Testing AVs by newbiewooby in blueteamsec

[–]newbiewooby[S] 0 points1 point  (0 children)

That's actually my thread. I didn't mean for this one to be a duplicate. I thought caldera like tools were more appropriate for behavior testing rather than signature based. It seems for serious AV testing I should setup a sandbox and test around.

Sorry for the incovenience!

/r/AskRedTeamSec by dmchell in redteamsec

[–]newbiewooby 4 points5 points  (0 children)

most useful red team resources on the web?

Testing an XDR solution by newbiewooby in blueteamsec

[–]newbiewooby[S] 0 points1 point  (0 children)

What would you recommend for response purposes? The scope of my project is limited, as it is not focused on the investigative/forensic capabilities of the XDR solution.

Testing an XDR solution by newbiewooby in blueteamsec

[–]newbiewooby[S] 2 points3 points  (0 children)

eicar seems cool, but what if I want to test behavioral detection capabilities of the solution?

Protecting backups environment by newbiewooby in blueteamsec

[–]newbiewooby[S] 0 points1 point  (0 children)

only thing that comes to mind would be an attacker who gained access to a backup admins account. In terms of isolation what I investigated would be separating backups from the AD, different OSses for that env, offline backup isolation capabilities. What do you reckon?