A few tricks to Anonymizing your Red Team

Patrick Matthews (Penetration Tester)

BSides NYC 2023 (0x04) · Day 1 · Talk - Red

Overview

In the dynamic and often adversarial landscape of cybersecurity, red teams and penetration testers are constantly striving to enhance their effectiveness while maintaining operational security. Patrick Matthews' talk, "A few tricks to Anonymizing your Red Team," delivered at BSides NYC, delves into the critical importance of anonymizing infrastructure and operations to better simulate advanced threat actors. This presentation is particularly relevant for security professionals working with clients who possess sophisticated detection and response capabilities, such as those in critical infrastructure sectors, which are increasingly targeted by state-sponsored and highly organized groups.

Watch on YouTube

Visual summary for A few tricks to Anonymizing your Red Team by Patrick Matthews
Visual summary for A few tricks to Anonymizing your Red Team by Patrick Matthews

Key moments

  1. 0:00 Overview of talk agenda and anonymity goals
  2. 2:00 Defining advanced engagement scope and target types
  3. 3:00 Introduction to the three core anonymity building blocks
  4. 3:30 Using prepaid debit cards for anonymous service payments
  5. 4:50 Recommended VPN services and anonymous purchase methods
  6. 6:20 The role of burner phones in creating proxy accounts
  7. 7:45 Critical advice on avoiding metadata correlation and disclosure

A few tricks to Anonymizing your Red Team

Speakers: Patrick Matthews, Penetration Tester

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=VZDFV1sVh4w

Overview

In the dynamic and often adversarial landscape of cybersecurity, red teams and penetration testers are constantly striving to enhance their effectiveness while maintaining operational security. Patrick Matthews' talk, "A few tricks to Anonymizing your Red Team," delivered at BSides NYC, delves into the critical importance of anonymizing infrastructure and operations to better simulate advanced threat actors. This presentation is particularly relevant for security professionals working with clients who possess sophisticated detection and response capabilities, such as those in critical infrastructure sectors, which are increasingly targeted by state-sponsored and highly organized groups.

Matthews, a seasoned penetration tester with a diverse IT background, emphasizes that effective red teaming isn't about "scaring" clients but about elevating their security posture by challenging their defenses with realistic, untraceable attacks. The talk outlines a comprehensive strategy for achieving this anonymity, covering everything from financial transactions and network infrastructure to physical dropboxes, side channels, social engineering, and the careful management of online presence. It provides actionable insights for red teamers to operate with a reduced digital footprint, making their activities harder to attribute and detect, thereby providing a more accurate assessment of a client's resilience against persistent and well-resourced adversaries.

The core premise is that by adopting the tradecraft of sophisticated threat actors – focusing on passive reconnaissance, careful infrastructure setup, and multi-layered anonymization – red teams can push the boundaries of their engagements. This approach helps organizations identify blind spots that traditional penetration tests might miss, especially when facing an opponent who is meticulous about their operational security and determined to avoid detection. The talk serves as a practical guide for red teamers to refine their methodologies, ensuring their simulated attacks truly mimic the challenges posed by real-world, anonymous threats.

Background

▶ Watch: Overview of talk agenda and anonymity goals (0:00)

The necessity for red teams to operate anonymously stems from the escalating sophistication of modern cybersecurity defenses and the persistent threat landscape. As organizations invest heavily in advanced detection systems, security information and event management (SIEM), and threat intelligence platforms, traditional penetration testing methods can sometimes be easily identified and blocked, diminishing the realism and value of the engagement. Matthews highlights that clients with mature security programs, particularly those in critical infrastructure like energy supply, require red team operations that can evade these advanced capabilities.

Matthews draws a connection to his earlier 2019 talk, which detailed the creation of anonymous companies and profiles by exploiting the "broken trust model of the internet." This foundational work established the building blocks for anonymized infrastructure, which are expanded upon in this presentation. The core components for achieving anonymity, as reiterated by Matthews, include:

