which allows both proactive incident discovery and detection of targeted APT (Advanced Persistent Threats) attacks regardless of where they come from. That way we find threats that go unnoticed by the IT security products deployed in the organisation, such as antivirus software.
Cyber threat hunting is a continuous process of proactively detecting intruders, not an off-the-shelf technology or a one-time exercise. We have broad knowledge and experience of how hacking attacks unfold and of the techniques used to cover tracks (so-called anti-forensics) – this follows directly from the attack simulation services we provide, red teaming and penetration testing, combined with our knowledge of analysing and detecting them: digital forensics and incident response. Bringing together professional experience on both the offensive (red team) and defensive (blue team) side lets us deliver genuine threat hunting. Our approach is built on taking hacking methods (TTPs) apart down to first principles, which means we can detect them irrespective of the tools the attackers happen to use.
We use our own dedicated software, RedEye, which helps find anomalies and symptoms that may indicate an intruder is present inside the organisation’s internal network. Successful detection means the incident is handled in time, before the organisation suffers material losses – whether an information leak or destructive operations such as encrypting critical data to extort a ransom.
The IT security team
Has everyone on your security team ever analysed a hacking attack? Has everyone on the team carried out a successful attack and compromised a network? Is the security team designing defences against attacks it does not know or does not understand? A lack of experience and offensive competence translates directly into significantly reduced ability to detect and analyse attacks. Our team holds competence in both attack simulation and incident analysis, including post-breach analysis and computer forensics.
Are alerts in your detection systems permanently active, whether or not an attack is under way? The fundamental problem with detection systems is the volume of false positives, which undermines effective detection by dulling the SOC team’s vigilance. If warnings are on virtually all the time, will the security team be able to tell a real attack apart and catch it? For this reason, owning even the most modern software in the form of an appliance does not by itself enable effective detection of intruders or defence against hacking attacks.
Threat hunting emerged from the need to defend against targeted APT (Advanced Persistent Threats) attacks that break through even the most innovative security tools. In 2021 Microsoft fell victim to such an attack and drew its own conclusions from the analysis of the Solorigate incident – proactive detection is a key factor in ensuring effective information security.
Proactive threat discovery
We know how to search effectively for symptoms of attack and for the presence of hackers in an organisation’s infrastructure, or of dishonest employees acting against the company. A typical threat hunter task is deploying honeypot software tailored to the given network using canary tokens, or monitoring DNS traffic for potentially dangerous activity – by examining entropy, the types of DNS queries (data exfiltration), comparing domains against IOCs (Indicators of Compromise) taken from threat intelligence feeds, and so on. Log analysis here does not come down to monitoring for basic events either, but to deep analysis and correlation of logs by joining many data sources and examining seemingly trivial events that may indicate a loss of integrity. On top of that we use data enrichment in detection – enriching internal data with information from outside, from our own Cyber Threat Intelligence (CTI) solution.
Cyber Threat Intelligence
Cyber Threat Intelligence (CTI, also Threat Intelligence Platform) means continuously acquiring information from external sources about threats to the organisation. The platform supplies information on IOCs (Indicators of Compromise) used for automatic data enrichment of internal monitoring systems such as SIEM (Security Information and Event Management), IPS (Intrusion Prevention System) or IDS (Intrusion Detection System) with all their variants: NIDS (Network Intrusion Detection Systems), HIDS (Host-based Intrusion Detection Systems) and so on. The simplest example of such enrichment is pulling information about attacker IP addresses from a distributed honeypot network, or detecting changes in the open ports of the organisation’s infrastructure.
Critical infrastructure protection
We know how advanced attackers operate, which is why we are able to design effective threat detection. In 2020, at the invitation of the Singapore Ministry of Defence, we took part as an offensive team (red team) in the international exercise Critical Infrastructure Security Showdown 2020 (CISS2020-OL) organised by the Singapore University of Technology and Design (iTrust SUTD). The objective was to attack critical infrastructure in the form of a water treatment plant (SWaT). During the exercise we successfully broke through the IT defences and took direct control of the SCADA HMI system.
