{"id":4911,"date":"2020-06-10T08:07:15","date_gmt":"2020-06-10T06:07:15","guid":{"rendered":"https:\/\/ditech.media\/?p=4911"},"modified":"2020-06-11T09:47:21","modified_gmt":"2020-06-11T07:47:21","slug":"red-team-of-white-hackers-how-crackers-help-business","status":"publish","type":"post","link":"https:\/\/ditech.media\/news\/red-team-of-white-hackers-how-crackers-help-business\/","title":{"rendered":"Red Team of White Hackers: how \u00abcrackers\u00bb help business"},"content":{"rendered":"<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Cyber attacks on banks, states and citizens&#8217; computers have been the commonness for a long time. The word \u201chacker\u201d in the mass consciousness is inextricably linked with the theme of cybercrime. Nevertheless, a hacker is not necessarily an attacker: advanced \u201ccrackers\u201d can not only disturb peace, but also know how to protect it.\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Let&#8217;s talk about white hackers` work and their usefulness for your business.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">\u0421ompanies are interested in protecting data: leaks lead to serious financial and reputational losses. Information security is neither a result nor a condition. This is an ongoing process. In order for the company\u2019s employees, who are responsible for cybersecurity, to be able to timely detect and correctly respond to a gap in the system, it is necessary to constantly increase the professional level of the team.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">The information security market offers several services for analyzing company&#8217;s security: analysis of systems` and applications` security, penetration testing (pentests), assessing personnel awareness of information security issues, etc., but the most effective method, in our opinion, is the method named \u00abRed Team\u00bb*.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">This method is similar to the traditional penetration test (pentest), which is used to check networks, services, systems and wireless access points, but do not mix them up. Pentesting &#8211; assessment of passive security of information systems, Red Teaming &#8211; assessment of active security. Pentest experts visit the customer with scanners and other equipment and, without hiding, try to \u201chack\u201d the system (I\u2019ll say right away that the statistics are disappointing). After checking and analyzing, they write a progress report about the presence of vulnerabilities and also give recommendations for their elimination.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Red Team &#8211; \u201cbattle check\u201d. White hackers have extensive knowledge of attack methods. Firstly, they gain experience during pentests, and secondly, they study the world practice of real hacker attacks. During the Red Team, hackers imitate a real cyber attack. Naturally, an \u201cattack\u201d takes place according to predetermined scenarios and does not interfere with the operation of the company&#8217;s critical information systems. Careful preparation and study of the systems allows the attack to be carried out accurately and as close to reality as possible. This, of course, directly depends on the experience and level of qualification of the Red Team. The exercises and fakeattack are reported to a very narrow circle of people so that the rest of the staff behave naturally.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">The goal of the Red Team, is to achieve the set goals, for example:<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">to penetrate the system, steal data, fix the process of \u201chacking\u201d and tell the \u201cblue team\u201d (customer side) about the mistakes made and ways of eliminating them. It turns out that the knowledge and skills of the \u201cblue team\u201d, the company&#8217;s internal experts, are growing because the \u201cred team\u201d\u00a0 provides an ever-higher level of attacks.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Red team is more time-consuming and labor-intensive than a pentest. But it allows you to solve several problems at once:<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li><span style=\"font-weight: 400;\">inspection of the effectiveness of information security systems used in the company;<\/span><\/li>\n<li><span style=\"font-weight: 400;\"> analysis of the information security department and other employees` actions\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\"> training of internal specialists to prevent errors in the future.<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Another feature of the Red Team method that distinguishes it from other methods of vulnerability analysis is the use of any options for extracting the necessary information to penetrate the system,including methods of social engineering.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">The weakest link in the security of the information system, as you know, is not software or hardware, but the users themselves. Hackers use psychological techniques and behavioral patterns of people to obtain information about access to the system. Despite the fact that the media is actively writing about social engineering and general awareness of this issue is growing, it is not usually found at the level of corporate protection. In addition, the methods of psychological attacks are changing: bulk letters and messages give way to targeted interaction.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">They use phone conversations, friendships on social networks and chatting. We have a successful system hacking case using information obtained in a private corporate chat on WhatsApp in our practice. About the ways, how attackers can get the necessary information we tell during the Red Team cyber orders. By the way, we train not only information security specialists, we increase the cyber literacy of all company employees.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Who should think about conducting &#8220;red team&#8221;? Cyber-orders do not make sense for organizations with an initial level of information security maturity &#8211; too early. Such companies can be limited to traditional services like a pentest or technical audit of information systems. We recommend \u201crediting\u201d to medium and large businesses and organizations of the financial and technical sector, which are traditionally a tidbit for attackers.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">In addition, I want to say that you should not be afraid of conducting exercises, especially to internal security services. The purpose of the audit is not to identify incompetence and lack of expertise, but, on the contrary, to help those involved in the information security of the company, provide maximum protection and increase professionalism during training battles, to always be ready and repel a real attack. As our white hackers like to repeat: it\u2019s hard to cyber training \u2013 it\u2019s easy to cyber battle.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">* The concept of Red Team and Blue Team came to information security from military terminology, where Red Team is a team of attackers, and Blue Team is a team of defenders. In the cybersecurity context, the Blue Team means a team of experts whose mission is to protect the infrastructure.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber attacks on banks, states and citizens&#8217; computers have been the commonness for a long time. The word \u201chacker\u201d in the mass consciousness is inextricably linked with the theme of cybercrime. Nevertheless, a hacker is not necessarily an attacker: advanced \u201ccrackers\u201d can not only disturb peace, but also know how to protect it.\u00a0 Let&#8217;s talk &hellip;<\/p>\n","protected":false},"author":6359,"featured_media":4914,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,157],"tags":[],"_links":{"self":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts\/4911"}],"collection":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/users\/6359"}],"replies":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/comments?post=4911"}],"version-history":[{"count":0,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts\/4911\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/media\/4914"}],"wp:attachment":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/media?parent=4911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/categories?post=4911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/tags?post=4911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}