About this talk
This talk focuses on penetration testing and red teaming activities specifically within the healthcare industry. The speaker provides an overview of the types of penetration tests available, including network, application, and mobile device testing, along with the importance of red teaming in identifying vulnerabilities in critical infrastructures. They discuss the preparation involved in conducting penetration tests, including information gathering, exploiting vulnerabilities, and reporting findings. The speaker shares insights from practical experiences, particularly in healthcare settings where the confidentiality and security of patient data are paramount. They emphasize compliance with standards such as HIPAA and GDPR, and highlight the need for effective security operations to monitor potential threats and maintain system availability.
Full transcript
[Music] hi everyone uh thank you for joining today's session uh I'm super excited to introduce an uh he's going to talk about penetration testing um and the red teaming activity specific to the healthcare industry um without further Ado look so thank you for joining us uh would you like to introduce yourself and uh oh and I'll open up your slides yeah thank you thank you um yeah
I will proceed I will short quickly go to an quick agenda and then a quick introduction about me uh in one of the slides and based on that I should be able to proceed Okay cool so agenda is quick about me um I'm s sua from the Netherlands uh remotely join some uh based on the audience just create some slide to discuss some basic uh terminologies what
we are using in red teaming penetration testing uh why we need to have a pen testing um why red teing is important and what uh Scopes we need to check and which type of pentest are available so quickly going through those steps then a part about preparation how to prepare a p penetration test from a penetration tester point of view the use case about Healthcare in an
real uh re teaming exercise when I was involved um and was doing the pen test so we will go bit in depth about it uh some motivation tips and uh at the end you are able to ask questions so uh my profile and who I am is actually uh I Tred to put it in one page um 31 years in it field working uh more than 21
years as a freelancer contractor on several assignment and the last 11 year into the cyber security field some of the roles um I'm still doing or uh um and at the left side you are able to see some of the clients where I'm currently working of have been work some of my cyber security related certifications and at the right side you are able to see some of
the branches uh I'm working mostly currently I'm still on assignment by the Dutch Minister of Defense as a cryptography architect and specialist uh for almost one and a half year uh but uh beside that from my own company soit uh we are also working in India uh with a lot of college and universities uh uh related to cyber security uh and recently add also some Quantum Computing
training into the program so by moving forward a short disclaimer the part is what I try to share in this presentation will be for educational purposes um any errors on any items what uh uh we are mentioning during the slides uh we are not responsible and please uh don't uh try it also um we are not trying to encourage any commercial products uh but just as mentioned
for educational purposes so some of the keywords and terminologies what we are mostly using uh um has will be quickly through it so this is a total overview what we uh are able to know uh where we should be able to do or work in the cyber security field for now we are mostly focusing in offensive part the red teaming the purple teaming uh and the blue
teaming more from the defensive part so more in depth about those and what are the responses and what are that teaming property teaming and blue teaming doing in the upcoming slides so pentesting uh is actually a test or of one or more Computing systems we try to find the F abilities uh and where those F abilities could be we try to make use of it or break
it and with those we are able to exploit it and go into the systems so some of the common keywords is when in some of those will also be mentioned is how we are able to gather information collect the information uh the preparation on is one of the separate uh uh topics I will discuss more in depth about it reporting is important part um try to also
get the information what we are getting from a pen testing uh and mention it also in a risk Matrix Mally for management level uh but also you need to be able to explain it uh on technical level uh to the engineers they need to fix or try to uh solve the issues uh based on those V abilities and Security operation centers are mostly also involved to deal
with the any items related to uh the pen test security issues so here are some of the words what is breach or what is a threat um and how we should be able to proceed based on F ability the weakness I already mentioned and after getting all those we should be able to exploit it um so we we are able to go in depth oint is one
of the keywords also very common use is the open source intelligence where we trying to get the info so by using jgpt Google Etc we are also able to collect information D do um uh distributed service in one of the uh scenarios also we will go in a bit more in depth about DS so by starting we are mostly considering and need also to check uh with
a pen testing with and familiar with this kind of uh keywords what could be in scope of the pentest uh or red teing exercise what are the out Scopes so we are totally not touching to those device is environment or uh Parts where we are not uh able to deal so we are minimizing the scope NDA nondisclosure agreements need to be signed which kind of pentest we
