
DEFE CON 33 - Deploying Deception in Depth for ICS - Brent Muir
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 22:20
Based on the feedback and the detailed transcript, I've revised the summary to address the gaps and align more closely with the presentation's key messages. Here's the optimized version:
Optimized Summary:
Deception techniques for Industrial Control Systems (ICS) address critical security challenges: overwhelmed security operations centers (SOCs), alert fatigue, and sophisticated threat actors like APT44 that bypass traditional defenses [0:15]. By operationalizing the MITRE Engage framework, organizations can deploy high-fidelity, low-noise detection using existing security controls and open-source tools, avoiding additional technology investments [2:12].
Key Framework Elements:
- MITRE Engage's 9-Stage Approach: Plan, Collect, Detect, Prevent, Direct, Disrupt, Reassure, Motivate, and Analyze [4:11]. This framework structures adversarial engagement by:
- Collecting threat intelligence (TTPs, malware, tools) targeting your environment [4:11].
- Designing & Deploying deception mapped to adversary attack paths [5:55].
- Fine-tuning deployments to eliminate false positives and avoid generating noise [7:28].
- Analyzing results to refine tactics and intelligence [22:08].
Core Deception Tactics for ICS:
- Lures: Decoys like fake documents, API keys, or SSH credentials planted strategically to detect reconnaissance [8:53].
- Personas: Fictional accounts (e.g., AD accounts, LinkedIn profiles) designed to appear legitimate; interactions trigger alerts [8:53].
- Artifacts: Fake system elements (browser history, recent files) to make honeypots indistinguishable from real systems [8:53]. Techniques include:
- Credential Seeding: Injecting fake AD credentials into system memory (e.g., via scripts) accessible only via credential dumping tools [15:13].
- Artifact Diversity: Replicating protocols, applications, and vulnerabilities from the actual environment to maintain authent
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Welcome everyone. Thank you. Um, apologies for my voice. I went to karaoke a few nights ago and it's a bit horsearse. So, um, yeah. Anyway, I hope you're all here for deception for ICS. Otherwise, you're in the wrong room. Time to get out. Um, my name is Brent Muer. I work for Mandant, which is now part of Google uh, cloud security. I've been with Mandant for just over 3 years. Uh prior to that I spent four plus years in uh banking and then prior to that 12 years in government agencies doing DFIR, digital forensics, malware analysis etc etc. These days I work with clients on the proactive side. So hardening environments um you know making their systems a lot more secure than where they started uh including for some IC clients. So we're going to kick off today uh brief agenda. Uh I don't ha…