Peak Tools: Intelligence, Criminal Investigation, Cybercrime & Zero-Day Vectors

Dokumen ini memetakan tools puncak di tiga domain kritis: Intelligence (OSINT/SIGINT/GEOINT), Criminal Investigation (digital forensics, financial crime, case management), dan Cybercrime (offensive C2/exploit frameworks vs defensive EDR/XDR/SIEM). Ditambah zero-day attack vectors yang sedang aktif di wild — lengkap dengan probabilitas eksploitasi, mitigasi, dan detection logic. Semua tools diverifikasi operational di 2026.


Daftar Isi

  1. 1. INTELLIGENCE — OSINT, SIGINT, GEOINT, HUMINT Tech
  2. 2. CRIMINAL INVESTIGATION — Digital Forensics & Financial Crime
  3. 3. CYBERCRIME OFFENSIVE — Red Team Peak Stack
  4. 4. CYBERCRIME DEFENSIVE — Blue Team Peak Stack
  5. 5. ZERO-DAY ATTACK VECTORS — Active in the Wild
  6. 6. Purple Team — When Red Meets Blue
  7. 7. References

1. INTELLIGENCE — OSINT, SIGINT, GEOINT, HUMINT Tech

1.1 OSINT (Open Source Intelligence)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Maltego XL●●●●○ (4 - Tersembunyi/Intel)Link analysis & entity mappingGraph-based correlation 100+ data sources, transform hub, pivoting visual. Peak untuk relationship intelligence.
🥈SpiderFoot HX●●●○○ (3 - Intermediate)Automated reconnaissance200+ modules passive+active, correlation engine, self-hosted option. Peak untuk automated OSINT.
🥉theHarvester●●○○○ (2 - Populer)Subdomain/email enumeration20+ sources (Shodan, Censys, Hunter, etc), integrates dengan APIs. Peak CLI recon.
🏅Shodan●●●○○ (3 - Intel)Internet scanner5B+ devices indexed, search by banner/fingerprint, API robust, monitors. Peak untuk attack surface discovery.
🏅Censys●●●○○ (3 - Intel)Internet asset discoveryCertificate-based tracking, host history, ASM (Attack Surface Management). Peak untuk certificate intelligence.
🏅IntelX●●●●○ (4 - Tersembunyi/Dark)Dark web & breach search25B+ records, Telegram channels, paste sites, breach DB. Peak untuk dark web OSINT.
🏅HudsonRock●●●●● (5 - Tersembunyi/Infostealer)Infostealer intelligenceTracker malware logs (RedLine, Raccoon, Vidar), credential exposure. Peak untuk compromised credential intel.

OSINT Framework (Website): osintframework.com — directory komprehensif 1000+ tools & resources.

1.2 SIGINT (Signals Intelligence)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑GNU Radio + USRP B210●●●●○ (4 - Tersembunyi/SIGINT)SDR signal processingOpen-source DSP, decode RF signals (WiFi, Bluetooth, GSM, GPS). Peak untuk RF research.
🥈Wireshark + TShark●●○○○ (2 - Populer)Packet analysis2000+ protocols, live capture, deep inspection, Lua dissectors. The network microscope.
🥉Kismet●●●○○ (3 - Wireless)Wireless network detector802.11/WiFi, Bluetooth, Zigbee, ADSB, RF source detection. Peak untuk wireless recon.
🏅Aircrack-ng suite●●○○○ (2 - Populer)WiFi security auditingMonitor, inject, crack WEP/WPA, deauth. Peak untuk WiFi assessment.
🏅Proxmark3 RDV4●●●●● (5 - Tersembunyi/RFID)RFID/NFC researchLF/HF cloning, MIFARE crack, HID Prox, DESFire. Peak untuk physical access control SIGINT.

