It was entertaining watching people attempt to get past Security @ Blackhat without a badge. Apparently, there are those who have forgotten how to do reconnaissance. When performing reconnaissance of a sensitive target, it is best to survey many times. Foremost, it helps to identify patterns. However, when surveying multiple times, it increases the chance one could be detected. Try to avoid the below issues and you will be on a path towards success.
Do not get caught:
- Filming places not normally recorded. Think if someone came to your property to film your neighbors. Wouldn’t that seem suspicious?
- Lounging in sensitive areas with no valid reasons. When was the last time you let a stranger on your network or yard?
- Holding maps or reconnaissance information with no valid reason. Ask yourself “In the first place, why would someone need this information?”
- Asking strange and/or appear to have abnormally long interest in security personnel, measures/policies/procedures, entry points, ACLs, and/or perimeter information. Enough said here.
- Surveying drills, exercises, and actions of security personnel to any threat, possible or not. See point #12.
- Monitoring scanners, mailing lists, discussions and/or other forms of communication for estimating response times.
- Causing unexplained fire/IDS/IPS alerts. One does wants their target to be relaxed, not paranoid.
- Mapping routes, timing networks, physical routes, and monitoring traffic flow in or near sensitive areas.
- Question security or facility personnel in any lengthy manner. While in accordance with point #12, those should attempt to keep distance from those who must remain vigilant.
- STARE or continually hit the target’s network.
- Do not avert gaze and/or retracing steps. Seems suspicious.
- Appear uncommon, different, and/or out of place. Vendors, shoe shiners, panhandlers, and 3rd party unknown tech support people come to mind. It wouldn’t be fair not to provide counter intelligence.
For those responsible for sensitive areas:
- One should remain vigilant and watch for observation behaviors.
- Use all techniques available such as field interrogation techniques.
- Document incidents to local police, terrorism task force, and or state/local fusion centers.