Frustrating the Adversary: Cisco Talos Researchers Share Practical Ways Defenders Can Thwart Attackers
Cybersecurity Awareness Month is underway, and Cisco Talos researchers are sharing practical ways defenders can frustrate adversaries at different stages of an operation. Deception techniques such as honeypot accounts, false infrastructure, and tarpits can slow adversaries down while giving defenders earlier opportunities to detect their activity.
Behavioral detections, tighter control of legitimate remote-management tools, and clear boundaries around AI agents can make essential adversary actions more visible and easier to interrupt. Breaking dependencies between stages of an operation can prevent an adversary from reaching their next objective.
Cisco Talos blocked an adversary's command-and-control (C2) traffic in the past, prompting a sarcastic tweet from the attacker: 'Write a rule for your a**.'
Adversaries rely on certain advantages, including environments where tools and infrastructure allow them to blend in with normal activity. Strong cybersecurity defenses can change those conditions by taking away adversary choices and increasing the risk attached to essential actions.
Researchers suggest several ways defenders can frustrate adversaries: take away their choices by being unique and setting up their environment differently; use deception techniques such as honeypot accounts or tarpits to slow down attackers; detect what they cannot avoid by creating behavioral detections that account for encoding, transformation, and obfuscation.
Control the tools they hope to use by inventorying remote monitoring and management (RMM) products and blocking unauthorized tools. Controls can be enforced through technologies such as application allowlisting.