,

Launching Detecteam

Detecteam is a continuous Breach and Attack Simulation platform to enable you discover attacks you cannot detect.

Have you noticed when an attack is found and described, the vendor’s security research team writes a fairly accurate document, update it over time with new discovers and provide a list of Indicator of Compromises (IoC) in the end of the document?

We have too, and we realized that this information was hard to use:

  • IoC change fairly quickly. Using them is better than nothing, but what matters is capturing the attack logic
  • The attack description describes a logic that cannot be automated
  • Hard to get data for the attack, how does it look like with your Firewall logs? Windows logs? Network traffic (pcap) etc.

This is why we built Detecteam, to provide a platform where Attacks are universaly described and actionable. We created the Breach and Attack Simulation (BAS) programming language to capture the Attack logic and understand all it does, while creating the Data Footprint at the same time!

Because attacks can be described accurately, Detecteam is able to Simulate technologies and provide how the attack would have looked with those various systems. We have a virtual clock which handles the Attack time duration and start time, to then submit to various log analytic platforms, SIEM/SOAR/XDR the data generated so detections can be tested accurately.

This gives to teams a hands-on training to learn and improve the overall Organization’s security posture, but also give to software developer how their detection technology could react with certain attack patterns.

[contact-form-7 id=”f245613″ title=”Newsletter”]

T1003.001 – LSASS Memory T1005 – Data from Local Syste T1012 – Query Registry T1016 – System Network Configuration Discovery T1018 – Remote System Discovery T1021.001 – Remote Desktop Protocol T1021.002 – SMB/Windows Admin Shares T1021.004 – SSH T1027 – Obfuscated Files or Information T1033 – System Owner/User Discovery T1036.005 – Masquerading: Match Legitimate Name or Location T1041 – Exfiltration Over C2 Channel T1047 – Windows Management Instrumentation T1053.005 – Scheduled Task/Job: Scheduled Task T1055 – Process Injection T1057 – Process Discovery T1059 – Command Line Interface T1059.001 – Command and Scripting Interpreter: PowerShell T1059.003 – Windows Command Shell T1069 – Permission Groups Discovery T1069.001 – Local Groups T1069.002 – Domain Groups T1070.004 – File Deletion T1071 – Application Layer Protocol T1071.001 – Web Protocols T1078 – Valid Accounts T1082 – System Information Discovery T1083 – File and Directory Discovery T1087.002 – Domain Account T1105 – Ingress Tool Transfer T1110.001 – Brute Force: Password Guessing T1112 – Modify Registry T1140 – Deobfuscate/Decode Files or Information T1190 – Exploit Public-Facing Application T1204.002 – User Execution: Malicious File T1210 – Exploitation of Remote Services T1218.011 – System Binary Proxy Execution: Rundll32 T1219 – Remote Access Software T1482 – Domain Trust Discovery T1486 – Data Encrypted for Impact T1490 – Inhibit System Recovery T1518.001 – Security Software Discovery T1543.003 – Create or Modify System Process: Windows Service T1566.001 – Phishing: Spearphishing Attachment T1574.002 – DLL Side-Loading