The ./havoc Podcast: Recent Episodes

Tom D'Aquino

The ./havoc podcast provides a platform for cybersecurity researchers to share their ideas, experiences and guidance with the cybersecurity community. For the scope of this podcast, the term “cybersecurity researcher” includes anyone that has published a widely available cybersecurity research report, submitted an original CVE record, or developed software that is used by the cybersecurity community. Topic categories include: threat actor research, tactics, techniques & procedures research, vulnerability research, and original red-team/blue-team software works. The content of the ./havoc podcast is delivered in an interview format. In each episode, the podcast’s host, Tom D’Aquino, interviews a guest cybersecurity researcher that recently published/released an original work in which they were either the sole producer of or participated as a pivotal member of the production team. Interview topics include personal interests that motivated the project, the technical aspects of the research involved, additional context that may not be present in the final release, and any lessons learned that the interviewee feels compelled to share.

View Details

In this episode of The ./HAVOC Podcast Microaggressions Series, I review two C2 projects developed by Red Team Developer, Saad Ahla. His VirusTotalC2 and GitHubC2 projects provide an interesting look into varying methods that attackers might employ to abuse trusted APIs for their C2 communications. Check out the links below for more details.

Follow Saad on LinkedIn here: https://www.linkedin.com/in/saad-ahla/

Follow Saad on GitHub here: https://github.com/D1rkMtr

Saad's VirusTotalC2 project: https://github.com/D1rkMtr/VirusTotalC2

Saad's GitHubC2 Project: https://github.com/D1rkMtr/githubC2

View Details

In this episode of The ./havoc Podcast Cybersecurity Research series, Andrew Martin, co-author of Hacking Kubernetes (O'Reilly Media, Inc. ISBN: 9781492081739) provides an in-depth look into how his experience advising clients on securing production Kubernetes clusters resulted in a comprehensive and masterfully written book that any CISO, Security Engineer or Incident Responder responsible for securing and monitoring Kubernetes should not go without.

Hacking Kubernetes book - https://www.oreilly.com/library/view/hacking-kubernetes/9781492081722/, https://www.amazon.com/Hacking-Kubernetes-Threat-Driven-Analysis-Defense/dp/1492081736

OpenUK - https://openuk.uk/
OpenSSF - https://openssf.org/
The Linux Programming Interface - https://nostarch.com/tlpi

Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is comfortable profiling and securing every tier of a bare metal or cloud native system, and has battle-hardened experience delivering containerised solutions to enterprise and government. He is a co-founder at ControlPlane (https://control-plane.io/). Andrew has presented at international conferences including KubeCon, Velocity, SANS, OWASP, DevOpsDays, Container Camp, IPExpo, and numerous other local events and meetups.

Video recording: https://youtu.be/6o9gpB5sCqM

View Details

On this episode of The ./havoc Podcast Microaggressions series, Rod Soto and Marco Palacios, cofounders of the Pacific Hackers Association, discuss their community based approach to helping people (especially veterans and under represented communities) find their way into the cybersecurity industry.

Pacific Hackers Association - https://www.pacifichackers.org/
Pacific Hackers Meetups - https://www.meetup.com/pacifichackers/
Pacific Hackers Conference - https://www.phack.org/

Rod Soto is a Security Researcher and the Co-founder of Hackmiami & Pacific Hackers Meetup, Conference and Association.

Marco Palacios is a Senior Tactical Threat Analyst at Fortinet and Vice-President of Pacific Hackers Association. He started his career in IT and spent over a decade in IT operations before transitioning to cybersecurity. A Blue teamer by heart, Marco has spent the last six years specializing in defending organizations and building and implementing modern Security Operations. Marco is also a co-founder of the non-profit Pacific Hackers Association (PHA). Through the PHA, he personally mentors and advocates for veterans and underrepresented communities to help them find non-traditional paths into the cybersecurity industry. He served in the United States Air Force and deployed as part of “Operation Enduring Freedom.” He holds a Master’s in Cybersecurity and a Bachelor’s in Information Systems.

