SIEM

Common Tools Used by Adversaries

Study these tools to find new ways to discover/defend against.

Discovery (Passive)

Stuff you probably won’t see on your network, but could use “against yourself”

Google Dorking

Breach Databases

Discovery (Active)

You might see some of this

Credential Access

Attack Demonstrations

Open Source Attacker Simulation Tools