Detecting Blue Team Research Through Targeted Ads

DEF CON 26

Presented by: 0x200b
Date: Saturday August 11, 2018
Time: 13:30 - 13:50
Location: Track 2

When my implant gets discovered how will I know? Did the implant stop responding for some benign reason or is the IR team responding? With any luck they'll upload the sample somewhere public so I can find it, but what if I can find out if they start looking for specific bread crumbles in public data sources? At some point without any internal data all blue teams turn to OSINT which puts their searches within view of the advertising industry. In this talk I will detail how I was able to use online advertising to detect when a blue team is hot on my trail.

0x200b

I'm just a Security researcher who's always using tools in unintended ways. I'm a defender by trade, I work on understating the adversary then designing the mitigations based on what I've learned. Currently I work at the intersection of healthcare and the cloud, designing systems that make it harder for the adversary to operate.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats