SAINTCON 2023 - Lee Christensen, Will Schroeder, and Maxwell Harley - Fighting Data With Data

Fighting Data with Data: Nemesis, a platform for aggregating and enriching data from various sources to analyze and respond to threats more efficiently.

Key takeaways
  • Nemesis is a platform that aggregates and enriches data from various sources, allowing operators to analyze and respond to threats more efficiently.
  • The platform uses a semi-structured data model and supports various data types, including files, registry keys, and network logs.
  • Nemesis provides a unified view of data, making it easier to identify patterns and relationships between different data sources.
  • The platform uses a browser-based interface and has a drag-and-drop feature for uploading files.
  • Nemesis integrates with various tools and frameworks, including Cobalt Strike and Bloodhound, to streamline the analysis process.
  • The platform has a focus on passwords, including password cracking and hash extraction.
  • Nemesis has a centralized data processing platform and supports offline analysis, making it suitable for use in environments where internet access is limited.
  • The platform has a Chrome plug-in and supports various file formats, including Office documents and ZIP archives.
  • Nemesis has a series of guides and tutorials to help operators get started with the platform.
  • The platform is designed to be scalable and can handle large amounts of data.
  • Nemesis has a commercial red teaming tool set and is used by red teamers and pentesters to identify vulnerabilities and gather intelligence.
  • The platform is designed to be extensible and can be modified to meet the specific needs of an organization.
  • Nemesis is available under an open-source license and has a community-driven development process.
  • The platform is being used by a variety of organizations, including consulting companies and software development firms.
  • Nemesis is a powerful tool for offensive security professionals and can be used to identify vulnerabilities, gather intelligence, and conduct penetration testing.
  • The platform has a focus on data analysis and reporting, and can produce a variety of reports and visualizations to help operators understand the data.
  • Nemesis is designed to be secure and has a number of security features to protect user data.
  • The platform is being actively developed and is expected to continue to evolve and improve over time.