DEFE CON 33 - Deploying Deception in Depth for ICS - Brent Muir

DEFE CON 33 - Deploying Deception in Depth for ICS - Brent Muir

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 22:20

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Based on the feedback and the detailed transcript, I've revised the summary to address the gaps and align more closely with the presentation's key messages. Here's the optimized version:

Optimized Summary:

Deception techniques for Industrial Control Systems (ICS) address critical security challenges: overwhelmed security operations centers (SOCs), alert fatigue, and sophisticated threat actors like APT44 that bypass traditional defenses [0:15]. By operationalizing the MITRE Engage framework, organizations can deploy high-fidelity, low-noise detection using existing security controls and open-source tools, avoiding additional technology investments [2:12].

Key Framework Elements:

  • MITRE Engage's 9-Stage Approach: Plan, Collect, Detect, Prevent, Direct, Disrupt, Reassure, Motivate, and Analyze [4:11]. This framework structures adversarial engagement by:
    • Collecting threat intelligence (TTPs, malware, tools) targeting your environment [4:11].
    • Designing & Deploying deception mapped to adversary attack paths [5:55].
    • Fine-tuning deployments to eliminate false positives and avoid generating noise [7:28].
    • Analyzing results to refine tactics and intelligence [22:08].

Core Deception Tactics for ICS:

  • Lures: Decoys like fake documents, API keys, or SSH credentials planted strategically to detect reconnaissance [8:53].
  • Personas: Fictional accounts (e.g., AD accounts, LinkedIn profiles) designed to appear legitimate; interactions trigger alerts [8:53].
  • Artifacts: Fake system elements (browser history, recent files) to make honeypots indistinguishable from real systems [8:53]. Techniques include:
    • Credential Seeding: Injecting fake AD credentials into system memory (e.g., via scripts) accessible only via credential dumping tools [15:13].
    • Artifact Diversity: Replicating protocols, applications, and vulnerabilities from the actual environment to maintain authent

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome everyone. Thank you. Um, apologies for my voice. I went to karaoke a few nights ago and it's a bit horsearse. So, um, yeah. Anyway, I hope you're all here for deception for ICS. Otherwise, you're in the wrong room. Time to get out. Um, my name is Brent Muer. I work for Mandant, which is now part of Google uh, cloud security. I've been with Mandant for just over 3 years. Uh prior to that I spent four plus years in uh banking and then prior to that 12 years in government agencies doing DFIR, digital forensics, malware analysis etc etc. These days I work with clients on the proactive side. So hardening environments um you know making their systems a lot more secure than where they started uh including for some IC clients. So we're going to kick off today uh brief agenda. Uh I don't ha…