need to consider is it an retest we need to already done by uh the same pentester or a third party and they want to ask you to do the pen test again Security operation centers but collecting all those information we need also to know the what the why the when and how we are able to do it kind of waivers mostly together with ndas and the duration
of the pen test of red teing uh if it hadn't been uh mentioned what kind and what type of pen testing we are able to do here are some of the the most Commons you will see networking websites mobile devices but also mobile apps uh pen testing uh is very common based on applications could be um so those are some of them now these days more a
movement also on cloud uh Cloud applications or Cloud environment where the pen testing need to be done and involving the physical one it's more part of the red teaming uh scope so here uh a fast uh part for an ethical hacker uh so Anis we try to get the information what we are able to get we are doing the scanning phases to scan the for f abilities
or any information that we should be able to collect uh we try to gain the access to those environment uh if we have the access we try to maintain the access don't make sense to uh bypass the security and um if the sock is able to find that someone is into the network they are blocking you directly so you still want to have the access um after
that if you are moving try and we try to clean our tracks also so they are not able to find us um and Reporting but this is the one for EIC but almost the similar kind of approach you will see for a pentester and also for the red teaming where we are still doing the preparation and it can be any any part of preparation a bit more
into the planning need to be considered uh in those situations how to discover is actually to collect the information try to uh get the information attacking uh exploiting the enironment also the reporting and evaluation uh is is almost always the case in those kind of red teing exercises or pen testing or it could be based on the result they fix it and they ask after a few
months or uh weeks how fast they are able to fix it to do a retest um to do the test again and see if problems has been solved or not so bit about the red teaming Technologies uh so that the previous was an overall one is uh where we are dealing with those um actually red teaming is a group of authorized um heers pentesters uh to simulate
the real uh world uh scenarios based on the real tools what they need to have or are able to have and it could also be open source but also commercial tools uh can also be involved and based on the environment uh it could be uh the assignment has to be in the scope that you need to do an active directory pen test or they have a f
system the telephone systems uh the scope can be only on those items or iot mobile devices so actually that could be a criteria or more branches of Parts what can be included the blue teaming is mostly the the the team who are try to defend it or try to monitor what's going on and if they are able to see so in those red teaming we should be
able to be sure that we are on a list and able to connect the environment and the systems um not by starting they will block you uh so those items need to be communicated with the sock teams uh in some situation they are having some models uh or Frameworks they are trying to uh apply could be that for the financial Market they are using PCI theys kind
of Frameworks and some of those need to be considered um could be in scope but also out scope is to set up a Comm of control center from where you are able to Monitor and do all the activities so we are some of them what could be U the part dealing with an red teing so the goals here are some scenarios and a reason why an organization
need to have an uh and what is the goal to do the pen testing the test the security test the inabilities uh is the system in control um that could be uh not only on computers but also test the hardware uh but also the physical access to a building organization or um any of those uh part uh can be one of the goals most of the one
with that is uh not always the case uh there and also provide a solution but Bo based on that they should be able to use a proper P patch management to update and be sure that those items are up to dat so so as I mentioned the preparation steps um are created in several steps let me go quickly to it so um here are the steps again
as I mentioned prepare information gathering F ability management exploit and Reporting and the testing for now the first one uh we will focus on that and I defi that in eight small steps uh where we are able to uh get uh do the planning and and get the information meet the clients or have the meetings what need to be uh pent tested when do we need to
do where do we need to do it and why uh can also and need also be considered in the first step getting the approvals and how we should be able to proceed and after that we should be able to create a documentation so uh in a meeting we try to get the goal what is the reason uh what could be and should be in scope and what
should be automatically uh or be sure that that is out of scope we will not uh deal with those items out of scope um the N discussion uh do we need to sign it or we don't need to sign it mostly in nine of the 10 times we need to sign it and we to agree and getting the formal approval to start with the pen testing which
kind of teams will be involved from the organization point of view uh the networking enger the it Engineers or the manager the security manager or uh and based on the kind of pentest that team can also be defined but also will the sock be informed or will it a a pentest where they don't want to inform the organization and start with your R teaming uh see what