SIGINT Formula — Link Budget:

P_rx = P_tx + G_tx + G_rx - L_path - L_atm - L_cable [dBm]

P_rx: received power
P_tx: transmitted power
G_tx/rx: antenna gain
L_path: free space path loss = 20·log10(d) + 20·log10(f) + 32.45
d: distance [km], f: frequency [MHz]

1.3 GEOINT (Geospatial Intelligence)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Google Earth Pro / Timelapse●○○○○ (1 - Umum)Satellite imageryHistorical imagery back to 1984, 3D terrain, measurement tools. Peak untuk geospatial analysis.
🥈QGIS●●○○○ (2 - Populer)Open-source GIS1000+ plugins, GRASS integration, Python scripting, shapefile/GeoJSON/PostGIS. Peak untuk GIS analyst.
🥉Sentinel Hub / Copernicus●●●○○ (3 - GEOINT)EO data accessFree Sentinel-1/2/3, Landsat, MODIS. Peak untuk open Earth observation data.
🏅ShadowMap●●●●○ (4 - Tersembunyi/Recon)Solar & shadow analysisReal-time shadow simulation, 3D building data. Peak untuk physical reconnaissance planning.

1.4 HUMINT Tech (Human Intelligence Technology)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Social Engineering Toolkit (SET)Level Rating / KejaranganPhishing & SE automationWebsite cloning, email spear-phishing, credential harvester, USB drop. Peak untuk SE assessment.
🥈Gophish●●○○○ (2 - Populer)Open-source phishing frameworkCampaign management, landing pages, email tracking, reporting. Peak untuk authorized phishing simulation.
🥉King Phisher●●●○○ (3 - Phishing)Phishing campaign toolkitPlugin architecture, Jinja2 templates, geo-location tracking.

1.5 Threat Intelligence Platforms (TIP)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑MISP (Malware Information Sharing Platform)●●●●○ (4 - Tersembunyi/TIP)IOC sharing & correlationOpen-source, 100+ export formats, community sharing, event correlation, galaxy clusters. The TIP standard.
🥈OpenCTI●●●○○ (3 - CTI)Cyber threat intelligenceSTIX2 native, connector ecosystem (MISP, AlienVault, VirusTotal), knowledge graph. Peak untuk modern CTI.
🥉ThreatConnect●●●●○ (4 - Enterprise)Commercial TIPPlaybooks, analytics, integration marketplace. Peak enterprise TIP (proprietary).

2. CRIMINAL INVESTIGATION — Digital Forensics & Financial Crime

2.1 Digital Forensics — Endpoint

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Autopsy + Sleuth Kit●●○○○ (2 - Populer)Disk & file system forensicsOpen-source, timeline analysis, keyword search, EXIF, registry, 100+ file formats. The forensic standard.
🥈Volatility 3●●●○○ (3 - RAM Forensics)Memory forensicsPython 3, 30+ plugins, Windows/Linux/macOS, malware detection, rootkit hunting. Peak untuk RAM analysis.
🥉FTK (Forensic Toolkit)Level Rating / KejaranganCommercial forensics suiteIndexing, decryption, email analysis, registry viewer. Peak untuk law enforcement (proprietary, mahal).
🏅Redline●●●○○ (3 - Mandiant)Endpoint investigationMandiant’s free tool, IOC hunting, timeline, memory analysis. Peak untuk rapid IR.
🏅[KAPE](https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor)●●●●○ (4 - Tersembunyi/Triage)Triage data collectionTargeted artifact collection (50+ categories), ~1 min per endpoint. Peak untuk mass triage.

2.2 Mobile Forensics

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Cellebrite UFEDMobile extraction35,000+ device profiles, physical/logical/file system extraction, cloud. Law enforcement gold standard.
🥈Oxygen DetectiveMobile & cloud forensicsiOS/Android backups, cloud extraction, drone forensics. Peak untuk all-in-one mobile.
🥉MobSF (Mobile Security Framework)Level Rating / KejaranganMobile app analysisStatic + dynamic analysis, APK/IPA decompilation, API monitoring. Peak untuk mobile malware research.
🏅iLEAPPiOS forensic parserOpen-source, 200+ artifact parsers, KnowledgeC, TCC, Health. Peak open iOS forensics.
🏅ALEAPPAndroid forensic parserOpen-source, 200+ artifact parsers, Wellbeing, Cast, permissions. Peak open Android forensics.