  1. Prepaid Debit Cards: These are presented as the "internet's version of cash" for acquiring services without leaving a traceable financial footprint. The key is to avoid cards requiring ID verification or those designed for recharging, opting instead for single-use gift cards. Matthews specifically notes that Amex cards can be less likely to be flagged due to their closed network. These cards can be used for purchasing virtual private servers (VPCs) from providers like DigitalOcean, email services, and VoIP.
  2. Virtual Private Networks (VPNs): Essential for obscuring the operator's true IP address. Matthews recommends providers like Private Internet Access (PIA) and Mullvad, both of which accept gift cards or prepaid debit cards. Mullvad is particularly praised for its privacy-focused approach, even allowing cash payments mailed to Sweden. Matthews advocates for a layered VPN approach, with all household traffic routed through one VPN service, and specific "dirty equipment" using a separate VPN provider.
  3. Burner Phones: Crucial for creating proxy social media accounts and other internet services. These prepaid, cash-rechargeable phones offer a local area code, which is vital for avoiding immediate suspicion when interacting with targets. Matthews stresses that while LTE and smartphone apps offer convenience, they are inherently not anonymous due to tracking services, OS-level data collection, and cell tower triangulation. Metadata management between phone numbers, accounts, and infrastructure is paramount, as threat hunters actively correlate this data to build profiles on penetration testing companies and threat actors. Matthews references threat hunters' use of Adversary Tactics, Techniques, and Procedures (ATTPs) profiles and intelligence feeds beyond the MITRE ATT&CK framework to detect and track activities, underscoring the need for red teams to understand these defensive models.

These foundational elements enable red teams to establish a robust, anonymous operational base, from which more advanced and active anonymized attacks can be launched, moving beyond passive reconnaissance to direct engagement with targets.

Key Findings

▶ Watch: Introduction to the three core anonymity building blocks (3:00)

Matthews' talk reveals several key findings and practical techniques for red teams to enhance their anonymity and operational effectiveness, allowing them to better simulate sophisticated threat actors. These findings span infrastructure, physical deployments, side-channel communications, social engineering, and online presence management:

  1. Foundational Anonymized Infrastructure is Achievable: The talk demonstrates that by meticulously using prepaid debit cards, privacy-focused VPNs, and burner phones, red teams can establish a robust, untraceable infrastructure for purchasing services and managing accounts, significantly reducing their digital footprint.
  2. Self-Destroying Dropboxes Offer Advanced Evasion: Matthews introduces a concept for self-destroying dropboxes using devices like the Nano R1 Pi. These devices are designed to wipe sensitive configuration files and reboot if tampered with (e.g., SD card removal or console cable attachment), providing a critical layer of defense against forensic analysis.
  3. LoRa (Low Range Radio) as an Untraceable Side Channel: A significant finding is the utility of LoRa for command and control (C2) communications. Operating in unregulated frequency bands (e.g., 954 MHz in North America) with ranges up to six miles, LoRa offers a physical layer side channel that is currently "unmonitorable" by traditional network security tools, making it ideal for discreet data exfiltration or C2.
  4. Breach Data Fuels Potent Social Engineering: Matthews highlights how combining publicly available breach data with personal search services (like The HASH and TruePersonSearch) allows red teams to craft highly personalized and convincing social engineering attacks, leveraging targets' personal and professional information to increase click rates for HTML smuggling or credential capture (e.g., with Evilginx).
  5. Proactive Burn Site Avoidance is Essential: The talk details methods to prevent detection of phishing or cloned sites. Key techniques include removing Google trackers, self-hosting files, changing user agents, and understanding how threat hunter tools like SearchStream and Common Crawl monitor new domain registrations and TLS certificates.
  6. Pretext Companies Enhance Credibility and Longevity: Establishing a legitimate-looking online presence through pretext companies (e.g., cybersecurity firms, recruitment agencies) complete with LinkedIn profiles and plausible services, allows red teams to create a believable cover for reconnaissance and phishing operations, making their activities appear less suspicious over extended engagements.
  7. Strategic VPN/Tor Signature Avoidance: Matthews provides practical workflows to bypass common Tor endpoint and VPN signature detections, advocating for simpler methods like tunneling through a Windows RDP session on a VPC or, for more complex scenarios, using a self-signed OpenVPN hidden service on a VPC.

These findings collectively provide a blueprint for red teams to elevate their operational security, enabling them to conduct more realistic and challenging engagements against clients with advanced security postures.

Technical Deep Dive

▶ Watch: Using prepaid debit cards for anonymous service payments (3:30)

The technical depth of Matthews' talk lies in its meticulous breakdown of anonymization techniques across various operational domains.

