logo

NJP

SecBytes (S2E2) : MITRE ATT&CK with ServiceNow

Import · Jun 23, 2022 · video

[Music] chris walker your security doctor back again with another exciting sex bite session now today's theme is brought to you by my pocket protector and of course servicenow with servicenow we want to find different ways to innovate understand and protect your assets using enterprise visibility and of course security operations now in today's demonstration we're going to be discussing how the now platform can connect your information handlers your analysts your threat hunters and even your security leaders to leverage the miter attack module which allows you to track various adversarial techniques leveraged in different stages of a cyber attack so let's go ahead and get right into our agenda for today's topics first and foremost we're going to be talking about what is mitre attack roles required which will be going through the demonstration third we're going to be talking about associating those miter tech techniques to understand how we can actually associate that information to an existing security incident record we're also going to be looking at how we can create the auto extraction rule for those base seam integrations lastly we'll look at miter attack properties this is going to cover a couple of different areas where we have some of those things turned on by default and other areas where we can actually turn on some of the automatic roll up of mitre attack information or that data which can then be posted or appended to those security incidents based on observables or alerts or different sources so let's go ahead and get after it so let's quickly define miter attack as you can see here got it popped up on my screen so it's easy to read but now let's understand how this framework can help your organization or your business now the mitre attack framework is based on understanding these behaviors and techniques that hackers are using against your organization today so it's not only removing the guesswork but it's understanding and really coming up with a proprietary solution of common vocabulary so that you and i can understand and discuss as well as collaborate on how we combat these different adversary methods but more specifically how do we apply this to our security teams and other teams alike so that we can really hone down into proper detection coverage mapping our alert rules but most importantly understand how we track the progression of those detection rules and also making sure we evaluate our current defenses so by leveraging miter attack framework we can track these different attacker groups very similarly to how kevin mcallister was tracking those robbers in the home alone series one of my favorite movies because it really speaks candidly to how we can create a cohesive relationship with the miter attack framework and establish better detection coverage rules mitigation and understand how you have a security plan or in this case your battle plan to protect your assets to protect your users and the integrity of that data it's so important to understand not only the user but the behavior analytics behind the scenes that these hackers are using to exploit weaponize and take advantage of which then of course means data reputation has gone out the door where we could have prevented these measures by using simple mechanics and mechanisms to prevent protect us against all attack vectors equally so with that let's go ahead and get right into today's demonstration around security incident records leveraging the miter attack framework methodology all right we are back we are in my instance for the purposes of the demonstration i am actually using the san diego release this is the latest release that has just come out and i am playing the persona of a security analyst so in terms of the roles that are required here you will need the sn underscore si.analyst role in order to view the security incident record and perform these series of operations which will be pretty quickly uh done and accomplished here so as we can see here we are in my security incident record i'm going to go ahead and associate miter attack information with the observables that we've captured so to simply do that we're going to go ahead and scroll down here to the bottom clicking on show all related lists this is just going to again open up all the different tabs that are available in this form as you can see here that's already been done and then i'm going to click on the associated observables now as the security analyst i need to understand which of these observables have been identified as either malicious or some other type in this case i already know which one has been investigated since i am that threat hunter and i can see here that this particular ip address has actually been deemed as a malicious type of data set so what we're going to do now is i'm going to go ahead and right click on set observable and you'll notice that i have an associate miter attack technique option clicking this will bring up a dialog box prompting me to select something specific in this case the source the tactic and then the series of different techniques now as i mentioned before in the beginning of the presentation we can select multiple tactics and we can obviously associate multiple techniques to a single tactic so this is a great way again to build out your battle plan right just as we mentioned before with kevin mcallister building out his battle plan this allows us to build out that battle plan so then we can see what these associated observables are tied to as it pertains to the tactic to the technique so then we have procedural steps to take actions and preventative measures to further safeguard our users and our datas and all of those entities so to show you very quickly here i've selected the source of enterprise attack my tactic i'm going to add an additional tactic here and i'm going to add one for privilege escalation now as i mentioned before this was a phishing security incident record so there may be some type of privilege escalation that was prioritized in terms of the hacker's eyes so as you can see here we have a number of different techniques that could be associated with this particular tactic again there are so many different techniques that can be associated with these tactics but this allows you as the analyst to understand how we can start to prioritize and mitigate these issues by having everything mapped out through that heat map navigation so i'm going to go ahead and select a random one here just to showcase how easy it is to map and associate this information to the security incident record in this case we're going to associate miter attack techniques to the observable that we've selected so now that we have that done we'll go ahead and click save now the action that's going to take here is it's going to go ahead and append this information to the observable mapping and associating this miter attack information it's going to reload my security incident record and now what i'm able to do as the security analyst is go through and actually see those particular miter attack techniques that have been mapped to this particular security incident record based on the observable that we just updated so as we can see here down below i have a couple of different tabs we have incident details related records but the priority is to look at the miter attack card now as the threat hunter and the analyst i can see that