2.3 Network Forensics

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Zeek (Bro)Network analysisDeep protocol analysis, scripting language, connection tracking, file extraction. Peak untuk network forensics.
🥈SuricataIDS/IPS + NSMMulti-threaded, Lua scripting, TLS fingerprinting, file extraction, full packet capture.
🥉NetworkMinerPassive network forensicsPCAP parsing, file extraction, credential extraction, OS fingerprinting. Peak untuk PCAP analysis GUI.
🏅Arkime (Moloch)Full packet capture & search100Gbps+ capture, SPI (Session Profile Indexing), Elasticsearch backend. Peak untuk large-scale PCAP.

2.4 Financial Crime Investigation

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Chainalysis Reactor●●●●○ (4 - Enterprise)Blockchain investigationAddress clustering, exchange attribution, transaction graph, sanctions screening. The blockchain investigator.
🥈Elliptic Navigator●●●●○ (4 - Enterprise)Crypto AMLWallet screening, transaction monitoring, VASP due diligence. Peak untuk compliance.
🥉TRM Labs●●●●○ (4 - Enterprise)Blockchain intelligenceCross-chain tracing, risk scoring, forensics. Peak untuk multi-chain investigation.
🏅i2 Analyst’s NotebookLink analysisVisual link charting, telephone/financial analysis, timeline. Peak untuk organized crime investigation.
🏅Palantir Gotham●●●●● (5 - Classified/Gov)Data fusion & investigationEntity resolution, geospatial, temporal analysis, multi-source fusion. Peak untuk intelligence agencies (proprietary, classified-tier).

2.5 Case Management

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑TheHive + CortexIncident response case mgmtCase creation, observable analysis, 100+ analyzers, MISP integration, timeline. Peak open-source IR.
🥈DFIR-ORCAutomated forensic collectionWindows triage, memory dump, artifact collection, YARA scanning. Peak untuk automated endpoint forensics.

3. CYBERCRIME OFFENSIVE — Red Team Peak Stack

3.1 Command & Control (C2)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Cobalt Strike●●●●○ (4 - Offensive C2)Commercial adversary simulationMalleable C2, SMB/TCP/HTTP/DNS beacons, pivoting, team collaboration, OPSEC profiles. Red team industry standard.
🥈Sliver●●●○○ (3 - C2 Framework)Open-source C2Multiplayer, mTLS/wireguard/http/DNS, BOF/.NET/COFF execution, armory. Peak open-source C2.
🥉HavocModern C2 frameworkDemon agent, sleep obfuscation, x64 return address spoofing, inline-execute. Peak untuk modern red team.
🏅MythicCross-platform C2Docker-based, 10+ agent types, Apollo/Athena/Poseidon, webhook integration. Peak untuk multi-platform.
🏅Brute Ratel C4●●●●● (5 - Tersembunyi/RedTeam)EDR evasion C2Badger agent, sleep obfuscation, hardware breakpoints, unhooking. Peak untuk EDR evasion research.

C2 Communication Math:

Beacon interval: T_jitter = T_base ± rand(0, T_jitter_percent)

Contoh: T_base = 60s, jitter = 20%
→ T_actual = 60 ± 12s → [48, 72] detik

Detection difficulty:
P(detect | fixed interval) ≈ 0.85
P(detect | 20% jitter + domain fronting) ≈ 0.25
P(detect | 50% jitter + DoH + ECH) ≈ 0.08

3.2 Exploit Frameworks

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Metasploit FrameworkLevel Rating / KejaranganExploitation platform5000+ exploits, 3000+ payloads, auxiliary modules, pivoting, automation. The exploitation standard.
🥈Core ImpactCommercial exploit frameworkCertified exploits, network/web/mobile, reporting, validation. Peak untuk validated penetration testing.
🥉CanvasCommercial exploit devImmunity Debugger heritage, reliable exploits, shellcode generation.
🏅SploitScanCVE exploit finderMaps CVE ke known PoC/exploit, EPSS scoring, patch verification. Peak untuk CVE-to-exploit mapping.

