RE: https://mastodon.social/@Viss/116240791835934578

they loved it.
im doing this format from now on for every tabletop i ever do.

telling them halfway through "oh no, this is real. go look at your logs. go look at your telemetry. its there"

their eyes get to be the size of dinner plates.

completely different story when you make them get out of the chair and go do stuff in meatspace.

fucking awesome, 500/10. would tabletop again.

also having a bunch of dumb/bullshit domain names from back in the hayday of redteaming is super helpful. having a lolballs domain name for your badness to phone home to makes it fun to find

@Viss hax.lol

(also you should set up a stylesheet class for that link instead of hardcoding it in a style attribute, and the element should be inside a div, with the style applied to it)

@krishean im no frontend guy :D - but if you wanna slip me some code i can test it
@krishean css fucks me up pretty bad. once i get like 100 lines into it, it starts getting confusing

@Viss

new line after div>iframe in the stylesheet:

div>a { /* stuff in the style attribute goes here */ }

then just move the link inside the div, above the canvas element without the style attribute on it

@Viss thats awesome Dan. Well done.

@Viss

sounds outstanding! nice!

@paul_ipv6 i think it went really well, and im gonna lean into advertising these things more. they're super fun to do and everyone seems to love em

@Viss

the most popular classes and tutorials i did have folks doing labs and poking on their own machines. things stick better learned that way.

@Viss so you pivoted from a tabletop to a surprise pentest?
@Viss Real logs and actions are what get the analysts to click instead of just the incident managers / commanders.
@Viss Maybe "click" isn't the right word but I think you know what I meant.

@cR0w oh that was the consensus at the end. im nudging them for a testimonal i can stick on the site :D

but everyone in the room was like "yes, having it go to physical - having a real thing to go chase down? that was absolutely awesome"

@Viss I keep wanting to do that with TTXs but don't have the authority to make it happen. 
@cR0w wanna rope me in? :D
@Viss Ha! I can't get them to buy a single Thinkst Canary. I don't think that's going to happen.
@Viss Did a lot of these in DOD. Sometimes in the role of my real job, sometimes playing other roles like SECDEF etc. Ultimately in the big exercises the injects often lead to worst case scenario and everybody dies in the end...
@Nonya_Bidniss heh, the stakes were considerably lower in this exercise - but one of yours sounds like it would be a fun one to do and/or play in! :D

@Viss But you're right, people do get a kick out of the hands-on role play where they have to come up with actions and do them and see whether it works, or what the next surprise is.

BTW, I ran across this one that's open registration right now and cyberspace operations is listed https://www.doctrine.af.mil/Portals/61/AFD35%20Wargame%20Invitation%20Flyer.pdf https://www.doctrine.af.mil/Home/AFD35/AFD35-Wargaming/

@Nonya_Bidniss neat! i wager they wont think twice about me since i have zero .mil experience or .gov experience, but it would be cool to participate in one of those
@Viss Who knows? Can't hurt to ask if it interests you. When I was in the IC we'd constantly invite experts from all kinds of fields & industries to let us pick their brains, give talks, participate in events...they didn't have any connection to govt but they had knowledge we wanted. Anyway if you know someone who might be interested, you can pass it along.
@Nonya_Bidniss i take it this is all volunteer basis stuff?
@Viss Sometimes yes, sometimes there's travel included. It depends. My guess on this one is it's volunteer.
@Viss But I don't know and that would be a question up front whether travel and per diem is covered.

@Nonya_Bidniss @Viss

Given current budgets, not likely they're sponsoring travel. Especially if you don't already have a deep track record.
Getting travel for active .mil students is rough right now.

@johntimaeus @Nonya_Bidniss to me it is extremely suspect, how much money makes it into the military, and how much of it gets to be used for 'computer stuff'

@Viss @Nonya_Bidniss

That's a "we need a quiet patio, and at least one bottle of scotch" evening.
It's amazing how little goes to computer stuff.

@Viss this seems really awesome. How did you accomplish the magic trick of pivoting to a real incident?

@deepthoughts10 my contact there is the head of systems/it so i met him for a burger last week and handed off the router, gave him creds to its wlan. his team plugged it in somewhere, and hung two laptops off its wlan, then gave me creds. it was setup to phone home via vpn so i could get into it and they had something to track, then i orchestrated a bunch of 'evil shit' coming from one of the laptops.

they had to go find them physically

@deepthoughts10 so i had to design the narrative around this fictional visit from some vendor with a demo, which was inside baseball - my contact gave me enough war stories about shit they normally had to do that i was able to craft a storyline that fit the typical shit they would encounter, but then found a nice spot to ask them to go look at their real systems for this thing that up til that point was supposed to be fictional

they found 4 days worth of log data waiting for em :D