happen uh if you are able to come into the environment is some of the what uh kind of pen testing a blackbox um pen to P pen testing uh where we are able to get very less uh information mostly we are able to get an uh for a website an URL or an IP address and just go away and just start with it and try to uh
come onto the environment or hack the the the website so there are very minimum information you are getting and you need to do and uh collect all the information by yourself the gray boxes you are able to get a part of the information and in a full and a white boxing you will get all the information uh mostly the white boxing is also a kind of uh
code based the pen testing where you should be also go in depth into the code and uh scripting language is what they are using so here a sample for blackbox uh pen testing so we should be able to get the information from the open sources uh as mentioned limited scope IP address or a website URL you will get um you are not getting any inside info who
is the it manager and which kind of network designs they are using will not be in the in the scope um and very less preparation from our site is required and mostly those pen test is depend on the IP addresses the amount of the IP addresses and URLs that could be in hours or in some days uh those kind of pen testes could be done so here
uh what kind I already mentioned quickly about this the type of pen testing uh could be Network website application Cloud apps or a combinations of two three or more of them uh could be included in the scope of the pen testing um and what and this is an sample uh uh for a web application pen testing uh where we try to get information and based on an
uh white box pen testing we should be able to collect all those info before we are able to uh proceed with a pen test so uh here are some of those and which kind of are the designs available low technical design high level uh you call it the source code are we able to get it based on this kind of information and maybe more and more in-depth
info is required to uh before we are able to start with an proper white box pen testing for application so when uh during business hour outside business hour could be weekend depend on the organization uh 24 uh our seven days they are working then they need to uh mention a Time window where we are able to do and that need to be planned uh scheduling the resources
the pent testers not only one pent test it could be that several pent testers are working on it uh in a red teaming exercise mostly will that be a group small group of uh pent testers working on it uh So based on that you should be able to get uh a confirmation and planning um then the question where can it be and should it be onsite uh
if it should be onside then we should be able to get access on it in an uh of course a gray and a white box a black box could be that uh you are not getting and a red teing exercise could be that we don't get access and try to uh figure it out how you are able to come inside the environment the building and to do
your uh uh your pen test offside uh that could be remote um having access or coming through uh internet CX or any of those kind of VPN connection and you are able to uh do your pen test mostly advice will be uh in in both situation especially on remote if it's possible do a communic connection test if you are able to connect to the environment and based
on that that should be able to have access and before the day you are starting with a pent test you are sure that uh access has been uh committed and you are able to proceed I'm facing a lot of situation that um it and the security team mention everything is fine you can just start come Monday morning and you can start Monday morning at 9:00 you with
a client and uh nothing was has been arranged and we even the the physical security don't allow us to come to to the department or go to those side and every part should be uh already uh done so by really starting it took us in some situation one two hours before we are able to start uh so to to be sure that all those stuff has been
arranged in proper way mostly we advice also to do an a pre-check uh if everything kind of Dy when where we are able to do a test before moving to the client and arranging so on the why it could be based on any Frameworks or any audit logs um security auditing what has been done or they are following so it could be that based on those uh
findings our pent test could be uh this part or some of those findings need to be into the uh pen testing where we are need to go in depth uh on those items with the result from the auditing uh security auditing reports the approvals uh need to be done the non-disclosure agreement any kind of waivers uh where we are able to say okay we we get the
commitment to start uh and that in those letter is a sample of letter uh there should be an a date and it will be approved from till here are some of items that need to be uh mentioned and this kind of document and of course each company could have different kind of uh uh layout uh paperwork that need to be signed and approved and mostly it should
be signed and given approval on management level um or coo coo CTO um especially in in in actually red teing as in p uh normal um so those kind of approvals need to be get uh in place before we are able to proceed here are some of the part um uh how we are able to do and when we are doing so we need to have it
could be that some uh extra tooling is required extra resource and softwares are needed uh if you're not dealing daily on any kind of iot pen testing it could be based on those iot def you need to uh get more info about those toolings um you maybe need to update your skills for that uh part um an action plan a checklist already mentioned and do a connection