Searching for cyber threats
RedEye is our own software, carrying a set of unique detection rules built on years of our experience in both offensive and defensive cybersecurity. RedEye makes it possible to detect the early phases of an attack, before it escalates into information leaks and the covering of the intruder’s tracks. The software also detects attacks that antivirus software does not catch. We offer RedEye together with continuous monitoring as an outsourced SOC service.
OSINT
We perform OSINT engagements (Open-Source Intelligence) where we gather a significant amount of information about the target organisation on the internet. The information obtained can be used to identify potentially vulnerable assets and weak spots that threat actors may choose to target. Information retrieved using OSINT techniques includes details about employees, organisational structure, physical assets, IT infrastructure and more.
Artificial intelligence and machine learning
Effective threat hunting cannot be replaced by artificial intelligence or machine learning. This is also why 0-day vulnerabilities are found by experienced people rather than by AI. The most effective threat hunters are people with deep offensive experience who think like an attacker. To date nobody has demonstrated a working mechanism of artificial intelligence or machine learning capable of replacing experienced cybersecurity experts.
SIEM rules
We create rules for SIEM (Security Information and Event Management) systems, especially for Windows environments. This is part of our threat hunting service, alongside extending logging capabilities, building honeypots and similar work.
CERT, CSIRT
Alongside the SOC service we also offer a CERT/CSIRT service, as well as ad-hoc incident response where a hacking attack has been identified. REDTEAM.PL CERT (RFC 2350) is recognised by the European Union Agency for Cybersecurity (ENISA) as an incident response team, and is a member of Trusted Introducer, the largest international organisation bringing CERT teams together.
Security Operations Center (SOC)
Threat hunting is most often delivered as the third, most expert and final line within a SOC structure.
Why us? Knowledge and experience
The difficulty of proactive threat discovery is captured in the well-known Pyramid of Pain, which treats knowledge of the tools and techniques used by attackers as the hardest aspects of the field. Many methodologies, knowledge bases and models – the Kill Chain and MITRE ATT&CK, for example – describe how hacking attacks unfold, what stages they break into and how that knowledge helps in detecting them. Our professional experience also covers offensive work such as red teaming and penetration testing, confirmed by recognised industry certifications such as OSCP and by numerous references from well-known organisations. Combined with equally extensive experience in computer forensics and incident response – which follows directly from the expert witness opinions we issue and from Adam Ziaja’s book “Praktyczna analiza powłamaniowa” (Practical post-breach analysis) – this gives us a genuinely different perspective on threat detection. We combine expert knowledge of attacks with expert knowledge of analysing them.
It is worth adding that as early as 2013 we built the first Polish system for automated open-source intelligence, that is Cyber Threat Intelligence (CTI). We took part in producing documents for the European Union Agency for Cybersecurity (ENISA) for CERT (Computer Emergency Response Team) units, and while carrying out research on threat detection we performed threat hunting for a US startup building new SIEM/IDS software. Adam Ziaja was a member of the winning team at ENISA Cyber Europe 2014, the largest European cyber defence exercise, and since 2013 has been the only Pole within the internationally recognised non-profit organisation MalwareMustDie, which actively fights cyber threats. That organisation was the first to describe threats such as Kelihos, KINS and Mirai – the latter responsible for the largest DDoS attack in history, generated by IoT devices. In 2019 we detected and analysed the global badWPAD attack, which CERT Polska highlighted in its report “Krajobraz bezpieczeństwa polskiego Internetu” (The security landscape of the Polish internet, pp. 61–62), and we received letters of thanks from the Estonian and Latvian national CERTs.
Rather than taking known APT campaigns apart after the fact, we detect them ourselves, regardless of their origin or chosen target. We have been at the front line of the fight against cybercrime for years, which is also reflected in repeated talks at the annual conference Techniczne Aspekty Przestępczości Teleinformatycznej (Technical Aspects of Cybercrime, TAPT) organised by the Police Academy in Szczytno.
Bringing this breadth of knowledge together, on both attack and defence, we are able to detect attacks at practically any level of sophistication – something that is out of reach for people specialising in defensive cybersecurity alone.
Our publications about threat hunting
Our publications being cited by well-known Polish and international cybersecurity organisations speaks to the level of our qualifications. We have been delivering threat hunting to international standards for years.