YouTube video: https://youtu.be/EvjglFly3d0

Video intro image credits:
TechCrunch hackathon photo - https://flic.kr/p/h24TKP
Raised fist photo - https://flic.kr/p/kB4dLM
Creative Commons license - https://creativecommons.org/licenses/by/2.0/

View Details

On this episode of The ./havoc Podcast, guest John Dwyer, Head of Research for the IBM Security X-Force, discusses his work on using PowerShell and Sysmon to hunt for evidence of DLL side-loading. He also provides some valuable insights into how to run a worldclass research organization and what it takes to maintain a healthy flow of useful research content.

Hunting for Evidence of DLL Side-Loading With PowerShell and Sysmon - https://securityintelligence.com/posts/hunting-evidence-dll-side-loading-powershell-sysmon/

SideLoadHunter - https://github.com/XForceIR/SideLoadHunter

Hunting for Windows “Features” with Frida: DLL Sideloading - https://securityintelligence.com/posts/windows-features-dll-sideloading/

Windows Feature Hunter (WFH) - https://github.com/xforcered/WFH

Frida - https://frida.re/

John (@TactiKoolSec) is the Head of Research for the IBM Security X-Force where he leads research efforts to uncover interesting findings based on the work done by the client-facing teams, as well as development projects to improve cross-functional solutions to enhance X-Force service offerings.

As a researcher within X-Force, John focused his efforts on researching adversary operations and developing simulation data to help drive improvements in the areas of incident response and threat hunting. Prior to joining X-Force John was a defensive cyber operations researcher helping the U.S. Army and U.S. Air Force improve incident response operations.

John has spoken at multiple events including the SANS Threat Hunting Summits, ISC2 Security Congress, and Fulbright Commission Cybersecurity Exchange on threat hunting and ransomware operations.

Video recording: https://youtu.be/Uk-cdoV004c

View Details

On this episode of The ./havoc Podcast, guest Jon DiMaggio, Chief Security Strategist at Analyst1 discusses his research that led to the release of two reports - "Ransom Mafia: Analysis of the World's First Ransomware Cartel" and "Absolute Ransom: Nation State Ransomware." Jon's analysis gives an unprecedented look into the relationships and cooperation between multiple ransomware groups and their associations with Russian intelligence services.

Jon DiMaggio is the Chief Security Strategist at Analyst1 and has over 15 years of experience hunting, researching, and writing about advanced cyber threats. As a specialist in enterprise ransomware attacks and nation-state intrusions, such as”Ransom Mafia: Analysis of the World’s first Ransomware Cartel” and “Nation State Ransomware” he has exposed the criminal cartels behind major ransomware attacks, aided law enforcement agencies in federal indictments of nation-state attacks, and discussed his work with The New York Times, Bloomberg, Fox, CNN, Reuters, and Wired. You can find Jon speaking about his research at conferences such as RSA and Blackhat. Additionally, in 2021, Jon authored the book “The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime” published by No Starch Press.

Video recording: https://youtu.be/_5C5tI4QgX0

View Details

On this episode of The ./havoc Podcast, guest Tom Hegel of SentinelOne's SentinelLabs discusses his recently released report ModifiedElephant APT and a Decade of Fabricating Evidence.

The analysis that formed the report is based on the digital forensic investigation results by Arsenal Consulting (along with other sources) that shows "a compromise of defendant systems led to the planting of files that were later used as evidence of terrorism and justification for the defendants’ imprisonment." The details of Arsenal Consulting's digital forensics investigation on behalf of defendant Rona Wilson can be found here.

Tom Hegel is a Senior Threat Researcher with SentinelOne. Working within the SentinelLabs team, his mission is focused on the threat intelligence of global advanced persistent threat activity. He comes from a background of security research, detection engineering, and malware analysis.

Video recording: https://youtu.be/PyFmqs2xGtA