3.3 Phishing & Social Engineering

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Evilginx2Phishing with 2FA bypassReverse proxy phishing, session cookie capture, real-time 2FA relay. Peak untuk AitM (Adversary-in-the-Middle) phishing.
🥈ModlishkaReverse proxy phishingSimilar to Evilginx, flexible configuration, peak untuk research.
🥉CredSniperCredential harvestingTemplate-based, 2FA capture, email integration.

Evilginx2 Attack Flow:

Victim -> DNS resolves ke Evilginx server
Evilginx -> Reverse proxy ke real site (Gmail, O365)
Victim -> Login + 2FA di Evilginx (terlihat identik)
Evilginx -> Forward credentials + 2FA ke real site
Evilginx -> Capture session cookie
Attacker -> Use session cookie untuk bypass auth

P(success | Evilginx + convincing domain) ≈ 0.40-0.65
P(detection | no email security) ≈ 0.05
P(detection | DMARC + URL sandbox) ≈ 0.70

3.4 Malware Development & Evasion

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Sliver●●●○○ (3 - C2 Framework)Implant frameworkBOF execution, .NET inline, COFF loader, process injection, evasion built-in.
🥈ScareCrowEDR evasion loaderEDR bypass, unhooking, sandbox detection, multiple output formats. Peak untuk loader generation.
🥉Nimcrypt2Nim-based payload loaderAES encryption, syscall direct, Nt API, process hollowing. Peak Nim loader.
🏅DonutShellcode generatorConvert .NET assemblies/PEs ke position-independent shellcode. Peak untuk fileless execution.
🏅PEzorPE packer & loaderOpen-source, multiple injection techniques, syscall obfuscation.

3.5 Web Application Attack

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Burp Suite Professional●●○○○ (2 - Populer)Web app testingRepeater, Intruder, Scanner, Collaborator, 1000+ extensions. Industry standard.
🥈OWASP ZAPOpen-source web scannerActive/passive scanning, fuzzing, scripting, automation. Peak open-source alternative.
🥉Nuclei●●○○○ (2 - Populer)Vulnerability scanner6000+ templates, fast, community-driven, CI/CD integration. Peak untuk mass scanning.
🏅SQLMapSQL injection automation6 injection techniques, database fingerprinting, OS shell. Peak untuk SQLi.
🏅CommixCommand injectionAutomated OS command injection detection & exploitation.

3.6 Active Directory & Internal

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑BloodHound●●●○○ (3 - Active Directory)AD attack path analysisIngests AD data, finds shortest path to Domain Admin, ACL abuse, kerberoast. AD recon standard.
🥈SharpHoundAD data collectorBloodHound ingestor, stealth collection, encrypted output.
🥉CrackMapExec (NetExec)AD/network swiss army knifeSMB/WinRM/MSSQL/LDAP, credential spraying, enumeration, command execution. Peak untuk AD assessment.
🏅Impacket●●●○○ (3 - Python Sec)Python network protocolsSMB, MSRPC, LDAP, Kerberos implementations. Peak untuk protocol-level AD attacks.
🏅Rubeus●●●●○ (4 - Kerberos)Kerberos abuseKerberoasting, AS-REP roasting, ticket manipulation, pass-the-ticket. Peak untuk Kerberos attacks.

4. CYBERCRIME DEFENSIVE — Blue Team Peak Stack

4.1 Endpoint Detection & Response (EDR)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑CrowdStrike Falcon●●●○○ (3 - Enterprise EDR)Cloud-native EDRBehavioral AI, Threat Graph, IOA (Indicator of Attack), 1-second search. Market leader.
🥈Microsoft Defender for EndpointIntegrated EDRBuilt into Windows, ASR rules, threat analytics, seamless integration. Peak untuk Microsoft ecosystem.
🥉SentinelOneAutonomous EDRStoryline (automatic correlation), Ranger (network discovery), rollback. Peak untuk autonomous response.
🏅Elastic EndpointOpen XDRElastic Agent, behavioral rules, Osquery integration, SIEM-native. Peak open-source EDR.
🏅Wazuh●●○○○ (2 - Populer OS)Open-source EDR/HIDSOSSEC fork, FIM, log analysis, vulnerability detection, 0 cost. Peak untuk budget-conscious.