Anonymized Infrastructure

The foundation of red team anonymity starts with untraceable procurement of resources.

  • Prepaid Debit Cards: Matthews stresses using non-rechargeable, non-ID-verified cards. Amex cards are highlighted as a potentially safer option due to their closed network. These cards are used to acquire virtual private cloud (VPC) services (e.g., DigitalOcean), email accounts, and Voice over IP (VoIP) services. Matthews notes that while obtaining monthly services like Gmail or O365 can be tricky, it's not impossible, sometimes requiring "breaking the payment flow."
  • VPN Services: For network anonymity, Private Internet Access (PIA) and Mullvad are recommended. PIA accepts gift cards and requires only a burner email. Mullvad allows cash by mail or prepaid cards and provides an account number without direct association to the payment method. Matthews employs a multi-layered VPN setup: a primary VPN at home via pfSense, and a separate VPN agent on "dirty equipment" for red team activities.
  • Burner Phones: Essential for establishing proxy social media accounts and other online services. The key is to obtain a phone with a local geographical area code to avoid immediate suspicion. Matthews cautions that while convenient, LTE and smartphone apps are not truly anonymous; metadata from cell tower triangulation, data brokers (like SafeGraph), and OS/app trackers can still disclose location and activity. He advises disabling tracking services and using separate burner phones for engagements.

Self-Destroying Dropboxes

For physical infiltration, Matthews proposes dropboxes designed to resist forensic analysis.

  • Device Choice: The Nano R1 Pi is preferred due to its dual NICs (enabling MAC bypass or man-in-the-middle capabilities), 8GB internal memory, SD slot, Wi-Fi, and USB ports. Its small form factor aids concealment.
  • Self-Destruction Mechanism: The crucial innovation is running the primary OS from internal memory, while a fake OS and config reside on the SD card. A Cron job monitors for two events:
  1. SD card removal: If the SD card is unmounted, sensitive configuration files (e.g., C2 details) are wiped.
  2. Serial cable attachment: This triggers destruction of debug ports or wiping of memory artifacts.

After wiping, the device reboots to clear any remaining data in RAM. This prevents responders from extracting sensitive information by simply pulling the SD card or attaching a console.

  • Egress Communication Concerns: Matthews warns against using LTE modems for egress due to their inherent traceability via IMEI numbers, SIM information, and carrier data retention policies. He cites reports on government agencies (like the FBI, though they claimed to stop) purchasing cell tower metadata from third-party brokers, making LTE tracking trivial.

Unmonitorable Side Channels

To overcome LTE traceability, Matthews explores side channels, with a strong focus on LoRa.

  • Limited Utility Channels:
  • Bluetooth SSH: Supported by some Pi devices, offering 30-300ft range. Practical only for on-site configuration during deployment due to limited range.
  • Zigbee: Another 2.4 GHz option, but Matthews hasn't found practical use for it in this context.
  • Wi-Fi: Can be extended with a Yagi antenna for operational range. However, rogue access point detection and jamming by security systems are significant risks. Blending into existing ESSIDs is crucial. Matthews also mentions S Tunnel as a wrapper to hide SSH traffic from network devices when using a reverse SSH shell.
  • LoRa (Low Range Radio): This is presented as the most practical and "unmonitorable" side channel.
  • Technical Details: Operates in unregulated frequency bands (e.g., 954 MHz in North America), offering approximately six miles range with suitable equipment. It's a physical, proprietary radio communication technique using low power for long range, primarily for IoT devices. It's a serial, half-duplex protocol, meaning custom programming is often required due to small packet sizes. Newer versions offer end-to-end encryption.
  • Operational Modes:
  • Gateway Adapter: Range of 0.5 to 2 miles in urban settings. Allows multiple devices to connect. Options include using a public LoRaWAN service like The Things Network (free for 10 devices, requires prepaid card/burner email, offers authenticated MQTT and multiple endpoint services). Alternatively, self-hosting an open-source LoRaWAN server offers maximum control but requires addressing power and internet connectivity (e.g., the "hollowed-out rock with a solar panel" concept).
  • Point-to-Point: Direct communication between two LoRa devices. AX.25 protocol can be installed to enable TCP services like SSH over LoRa.
  • F-Port Byte: A unique feature of LoRa that allows overcoming message size restrictions. By incrementing the F-Port byte (up to 224), large uplink messages can be broken into smaller chunks, effectively creating a more robust C2 channel. Similarly, the F-Port can distinguish different command types for downlink messages.

