Ants, Bricks and Spiders: Threat Emulation on the VMware Stack
Despite acquisitions, changes in names and pricing models, the VMware private cloud remains a high-value target for threat actors. From ransomware gangs to nation states, breaching vCenter or getting a shell on an ESXi host presents a range of opportunities with new TTPs observed in each campaign. But how can security teams build defences proactively? This talk will provide a guide for conducting threat-led simulations against Broadcom VCF or vSphere environments. We will also introduce a free repository containing a comprehensive collection of 80+ reproducible VMware attack techniques - complete with detection advice. Building on freely available resources and experience from red and purple team engagements, we will aim to empower security teams to turn the tables and defend the target-rich, detection-poor attack surface of VMware stacks.
Speaker

Leo Tsaousis
Senior Security Consultant
Leo is a Senior Security Consultant and Attack Path Mapping lead at Reversec, based in London, UK. His current role involves designing and conducting large scale exercises, while building the team globally and pushing the boundaries of threat simulation. Driven by a passion for offensive research, he frequently blogs about attack techniques in everything from on-premise technologies to cloud, and from mobile platforms to Kubernetes. When not helping SOC teams or leading purple teams for so... read more