1 of 48

Modern Red Teaming:�macOS, K8s, and Cloud

Carnal0wnage

int0x80

2 of 48

Chris Gates | carnal0wnage

  • Offsec since 2007 / IT since 2002
  • Employers relevant to this talk: Facebook (Meta), Uber, Cruise, BitMex, Robinhood
  • Building OFFSEC programs
  • Hacking Boxes & Hacking Consciousness

https://www.linkedin.com/in/chrislgates/

3 of 48

int eighty

int eighty (he/him) is a computer crime enthusiast, and the rapper in Dual Core.

Occasional memes and hacking content as @int0x80.

@wafflesweekly

📸

4 of 48

The Setup

01

How are modern tech companies and startups different from other targets

5 of 48

What’s different?

6 of 48

What’s different?

7 of 48

What’s different?

8 of 48

What’s different?

9 of 48

What’s different?

10 of 48

What’s different?

11 of 48

What’s different?

  • No giant Windows Active Directory
  • (Probably) no Windows endpoints
  • Zero Trust / VPN — no “flat network”
  • macOS for most corp endpoints
  • Kubernetes
  • Cloud (maybe multi cloud)
  • TONS of random other services

TL;DR You’ll be dev’ing your own stuff and doing R&D to find bugs

12 of 48

Pre ATT&CK

02

All the Pre stuff according to MITRE

13 of 48

Nothing changed - still gotta do it

14 of 48

Nothing changed - still gotta do it

15 of 48

Nothing changed - still gotta do it

16 of 48

Initial Access

03

Getting in from outside

17 of 48

Initial Access

  • Cloud vulns, misconfigurations, leaked creds
    • CSRF/SSRF
    • AI/ML software
  • Web application vulnerabilities
  • Single factor things (cred stuffing)
    • Password dumps/breaches/compromised creds
  • Physical access
  • Supply chain compromise
  • Trusted relationships
    • Misuse onboarding flow / MDM

18 of 48

Initial Access

  • Phishing
    • Asking for creds
    • Malicious documents — sandbox escape
    • Installer packages (.app, .dmg, .profile)
    • Executables or binary payloads
    • Malicious scripts a user may be tricked into running
    • Backdoored applications
    • Client RCE
    • Employment-related lures
      • Backdoored coding challenges
    • Legitimate remote access clients
  • Vishing
  • Content Injection
    • Adversary in the Middle
  • 0days

19 of 48

Initial Access

Important takeaways

📱 > 🐠

Web app vulns

Send 📩to see response

🐠 Phishing�⚠️ Misconfigurations and vulnerabilities

20 of 48

Initial Access Attacks

Thinking outside the cloud – https://t.ly/Ge0Xb

21 of 48

Cast of Characters

04

Common targets to pwn

22 of 48

Network / VPN / Zero Trust

You’ll commonly see people using a VPN to access internal resources, some sort of always on VPN, or “zero trust” where everything is “on the internet”

23 of 48

Network / VPN / Zero Trust

Important takeaways

💡If VPN, steal creds/certs

🕵️‍♂️💻 If ZT, steal cookies/pivot thru host

💥 There is probably a backup VPN around :-)

💥 Full-contact recon

24 of 48

macOS

Perceived* to be more hardened than Windows

Less published research and weaponized Red Team tools & exploits

Environments can vary drastically

  • AD / LDAP / No AD (IdP)
  • Managed / Unmanaged / Partially Managed (e.g. Chrome)
  • Draconian software restrictions vs YOLO install whatever

25 of 48

macOS

Usual looting after initial access

  • Not protected: $HOME, ~/.ssh, ~/.aws, ~/.config/gcloud, /tmp
  • Steal cookies and ask for keychain password

Priv escs and persistence exist - review / find TCC vulns or ride approved apps

Dev something for persistence aside from launchagents, still mostly *nix under the hood → dust off some old stuff

26 of 48

macOS

27 of 48

macOS

Important takeaways

🧑‍💻 Dev your own persistence & priv escs

🕵️‍♂️💻 Need to develop tooling to find vulns once on target

🔬🦠People aren't sharing / R&D + use TI reports for new ideas

🧑‍💻 Client-side phishing�🔓 Access restriction mechanisms�🚀 Privilege escalation

28 of 48

Version Control

  • Early 2010s: Bad coding practices
  • Mid+ 2010s: Infrastructure as Code

  • Monorepos are a thing… IDK why

29 of 48

Version Control

Important takeaways

🕵️‍♂️💻 Creds in code still a thing

🔍 (overscoped) access tokens can frequently get you entire codebases (monorepos) → Find appsec 🪳

🚀🔬Lines being blurred between version control+CI/CD with integrations/automations

🦠cross-contamination w personal github

🔍 More than repos�🪵 Creds in old commits

30 of 48

CI/CD

31 of 48

CI/CD

32 of 48

CI/CD

33 of 48

CI/CD

34 of 48

CI/CD

35 of 48

CI/CD

Important takeaways

💰Most likely the creds you want are here

💻🛠️ complex and easy to make mistakes = 🪳

💻🖥️🔥(lack of) isolation in shared runners/worker is 👑

🐛 Still software

36 of 48

Kubernetes

  • Learn it
  • Seriously, LEARN IT

37 of 48

Kubernetes

38 of 48

Kubernetes

39 of 48

Kubernetes

Important takeaways

🔐Namespaces can/should be security boundaries but frequently aren’t

🪳vuln images can undo k8s hardening

💻🛠️RBAC is easy to mess up (move fast vs security)

💻🖥️🔥Node isolation between sensitive namespaces

🔎 detections in k8s all over the place/resource intensive

🧠 Persistence

40 of 48

Datastore

  • Object storage
  • Databases

41 of 48

Datastore

Important takeaways

🔑🌎 all the data

💰 Common objective�👀 Use an assist

42 of 48

Red Team Stories

05

Adventure time

43 of 48

Stories… not representative of any specific organization

44 of 48

Sasquatch Squad

Hacker, Keys icons by Smashicons - Flaticon | Building, Workstation icons by Freepik - Flaticon | Macbook icon by Irvan Kurnianto - Flaticon | Employees icon by monkik - Flaticon | Loot icon by Eucalyp - Flaticon |

45 of 48

Falcon Bot

Vpn, Hacker icons created by Smashicons - Flaticon | Work icons created by monkik - Flaticon | Phishing icons created by Freepik - Flaticon | Files and folders icons created by iconixar - Flaticon |

10.100.0.20 flink-dev.exmpl.com

Access-Control-Allow-Origin: *

46 of 48

Falcon Bot

Vpn, Hacker icons created by Smashicons - Flaticon | Work icons created by monkik - Flaticon | Phishing icons created by Freepik - Flaticon | Files and folders icons created by iconixar - Flaticon |

CSRF + RCE

Reverse Shell

47 of 48

Sakimori

Hacker, Keys icons by Smashicons - Flaticon | App, Building, Credential, Firewall icons by Freepik - Flaticon | Hub icon by Edi Prast - Flaticon | Employees icon by monkik - Flaticon | Loot icon by Eucalyp - Flaticon |

📦

48 of 48

HACK MORE!

Chris Gates

int0x80

We kept this slide for attribution.

CREDITS: This presentation template was created by Slidesgo, including icons by Flaticon, and infographics & images by Freepik.