Custom Concealments

To physically hide dropboxes, Matthews suggests practical, low-cost methods:

  • Materials: Old bricks, oversized bricks from Goodwill. The challenge is the fixed internal space.
  • Components: Micro AC to DC 5V 2A converters, C14 recessed male adapters (like computer power ports). Learning to cut RJ45 and USB cables is essential for tight fits.
  • 3D Printing: Copying and modifying existing enclosures (e.g., a "sliding box" design or a PoE injector look-alike) is effective. Adding fake labels with a laser printer and clear stickers or using yellow electrical warning stickers enhances believability.

Social Engineering with Breach Data

Matthews outlines a potent method for crafting highly effective phishing attacks.

  • Data Acquisition: Combine breach data services (e.g., The HASH) with personal search services (e.g., TruePersonSearch, which Matthews notes is currently free) to gather targets' current addresses, birth dates, and phone numbers. These services are acquired using prepaid debit cards and burner accounts.
  • Data Correlation: Matthews uses the Accurint breach (2020) as an example, which provided names, home addresses, phone numbers, and work email addresses. By correlating this with current data from personal search services, old addresses can be linked to present ones.
  • Pretexting: To obtain information for personalized emails (e.g., tax time, open enrollment), Matthews suggests calling the HR department of the target company under the guise of selling a new system, asking about current payroll vendors or benefits providers.
  • Phishing Techniques: Using existing phishing samples, cleaning links to company systems, and creating reasonable landing pages. The goal is to make the email appear highly personal and trustworthy, driving targets to click on malicious links for HTML smuggling or credential/session capture (e.g., with Evilginx).
  • Google Dorking: A quick and effective way to confirm target details by searching social media sites with the target's domain name.

Burn Sites and Avoidance

Preventing detection of malicious infrastructure is critical for long-term engagements.

  • Causes of Detection:
  1. Google Tracker: Forgetting to remove Google Analytics or other trackers when cloning a site provides an easy way for threat hunters to link sites.
  2. Monitoring Services: Brand monitors and threat hunter vendors actively scan for newly registered domains, especially those similar to high-profile companies or those with "dodgy" metadata.
  3. TLS Transparency Logs: Services like SearchStream (from Fish Finder) show newly issued TLS certificates in real time, allowing threat hunters to quickly flag suspicious new domains.
  4. Common Crawl Project: Provides monthly snapshots of the web, which can reveal newly created sites, though with a delay.
  • Avoidance Techniques:
  • Kill the Google tracker.
  • Self-host files rather than directly linking to the target's systems.
  • Change the cloner's user agent to mimic normal browsing.
  • Use a proxy when cloning sites.
  • Offensive Use of Threat Hunter Tools: Matthews suggests using SearchStream and Common Crawl offensively to identify typosquatters or high-volume sites with malware redirects, allowing red teams to harvest JavaScript or new infection methods. He gives foxbnews.com as an example of a typosquatted domain.

Pretext Companies

To enhance credibility and provide a cover for operations:

  • Establish a Proper Internet Presence: Create a company (e.g., cybersecurity, tax service, recruitment, even a law firm) with a legitimate-looking website, LinkedIn page, and plausible services. These sites can proxy malicious traffic.
  • LinkedIn Profile Management: Instead of creating new profiles, modify existing ones to match the current pretext, changing job titles and descriptions. Target conference attendees or leverage LinkedIn's suggestion algorithm by temporarily claiming to work for the target company.
  • Anonymous Procurement: Domain registration uses burner phone numbers and emails. Domains are purchased with prepaid debit cards, and infrastructure is hosted on prepaid VPC services.

VPN and Tor Signature Avoidance

For active reconnaissance and C2, bypassing network detections is key.

  • Tor/VPN Endpoint Detection: Many organizations block known Tor exit nodes and VPN endpoints.
  • Simple Bypass: Purchase a VPN service or VPC with prepaid debit cards. Set up a Windows host in the VPC, then RDP to it and surf from there. This minimizes IP leakage and is easier for social media accounts. Always clean logs on the VPC.
  • Complex Bypass: For extreme scenarios, set up an OpenVPN hidden service on your VPC. Connect your "dirty laptop" to the Tor network, then connect to your OpenVPN hidden service (self-signed certificates are fine on Tor). Proxy and surf through this layered setup. Matthews notes this is "overly complicated" for most engagements but demonstrates the possibilities.