test before you are able to um after getting all those those document need to be signed and of course uh uh before you are able to proceed uh buet in some situation or invoice or approval on those uh is also one of the part what need to be considered mostly a project leader or or anyone who is leading this kind of pen testing should take care of
all those uh uh items and on number five we from a pentester point of view we don't start if we don't get all those document uh formal approved um to be sure that uh even uh we are getting the assignment to do the pentest but if those documents don't have been approved uh we don't want to argue and discuss about legal issues uh during the pentest or
uh if something happen during the pentest and it can be uh and it's one of the uh possibilities that by doing a simple scan the whole system is not working or the whole network is going down or something like that so to be aware on it so moving forward uh on red teaming pen testing so here is an a quick uh overview uh when I was doing
a pen test uh how it looked like uh so mostly we prepare two laptops uh uh to to go one with all those our toolings and all one could be on for documentation or notes or anything what we should be able or have access to the environment or if it's an interal pantastic sample you need to consider your traveling to go to to onsite if any hardware
it's required could be uh dong um uh devices switches in some situation or or any of those Hardware extra is required you need to take care of it so in some situ mostly we get an an stand up or a daily or just call a briefing about the pentest it's still uh what has been discussed in scope uh what part can we do is all the documentation
ready are we are getting the green line to start with a pen testing or not or we need to wait so by an example to do a pen test on on we need to a blackboxing simple we need to start with the the open source uh info to get in turn on one you are able to do fundability Management Port scanning um with those results you should
be able ble to go in depth find and go in depth about those results what you are able to get use the techniques and the tools what you should be able to use or allowed to use uh in the environment collect those finding make note make your documentation already or make a draft of your notification So based almost end of the day you should be able to
see okay I'm done in one day or I need to come the next day or the coming days because there are so many uh items or so many findings we are able to find um we need to extend the day mostly in our situation even if especially in offices take all your stuff and leave the desk uh empty or as it was um don't uh leave your
notes there um and you should be able to uh proceed so there an average day how would look like next day could be different or uh mostly in some situation you are only starting with uh with with the whole day maybe to prepare the the and discuss about the scoping um so there are some of the uh part during a day when it should be uh and
the most time is mostly on number four where you are doing the fundability port scan and the number five uh where you are going in depth uh and six also use your tools techniques where you are able to collect and get the informations from the systems so another one as a cryptography specialist when I was working a kind of similar kind of approach um in in in
few steps uh travel of go on site having the meeting get the intro uh one but this is mostly to have the technical or the brainstorm session about cryptography or pay or those kind of uh issues what need to be discussed uh and how we are able to give a solution on it um similar kind of preparing having a test environment are we able to use those
certificates on an test environment or not uh or the solution what we want to implement can that be uh deployed can we do the proper full test on a test environment mostly coordination planning especially with the thir party fenders or Partners if you're dealing with Comm on communication level is one of the part what need to be discuss uh technical adjustment so yeah and that could be
you need to create a example certificate or uh configure it install it be sure that the the surface are able to uh accept it and that could be Windows Linux or any any kind of systems where you are able to test it so these are another different kind of role but another kind of approach but there is some similarity discussing preparing coordinating uh not always the indepth
technical part uh but also uh uh with project management and overall is one of the part uh included and du to the time I will go bit quickly um related and actually on comparing if compare F ability management with a pentesters uh who they are the are two separate roles a pentester is mostly almost always doing a affability management but affability manager is not always doing the
whole pen test so here you are able to see some uh difference between those two uh roles uh the same is a bit about the ethical hacking and a pentester where the pentester is getting and going more in depth uh and always to Pro provide also a pentester report um and and pentester is also able to focus bit more about the need from the business uh or
those apps or those application or the uh only those parts so those are some of the differences between those two so as I mentioned red teing red teing is more the offensive the physical security is mostly involved in the almost always involved also in the scope of the red teing you are able to use oent ethical hacking and penetration testing skills are of course required the purple
