<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - sans</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/sans/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2018-06-27T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/sans/atom.xml</id>
    <entry xml:lang="en">
        <title>Emerging Cyber Ranges: Competition to Compliance</title>
        <published>2018-06-27T00:00:00+00:00</published>
        <updated>2018-06-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/"/>
        <id>https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons SANS @ Night presentation Emerging Cyber Ranges: Competition
to Compliance, delivered on June 27, 2018, explores how purpose-built
environments can accelerate offensive and defensive security practice, foster
competitive e-sports, and underpin formal compliance and product validation
efforts .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cyber-range&quot;&gt;Cyber Range&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon defines a cyber range as any isolated, refreshable networkvirtual
or physicalused to detonate malware, test exploits, or simulate advanced
threats. He surveys existing platforms from SANS NetWars (both virtual
challenges and the physical CyberCity model) to JYVSECTECs SCADA-focused ranges
and the Michigan Cyber Range, and even the DARPA-led National Cyber Range. Each
example illustrates how controlled environments enable realistic training,
product proof-of-concepts, and large-scale team competitions without risking
production assets .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;principles-to-proof-of-concept&quot;&gt;Principles to Proof of Concept&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the talk shifts to design principles and hands-on constructs. Harmon
outlines key requirementscontainment, auto-scaling, encrypted peer tunnels,
explicit authorization, rapid restoration, and portabilityand presents a
Raspberry Pi-based proof-of-concept leveraging OPNsense, HardenedBSD routing,
iPXE booting, and YubiKey-backed hardware security modules. He also covers
adversary simulation using MITRE CALDERA, Uber Metta, and Netflixs Simian Army,
and shows how cyber ranges can be woven into compliance lifecyclesfrom
requirements gathering through vendor evaluation, baseline verification, and
resilience testingtransforming these playgrounds into governance-grade testbeds
.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;58296_2018-06-27_Cyber_Ranges-SANS_with_Script.pdf&quot;&gt;Cyber Ranges,
Script&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Internet of Everything: Hands-On Cyber Security</title>
        <published>2017-06-21T00:00:00+00:00</published>
        <updated>2017-06-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/"/>
        <id>https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night Internet of Everything workshop on June 21, 2017, by Matthew J.
Harmon frames the cybersecurity challenges posed by a rapidly expanding
landscape of interconnected devices and emphasizes why smart often means
exploitable.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;legal-hurdles&quot;&gt;Legal Hurdles&lt;&#x2F;h2&gt;
&lt;p&gt;Harmon begins by unpacking the legal hurdles around IoT security research
including reverse-engineering restrictions and patent ambiguities and uses an
analogy to routine maintenance to stress the need for continuous device hygiene.
He then quantifies the IoT explosion (8 billion connections in 2016 per Cisco,
460 million responsive IPs in the Carna botnet census) and surveys Shodans index
of exposed smart endpoints. Drawing on the OWASP IoT Attack Surface model, he
breaks down exploitable vectorsdefault credentials, unencrypted data flows,
firmware backdoors, sensor privacy leaksi and poses probing questions (e.g., Is
your dishwasher a web-server?) to underline the urgency of visibility and risk
awareness.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;hands-on&quot;&gt;Hands-On&lt;&#x2F;h2&gt;
&lt;p&gt;In the hands-on segment, participants build a known state monitoring stack:
deploying Security Onion for network visibility; integrating Darkstat and ntopng
for passive traffic analysis; and using Bro for protocol inspection, alongside
OSSEC and Sysmon for host telemetry. Harmon extends the lab with DCIM&#x2F;IPAM via
NetBox and leverages MITREs Cyber Analytics Repository (CAR) and ATT&amp;amp;CK
frameworks to detect lateral movement and prune low-hanging IoT risks. Through
systematic enumeration of devices, data stores, and normal traffic baselines,
the workshop demonstrates how comprehensive visibility transforms an
overwhelming IoT attack surface into manageable, proactive security controls.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57925_2017-06-21_MJH_Internet_of_Everything-SANS.pdf&quot;&gt;SANS @ Night: Internet of Everything