The talk concludes with a "story time" scenario involving a fictional energy supply company, illustrating how these techniques – from passive reconnaissance using Zuma (a Shodan-like tool) to social engineering with breach data and the discovery of a spouse who is a retired FBI agent – highlight the critical need for comprehensive anonymization when facing sophisticated targets.

Demo / Proof of Concept

▶ Watch: The role of burner phones in creating proxy accounts (6:20)

While Patrick Matthews did not conduct a live, interactive demonstration during the talk, he extensively referenced and conceptually walked through several proof-of-concept scenarios and underlying technical implementations.

He explicitly states that detailed articles, including proof-of-concept scripts for the Dropbox setup (external egress, Wi-Fi side channel, duck walls, NAT bypass, and the self-destroying script) and the LoRa implementation, are available on Natitude's Labs. This indicates that the technical feasibility and implementation details are well-documented and available for replication.

The "Story Time" segment, rather than a live demo, served as a narrative walkthrough to highlight the practical application of the anonymization techniques discussed. Matthews described a fictional engagement against an "Energy Supply Group" client, detailing how a red team would:

  • Conduct passive reconnaissance using tools like Zuma (a Shodan-like service) to identify Fortinet VPNs, SIP servers, and single-factor sign-in portals.
  • Use physical reconnaissance to identify potential Dropbox deployment locations with open lines of sight for Wi-Fi or LoRa side channels.
  • Leverage The HASH and TruePersonSearch to find breach data and personal information (e.g., current address, birth date, family details) of a target employee, "Seismic Vicker."
  • Craft a personalized email using this data, relying on pre-text domains and avoiding tracking.
  • Discover, through further investigation of the breach data, that the target employee's husband was a retired FBI agent due to mismatched phone numbers and professional associations.

This narrative effectively demonstrated why multi-layered anonymization is crucial, illustrating how unexpected relationships or an adversary's operational security missteps can quickly expose a red team if their infrastructure isn't adequately anonymized. It underscored the talk's central theme: "you never know who knows who or what relationships the targets have."

Defensive Implications

▶ Watch: Critical advice on avoiding metadata correlation and disclosure (7:45)

The insights shared by Patrick Matthews offer critical guidance for defenders looking to bolster their organization's security posture against advanced and anonymous red team operations, or indeed, real-world sophisticated adversaries.

  1. Enhance Monitoring for New Infrastructure:
  • Domain and Certificate Monitoring: Defenders should actively monitor TLS transparency logs (e.g., SearchStream) and new domain registrations (e.g., via Common Crawl) for domains similar to their own or newly registered domains that could be used for phishing. Automated scripts can flag potentially "dirty sites" for investigation.
  • Threat Intelligence Integration: Integrate threat intelligence feeds that track known Tor exit nodes and VPN endpoints into firewalls and Intrusion Detection/Prevention Systems (IDPS) to block inbound connections from these sources.
  1. Physical Security and Device Detection:
  • Rogue Device Detection: Implement and enforce strong rogue access point detection and jamming capabilities for Wi-Fi networks.
  • Physical Audits: Conduct regular physical audits of network infrastructure (e.g., under desks, in less-monitored areas) to detect unauthorized devices that might be disguised as innocuous items (e.g., "Lenovo bricks," custom concealments).
  • Forensic Preparedness: Be aware of self-destroying dropboxes. If a suspicious device is found, assume it might wipe data upon tampering. Consider non-invasive imaging or power-down procedures before attempting forensic analysis.
  1. Employee OpSec and Social Engineering Awareness:
  • Metadata Awareness Training: Educate employees, especially high-value targets, about the dangers of mixing personal and professional information online (e.g., using personal cell numbers for business trips, sharing excessive family details on social media). Emphasize that breach data is a goldmine for attackers.
  • Advanced Phishing Training: Conduct realistic phishing simulations that leverage personalized breach data and pretexts (e.g., tax time, open enrollment) to test employee resilience against highly targeted attacks. Train employees to identify subtle cues in emails, regardless of personalization.
  • HR and IT Pretext Awareness: Inform HR and IT staff about common pretexting techniques used to gather internal information (e.g., calls asking about payroll systems or benefits providers).
  1. Network and Endpoint Detection & Response (EDR):
  • Layered VPN/Tor Detection: While blocking known endpoints is a start, be aware that attackers can tunnel through RDP sessions on VPCs or use self-signed OpenVPN hidden services. Focus on behavioral analytics and anomaly detection for unusual traffic patterns originating from seemingly legitimate cloud services.
  • Side Channel Awareness: While LoRa is currently "unmonitorable" by traditional network security, understanding its capabilities can inform physical security strategies in critical environments. For example, monitoring for unusual radio frequency activity in specific bands (954 MHz in North America) could become a future defensive measure.
  • User Agent and Traffic Anomaly Detection: Monitor logs for unusual user agents or traffic patterns that might indicate automated cloning or reconnaissance tools.
  1. Proactive Threat Hunting:
  • Leverage Adversary Tradecraft: Defenders should familiarize themselves with how red teams and threat actors anonymize their operations. Understanding techniques like using prepaid cards, burner phones, and pretext companies can help identify indicators of compromise (IOCs) that might otherwise be overlooked.
  • Internal Metadata Correlation: Develop and refine internal capabilities to correlate metadata from various sources (network logs, HR data, public records) to identify potential insider threats or compromised accounts that align with threat actor profiles.