we have a couple of areas of concern we have several different techniques for initial access that have been identified with specific techniques and of course tactics that are taken in order to obtain or gather set information we have two around defensive evasion and then two around reconnaissance now for the purposes of this demonstration i went ahead and manually added and associated this information and we can distinguish that here within the platform we can also see that we also can leverage sim tools that provide this information to automatically roll up and then of course append the information to this particular security incident record we can also show the technique id which is a great value add because now i can actually start to prioritize prevent and measure how well i'm actually detecting and covering these specific areas of concern based on the technique based on those tactics and being able to actually streamline a process to look at these different technique ids in a much more global kind of visible view this is a great way to start prioritizing what's most important and what are the areas that we need to be very hyper focused on as it pertains to the entire miter attack framework and of course your organization's abilities to prevent some of these different attacks these techniques that are actually being posed as a threat with an actual process a plan and a procedure so this is a really great use case and a great area that you can start to leverage right out of the box today all right we're back again to cover the last two topics for today's demonstration now going back to our security incident record what we were able to showcase was the ability to manually add and associate miter attack information such as the tactic and the technique well that's cool and all but i want to automate this stuff so let's go ahead and showcase how we can simply automate that through technique extraction rules so as you can see here on my screen i'm looking at a couple of different extraction rules that have already been predefined because we're using base seam integrations that natively support the ability to parse the payload in this case the raw payload that's coming from these sim tools now that's not to say we can't pull and associate minor information from your threat intelligence feeds or those tools we absolutely can do that again as long as the vendor or the provider has the capabilities to parse this information we can absolutely gather that miter attack technique as well as the tactic and then of course roll that up into your security incident records based on a series of ways either that's through a rule or through a threat lookup or through a child security incident and a number of other methodologies but to keep it pretty simple let's go ahead and just walk you through the miter attack technique extraction rule framework so as we can see here we have a couple of different roles we have one that is actually going to be specific for our splunk integration this is what we call our seam extraction rule so this one is already conditioned and it's predefined it's going through the right areas that we need to pull this information in terms of extracting that through a regular expression method and then of course it's going to then roll this information up to then extract that technique and of course write those records to the import table then from there roll that up into security incident records based on our detection rules so we have this one already pre-configured but what if i wanted to pull this information from a global perspective right from all my threat intelligence integrations so let's go ahead and look at what that would look like here so in this methodology what i'm doing here is when any of these threat intelligence integrations have been configured within your servicenow instance and they support the miter attack framework we can now parse that information at the integration level so i'm going to go ahead and call this test here i have my role type threat lookup and now i'm going to select the global engine setting now when we use this this is the extraction that runs on all threat lookup integration results so not just the one but all the integration results that you have in here so now that we have that all set up and populated we can add our description our comments and then of course at any time we can go ahead and change out the regular expression extractions or tactics but these have already been predefined and we can go ahead and start to use this right away last but not least ignoring auto extraction we know what that does it'll obviously ignore it so by default that is unchecked because we want to go ahead and enable the automatic extraction of the miter attack techniques so once that's done we'll go ahead and hit submit and our rule will be ready to run now from there we need to set up our detection rules this is how we map and associate those techniques to the security incident records so in this particular use case i have a phishing role and i've gone ahead and i've configured the specific tactics and techniques that i want to have associated to said security incident now you can also see that i can pull this from a specific source i could also set this up through an alert sensor so there could be some type of sensor that i want to report on this or in this case i want to go ahead and say if this is in the fishing use case let's go ahead and map that based on the fishing category now that i've mapped that appropriately when we go back right and we rolled up and enabled that property we're able to now see the security incident count so when we go back to our security incident record and we can see the category is fishing what will happen once we've enabled the property our miter attack properties which is the last topic for today we'll actually see this number populated as a one now chris how do i do that well pretty simple we go to our miter attack properties now this can be found in the application navigator here i can see all of the different areas that can be enabled now by default not all of these are enabled and i'll populate a link in here within the description so you can see what each of these different components do but in this particular use case we want to go ahead and make sure that we roll up the information either from the threat lookup results or in this case based on our detection rules so by enabling this property we can map the security incident fields such as category subcategory based on our detection rules and it clearly distinguishes and identifies detection rules minor attack mapping which we were just in so now we can roll up the information we can see which security incidents in that count and we can see exactly what technique and tactic it's being mapped to which of course will then produce our miter attack heat map and navigator this is your kevin mcallister home improvements battle plan now i can protect what i see i understand my coverage my mitigation i can take next steps to be more preventative and proactive to start to increase my coverage as well as how i'm going to mitigate and remediate some of the issues that might fall between the cracks so with that thank you so much i really appreciate you taking the time to go through this miter attack demonstration stay tuned for more content coming from chris walker your security doctor and as always stay safe

View original source

https://www.youtube.com/watch?v=7-mWOOJLir8