theme is actually between the blue and the red theming uh they are trying to improve the um detection and the defense so part um coordinated also and the findings and the skills what need to be shared can be shed between those two uh defensive part the sock teams mostly the threat Intel teams uh they are also uh responsible for be sure that uh the damage what the
red teaming are making will be in control and blue teaming are also dealing with the digital forensics investigations related to the uh activities there are more teams uh not very common use but there are some more the white the orange the yellow and the ones here are comparison with the red teaming and the pent tester uh what they are doing so red team exercise can be take
longer uh durations is also a bit more expensive mostly if you because you need to spend more time uh the techniques and the skills could be similar but they are able to go in depth and more adding the physical one where the pent tester normal could be in days weeks and in some situation they are not able to uh they are following some scope and guidance where
red teaming is bit Yeah free to to decide which kind of scoping they need to uh use so moving forward about a critical infrastructures there are some of them uh for I guess this from mostly for Europe uh base uh power electricity P oil gas these are some of the but the healthare is also one of the uh critical one uh we have seen it due to
co how important our Healthcare was so what we are dealing and if you are checking and focusing on that yeah those are the emergency systems uh the fire station the hospitals uh call centers and of course uh police departments all those part will be into environment healthc carees are dealing mostly with heppa compliance it's a compliance from us uh and they are dealing but there are could
be a combination the gdpr example in combination with the hypa So based on those compliance see you should be able to consider of course more but I just highlight that based on those uh guidance we need also to work so they what they are dealing with especially on the healthcare they are dealing with all the health care centers the hospitals of course the it the it teams
who need to provide and be available or giving the support on the healthcare uh computer systems networks um of course the medical devices uh Etc what are important for those environments so by the part by dealing and starting with a red teaming um no short disclaimer I can't disclose the client and then name but some of the client names I can't share uh tool techniques I'm not
able to share everything uh the location and where this pent test has been done I'm also not able to share share somewhere in Europe uh that's only what I can say and the results uh and the the guidance and advice what we have given all not able to share this this an average day don't mean that all the uh P redings are doing this kind of exercise
we know how important this kind of graphs are for us if you especially in the hospital uh due to some uh reason uh so the the doctors need to be aware are able to get all those information but what happen if they are not able to access this system the monitoring part is not working so I guess we as an uh patient there should be able to
face issues uh so this is just an uh image somewhere in the world from an uh uh Healthcare organization um and we try to be sure that we are able to inside the building and do the uh our red teaming exercise so in this situation we discuss with the client with with a goal we discuss on it and we make two approach one is an internal with
together with O to try to get physical access we had cre a plan on about it how we are able to do we discuss also how what will be in scope a bit not in details uh uh the NDA and we need and should provide a report after that and another approach was the external from outside the the the building the hospitals uh try to do a
DS attack on the website what they are using was not the the the corporate website but was the website what they was using for remote working so the the doctors should be able to use uh and make the connection on it so by trying to access uh and having access into the building um we tried to uh before uh coming to the location uh we tried to
find on social medias the employees was working there and which kind of roles they had so there was an whole preparation before the day we are reaching to the to the hospital so we tried to uh make an appointment uh and uh those kind of appointments related to not any part related to pen testing or red teaming we try to get access to the building and how
we should be able to come and go to the environment so by uh so that was not so hard to get uh inside the building and uh to one of the locations was able mostly in in this uh organization if you are already inside you we was able to walk to some uh rooms environments we saw a computer system um we use our USB stick and a
laptop also with us and try to make a connection into one of the computer system just plug off the network cable and pl plug in in the uh laptop so we had a goal we had an action plan we know what to do uh what will be the scope and which kind of combinations we should be able to do the result at that moment was not able
to to get it yet um uh and a report was submitted so oh here so we make a network connection we was able to get an IP address uh into the network on on laptop he was able to do sniffer a bit use a inability scan and um exploit and we the exploit part we was not able and there was in the scope if you found anything
we are not able to do any exploit so please provide us first what happened and what are the weakness and are you able to find anything into this environment so we got one uh cross SK scripting uh uh fundability quick about it and uh we saw also uh an option that uh slow HTTP DS was also possible so based on those two finding we were uh proceeding