Workshop&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat Intelligence and Baselining</title>
        <published>2016-07-20T00:00:00+00:00</published>
        <updated>2016-07-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night session Threat Intelligence: Neighborhood Watch for Your
Networks &amp;amp; Why Baselining Matters, delivered by Matthew J. Harmon on July 20,
2016, explores how integrating crowdsourced Indicators of Compromise (IoCs) with
rigorous network baselining practices equips defenders to spot, prioritize, and
respond to threats before they escalate .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;state-of-cyber-security&quot;&gt;State of Cyber Security&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon frames the state of cybersecurity emphasizing that breaches are
inevitable against motivated adversaries and introduces the fundamentals of
threat intelligence. He walks through the CIAs 15 Axioms for Intelligence
Analysts, defines IoC types (DNS hosts, IPs, URLs, file hashes), and outlines
the CybOX, STIX, and TAXII standards for packaging and exchanging structured
threat data. A real-world case study shows how to trace a Dyreza banking-trojan
infection from anomalous traffic to phishing emails, package findings into a
STIX header, and share via TAXII. Harmon then compares commercial and
open-source intelligence feedsi ThreatConnect for expert-curated data and
CriticalStack Intel for aggregated TSV-formatted IoCs demonstrating how
organizations can leverage these resources for timely, actionable insight.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;baselining&quot;&gt;Baselining&lt;&#x2F;h2&gt;
&lt;p&gt;Next, the presentation pivots to the critical role of baselining: defenders must
know their normal network behavior to detect deviations. Harmon introduces key
open-source tools Bro (for traffic analysis), PRADS (for asset discovery), SGUIL
(for alert management), and LOKI (for IOC scanning)and shows how they integrate
within the Security Onion distribution. He provides a do-it-yourself lab
outline: install Security Onion, subscribe to CriticalStack feeds, configure Bro
and YARA rules, and deploy a network tap for continuous monitoring. By combining
structured threat intelligence with continuous baselining, organizations can
proactively identify both emerging campaigns and internal anomalies,
dramatically improving detection and response capabilities.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;2016-07-20_Threat_Intelligence_and_Baselining-SANS.pdf&quot;&gt;Threat Intelligence and
Baselining&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat Intelligence: Neighborhood Watch for Your Networks</title>
        <published>2015-07-23T00:00:00+00:00</published>
        <updated>2015-07-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night session Threat Intelligence: Neighborhood Watch for Your
Networks by Matthew J. Harmon introduces the concept of crowdsourced cyber
threat intelligence as a critical component of modern defense. Harmon defines
threat intelligence as the collection of Indicators of Compromise, DNS hosts, IP
addresses, email addresses, URLs, and file hashesi, enriched with contextual
information about campaigns, tactics, techniques, and procedures (TTPs) to
produce actionable insights. He stresses that confidence in data varies from
unvetted open-source feeds to expert-curated platforms and that standardized
formats like CybOX for observables, STIX for structured information, and TAXII
for automated exchange enable seamless sharing across organizational boundaries.&lt;&#x2F;p&gt;
&lt;p&gt;Through a step-by-step case study, Harmon demonstrates how to apply these
standards in practice: identifying excessive traffic on a server, back-tracing
it to a phishing email with a malicious ZIP attachment, extracting MD5 hashes
and C2 IPs, and packaging them into a STIX header with appropriate Course of
Action blocks. He then compares two data-sharing solutions: ThreatConnect, which
offers high-confidence, expert-vetted intelligence via CybOX&#x2F;STIX&#x2F;TAXII; and
CriticalStack Intel, which aggregates over a hundred open-source IoC feeds in
simple tab-separated values for rapid integration with Bro (the network analysis
framework). To reinforce the concepts, Harmon outlines a hands-on lab deploying
Bro or Security Onion, subscribing to Intel feeds, and using bro-cut to validate
detectionsunderscoring the power of a community-driven neighborhood watch to
elevate collective security posture.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57226_2015-07-23_Threat_Intelligence_Neighborhood_Watch-SANS.pdf&quot;&gt;Threat Intelligence: Neighborhood Watch for your
Networks&lt;&#x2F;a&gt;
&lt;a href=&quot;&#x2F;attachments&#x2F;57925_2017-06-21_MJH_Internet_of_Everything-SANS_Script.pdf&quot;&gt;Threat Intelligence: Neighborhood Watch for your Networks,
Script&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
