Modern Red Teaming:�macOS, K8s, and Cloud
Carnal0wnage
int0x80
Chris Gates | carnal0wnage
https://www.linkedin.com/in/chrislgates/
int eighty
int eighty (he/him) is a computer crime enthusiast, and the rapper in Dual Core.
Occasional memes and hacking content as @int0x80.
@wafflesweekly
📸
The Setup
01
How are modern tech companies and startups different from other targets
What’s different?
What’s different?
What’s different?
What’s different?
What’s different?
What’s different?
What’s different?
TL;DR You’ll be dev’ing your own stuff and doing R&D to find bugs
Pre ATT&CK
02
All the Pre stuff according to MITRE
Nothing changed - still gotta do it
Nothing changed - still gotta do it
Nothing changed - still gotta do it
Initial Access
03
Getting in from outside
Initial Access
Initial Access
Initial Access
Important takeaways
📱 > 🐠
Web app vulns
Send 📩to see response
🐠 Phishing�⚠️ Misconfigurations and vulnerabilities
Initial Access Attacks
Thinking outside the cloud – https://t.ly/Ge0Xb
Cast of Characters
04
Common targets to pwn
Network / VPN / Zero Trust
You’ll commonly see people using a VPN to access internal resources, some sort of always on VPN, or “zero trust” where everything is “on the internet”
Network / VPN / Zero Trust
Important takeaways
💡If VPN, steal creds/certs
🕵️♂️💻 If ZT, steal cookies/pivot thru host
💥 There is probably a backup VPN around :-)
💥 Full-contact recon
macOS
Perceived* to be more hardened than Windows
Less published research and weaponized Red Team tools & exploits
Environments can vary drastically
macOS
Usual looting after initial access
Priv escs and persistence exist - review / find TCC vulns or ride approved apps
Dev something for persistence aside from launchagents, still mostly *nix under the hood → dust off some old stuff
macOS
macOS
Important takeaways
🧑💻 Dev your own persistence & priv escs
🕵️♂️💻 Need to develop tooling to find vulns once on target
🔬🦠People aren't sharing / R&D + use TI reports for new ideas
🧑💻 Client-side phishing�🔓 Access restriction mechanisms�🚀 Privilege escalation
Version Control
Version Control
Important takeaways
🕵️♂️💻 Creds in code still a thing
🔍 (overscoped) access tokens can frequently get you entire codebases (monorepos) → Find appsec 🪳
🚀🔬Lines being blurred between version control+CI/CD with integrations/automations
🦠cross-contamination w personal github
🔍 More than repos�🪵 Creds in old commits
CI/CD
CI/CD
CI/CD
CI/CD
CI/CD
CI/CD
Important takeaways
💰Most likely the creds you want are here
💻🛠️ complex and easy to make mistakes = 🪳
💻🖥️🔥(lack of) isolation in shared runners/worker is 👑
🐛 Still software
Kubernetes
Kubernetes
Kubernetes
Kubernetes
Important takeaways
🔐Namespaces can/should be security boundaries but frequently aren’t
🪳vuln images can undo k8s hardening
💻🛠️RBAC is easy to mess up (move fast vs security)
💻🖥️🔥Node isolation between sensitive namespaces
🔎 detections in k8s all over the place/resource intensive
🧠 Persistence
Datastore
Datastore
Important takeaways
🔑🌎 all the data
💰 Common objective�👀 Use an assist
Red Team Stories
05
Adventure time
Stories… not representative of any specific organization
Sasquatch Squad
Hacker, Keys icons by Smashicons - Flaticon | Building, Workstation icons by Freepik - Flaticon | Macbook icon by Irvan Kurnianto - Flaticon | Employees icon by monkik - Flaticon | Loot icon by Eucalyp - Flaticon |
Falcon Bot
Vpn, Hacker icons created by Smashicons - Flaticon | Work icons created by monkik - Flaticon | Phishing icons created by Freepik - Flaticon | Files and folders icons created by iconixar - Flaticon |
10.100.0.20 flink-dev.exmpl.com
Access-Control-Allow-Origin: *
Falcon Bot
Vpn, Hacker icons created by Smashicons - Flaticon | Work icons created by monkik - Flaticon | Phishing icons created by Freepik - Flaticon | Files and folders icons created by iconixar - Flaticon |
CSRF + RCE
Reverse Shell
Sakimori
Hacker, Keys icons by Smashicons - Flaticon | App, Building, Credential, Firewall icons by Freepik - Flaticon | Hub icon by Edi Prast - Flaticon | Employees icon by monkik - Flaticon | Loot icon by Eucalyp - Flaticon |
📦