here the sample what we use for the DS attacks and based on that we was able to uh get info get and find the whole network INF what they had uh which kind of service was included can't disclose about it this kind of service uh and try to uh go further uh do a Brute Force attack to get an uh uh password uh on on log one
on the system so that only to those part we was able to go and that was also we are able to to get a username and a pass for and we are able to log on in the system so that was one of the finding what we shared with them uh uh to to improve it so the DS attacks uh here a sample how DS attack look
like normally you are sending a normal packages and at that time we are was sending need not the normal but two three times more load to the same environment uh where uh the website was not available anymore so the next Doctor someone who want try to log on was not able to log on so by stopping the Dos attack uh there was a fireball uh behind um
the envirment uh and that recover the system after one minute automatically even the sock was not aware that something happened so we mentioned that your monitoring is maybe not uh strong enough you the sock was not able to get any uh response uh and any uh update on the monitoring any alert that that is a DS attack going on uh or at least the website is not
available even those information they was not able to get so these are also important for us but uh as I mentioned what happen if those systems are not available uh we should be able to consider and I guess a lot of pen testing need to be done uh on in this environment uh especially also FDI deploying new systems making the connection also with Cloud environments so those
items uh need to uh consider proceed so I think few minutes left uh I need to quickly some takeway tips and tips how to uh become a red teer here them sorry join capture the flags uh to learn more handson um have the it uh skills especially on networking if you are doing more networking python or any scripting languages could be uh useful to to learn uh
ENT uh training or part aware about ENT physical securities uh and that physical security can be on a lot of parts uh also part can be uh breaking a lock or how uh uh those kind of Securities are involved um of course if you speak and and conferen and creating preparations you should be able also to prepare if you need to deliver the reports or sharing the
Dort in the presentation almost similar kind you will see on the pentest part and cryptog graphy but it's a separate order kind of role but you will see that encryption decryption where I pentest the r is also aware or should be able to aware uh uh but some other items related to those as been mentioned quick some motivation tips uh here uh what and how we are
able to uh uh proceed um and this is a famous uh uh quote uh where you are able to to know what's going on but we need to understand this applies also for pentesters and ethical hackers or hackers not the ethical one how we are able we need to consider and know how the hackers are trying to get info to the info if you are able to
get that that info or understand how they are able to think about it we should be able to prepare ourself make the chances bigger to uh be sure that you will win battle one of the tips is maybe to compare a cyber security uh expert with the cyber crime one uh the pro and cons has been mentioned uh and activities uh this is one of the europol
and Dutch police and Dutch government uh uh promo what I found were look interesting uh you know you can see and compare those two so our advice of course will please focus on the cyber security expert don't move into the cyber crime area so I've done a lot of certification but even I was able to fill uh sometime um but if you look at this picture with
a lot of certification what I passed I don't think someone should be able to say or can be able to say that I'm a failure uh but the most important part is about failure is uh I Tred it again so after that I was able to pass the same exams uh and learn about it so that make it uh part and advice will be also try to
do this this is one of the quote um my dad was using uh everything we should be aim uh to become a better version of ourself so it's apply for me but hopefully can also be applied for you all so that is my part hopefully I'm not uh taking too time the the time was fantastic um we don't actually have any uh questions right now oh there's
actually one so the last question I popped in there is white listing of source IP mandatory uh isn't it part of the penetration testing to gain access and bypass access lists uh yeah depend um in in some situation we are able to see we are not able to uh we we in advance they saying okay this part is already WID listed um so and getting the info
and go further to do the source code scanning or see what's funil or not correct uh written in the code that could be one part and in some situation they are saying we are not WID listing go and find your own way so uh uh and yeah could be or you are not able to to come directly to that but by bypassing other systems or other parts
from other ways uh you should be able to to to come and get the same info um yeah so that depend on on the scope and what part can be done so yeah yeah this answer I think it did yeah and again what I will say is anyone um after this session who still has outstanding questions uh you know you can reach out Direct to S he's
just put up his details here on screen and unfortunately we've run out of time so no it was a it was a fantastic session I'm just going to close out the thank you notice but again thank you s really honestly it was brilliant session and looking forward to hearing more about this in the future thank you thank you all have a nice day today you too bye
for now