Full Report
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.
Analysis Summary
# Best Practices: Frustrating the Adversary
## Overview
These practices focus on shifting the economic and operational burden from the defender to the attacker. By implementing deception, breaking attack dependencies, and enforcing behavioral baselines, organizations can force adversaries to abandon their targets due to increased cost, risk, and technical difficulty.
## Key Recommendations
### Immediate Actions
1. **Restrict Administrative Login Paths:** Limit which accounts are permitted to sign into critical servers and alert on unauthorized attempts.
2. **Monitor Admin Groups:** Set immediate alerts for any changes to administrative users or group memberships.
3. **DNS Filtering:** Block known malicious domains and C2 infrastructure using DNS filters or Secure Web Gateways (SWG).
4. **Anti-Urgency Training:** Update security awareness to include "red flag" triggers for manufactured urgency (e.g., requests to bypass MFA or transfer funds immediately).
### Short-term Improvements (1-3 months)
1. **Deploy Deception Accounts:** Create "honeypot" email accounts using expired domains or fake employee profiles to identify early-stage phishing and infrastructure.
2. **RMM Tool Lockdown:** Audit Remote Monitoring and Management (RMM) tools; restrict their use to specific authorized IP ranges and alert on any execution outside of normal admin windows.
3. **Network Tarpits:** Implement false servers, shares, and network spaces to confuse scanners and lateral movement attempts.
4. **Credential Hardening:** Implement unique authentication methods (different from standard SSO) for the most sensitive internal systems.
### Long-term Strategy (3+ months)
1. **Behavioral Detection Engineering:** Shift from signature-based detection (blocking tools like Mimikatz) to behavioral detection (monitoring any access to LSASS memory or credential material).
2. **AI Agent Governance:** Establish "off-switches" and identity boundaries for AI agents, ensuring every automated session has a distinct identity that can be revoked.
3. **Blockchain Infrastructure Control:** If the business has no legitimate use for blockchain, block RPC infrastructure to disrupt modern malware that uses smart contracts for C2.
4. **Environment Uniqueness:** Move away from "default" configurations to ensure the environment does not scale well for automated adversary toolsets.
## Implementation Guidance
### For Small Organizations
- **Focus on Visibility:** Prioritize DNS filtering and basic alerting on admin group changes.
- **Low-Cost Deception:** Use simple "canary" files or fake accounts that should never be accessed.
### For Medium Organizations
- **RMM Control:** Tightly manage legitimate remote tools to prevent "living off the land" attacks.
- **Identity Segregation:** Ensure administrative accounts are separate from daily-use email/web browsing accounts.
### For Large Enterprises
- **Behavioral Auditing:** Deploy advanced detection engineering that looks for the *results* an attacker needs rather than specific file hashes.
- **Infrastructure Disruption:** Actively monitor and block specific smart contract addresses or malicious RPC calls identified by threat intelligence.
## Configuration Examples
- **Active Directory Monitoring:** Enable Auditing for **Event ID 4728** (A member was added to a security-enabled global group) and **Event ID 4732** (A member was added to a security-enabled local group).
- **AI Governance:** Implement a "Kill Switch" for AI agents by mapping every agent to a unique **Service Principal Name (SPN)** that can be disabled instantly without impacting other systems.
## Compliance Alignment
- **NIST CSF:** Aligns with *Detect (DE.CM)* and *Protect (PR.AT)* categories.
- **CIS Controls:** Specifically Control 5 (Account Management) and Control 13 (Network Monitoring and Defense).
- **MITRE ATT&CK:** Directly addresses techniques related to *Lateral Movement* and *Command and Control*.
## Common Pitfalls to Avoid
- **Tool-Centric Detection:** Relying only on blocking specific filenames or hashes, which attackers can change in seconds.
- **Lack of Context:** Setting up honeypots without an alerting pipeline; a honeypot that isn't monitored is useless.
- **Default Trust:** Assuming that activity from legitimate tools (like PowerShell or ScreenConnect) is always safe.
## Resources
- **Talos Intelligence Blog:** `hXXps[:]//blog[.]talosintelligence[.]com/`
- **MITRE Engage:** (Framework for Deception and Adversary Engagement) `hXXps[:]//engage[.]mitre[.]org/`
- **CISA RMM Security Guide:** `hXXps[:]//www[.]cisa[.]gov/resources-tools/resources/remotely-monitored-and-managed-threats`