By understanding the methods an anonymous red team would employ, organizations can proactively strengthen their defenses, enhance their detection capabilities, and improve their overall resilience against sophisticated, untraceable threats.

Key Takeaways

  • Foundational Anonymized Infrastructure is Paramount: Meticulous use of prepaid debit cards, privacy-focused VPNs, and burner phones is the bedrock for untraceable red team operations, minimizing digital footprints and preventing attribution.
  • Self-Destroying Dropboxes Enhance Physical OpSec: Devices like the Nano R1 Pi can be engineered with self-destruction mechanisms (e.g., wiping data on SD card removal or console access) to prevent forensic analysis upon physical compromise, making them resilient against IR teams.
  • LoRa Offers a Unique, Untraceable C2 Channel: Low Range Radio (LoRa), operating in unregulated frequency bands, provides a currently "unmonitorable" and practical side channel for command and control, ideal for discreet data exfiltration and maintaining persistent access from a significant distance.
  • Breach Data Powers Effective Social Engineering: Combining publicly available breach data with personal search services allows red teams to craft highly personalized and credible phishing campaigns, significantly increasing the likelihood of successful HTML smuggling or credential capture.
  • Proactive Burn Site Avoidance is Critical for Longevity: Red teams must actively manage their online presence by removing Google trackers, self-hosting content, and understanding threat hunter tools like SearchStream to prevent the early detection and burning of phishing or pretext infrastructure.
  • Pretext Companies and Strategic VPN/Tor Usage Elevate Credibility: Establishing a believable online presence through pretext companies and employing layered VPN/VPC setups (potentially with RDP sessions or OpenVPN hidden services) provides a robust cover for reconnaissance and C2, bypassing common signature-based detections.

About the Speaker(s)

Patrick Matthews is a seasoned Penetration Tester whose extensive career in various IT roles has provided him with a comprehensive understanding of technology, which he leverages in his current position. He holds numerous industry certifications, though he humorously states they are primarily for his own improvement rather than impressing others. Beyond his professional life, Matthews is a hobby farmer and beekeeper, describing himself as an "overall force of chaotic good." His diverse background and practical approach are evident in his talks, where he focuses on actionable strategies for improving security testing and operational security.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent, practitioner-level OpSec tradecraft talk that pulls together a coherent anonymization playbook for red teamers — prepaid infrastructure, self-destructing dropboxes, LoRa C2, breach-data social engineering. Nothing here is genuinely novel to anyone who's been paying attention, but it's well-organized and actionable enough to be useful for a BSides audience that hasn't systematized this stuff before.

Heather Calloway (CISO) — WEAK

Technically solid red team tradecraft with real craft behind the LoRa and dropbox work, but the talk never translates operator capability into institutional consequence. A CISO learns nothing about what to do with findings from an engagement this sophisticated, and the governance dimension — what it means for your program if an adversary or red team can operate this quietly against you — is never addressed.

→ Top-rated talks at BSides NYC 2023 (0x04)

All talks from BSides NYC 2023 (0x04)