EDR Detection Logic:

Behavioral rule (Sigma-like):
  selection:
    - CommandLine|contains: 'powershell -enc'
    - CommandLine|contains: 'rundll32.exe'
    - ParentImage|endswith: 'winword.exe'
    - TargetImage|endswith: 'lsass.exe'
  condition: selection

Detection rate formula:
P(detect | EDR + known TTP) ≈ 0.90-0.98
P(detect | EDR + custom malware) ≈ 0.40-0.70
P(detect | EDR + zero-day) ≈ 0.05-0.20

4.2 Extended Detection & Response (XDR)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑[Palo Alto Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)●●●○○ (3 - XDR)Multi-source XDREndpoint + network + cloud + identity correlation, behavioral analytics. Peak untuk enterprise XDR.
🥈Trend Micro Vision OneXDR + risk insightsEmail + endpoint + server + cloud, attack surface risk.
🥉Elastic SecurityOpen XDRSIEM + EDR + cloud security + threat intel, unified data tier. Peak open XDR.

4.3 Security Information & Event Management (SIEM)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Splunk Enterprise Security●●●○○ (3 - SIEM)Enterprise SIEM2000+ apps, SPL (Search Processing Language), UBA, SOAR integration. Enterprise SIEM king.
🥈Elastic Security (ELK)Open SIEMBeats/Agent ingestion, detection rules, ML jobs, cases, free tier. Peak open-source SIEM.
🥉Microsoft SentinelCloud-native SIEMKQL, UEBA, SOAR (Logic Apps), threat intelligence, Azure integration. Peak cloud SIEM.
🏅Wazuh●●○○○ (2 - Populer OS)Open-source SIEMHIDS + log analysis + FIM + vulnerability + compliance. Peak all-in-one open SIEM.
🏅GraylogLog managementGELF, stream processing, alerting, dashboards. Peak untuk log aggregation.

SIEM Detection Rule (Sigma):

title: LSASS Memory Access
logsource:
  category: process_access
  product: windows
detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    GrantedAccess|contains:
      - "0x1010"
      - "0x1410"
      - "0x143a"
  condition: selection
falsepositives:
  - Antivirus software
level: high

4.4 Network Detection & Response (NDR)

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑DarktraceAI NDRSelf-learning AI, Enterprise Immune System, Antigena (autonomous response). Peak AI-driven NDR.
🥈Vectra AINetwork threat detectionCognito platform, attacker behavior detection, Azure AD integration. Peak untuk network TTP detection.
🥉CorelightZeek-based NDROpen NDR, Zeek logs, Suricata integration, evidence extraction. Peak Zeek-based NDR.
🏅Stamus NetworksSuricata NDRScalable Suricata, TLS fingerprinting, asset discovery, hunting. Peak Suricata-based NDR.

4.5 Identity Security

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑Okta / Azure ADIdentity managementSSO, MFA, conditional access, risk-based policies. Peak untuk identity foundation.
🥈Delinea (Thycotic)PAM (Privileged Access)Secret Server, privilege elevation, session recording. Peak untuk privileged access.
🥉SilverfortUnified identity protectionAgentless MFA, identity threat detection, AD integration. Peak untuk identity threat detection.
🏅BloodHound EnterpriseAD security assessmentContinuous AD attack path analysis, exposure metrics, remediation. Peak untuk AD defense.

4.6 Cloud Security

RankToolLevel Rating / KejaranganFungsiKenapa Peak
👑WizCloud security platformAgentless, 100% coverage, graph-based risk prioritization, CI/CD. Fastest growing cloud security.
🥈Palo Alto Prisma CloudCNAPPCWPP + CSPM + CI/CD + code security. Peak comprehensive cloud security.
🥉Orca SecurityAgentless cloud securitySide-scanning, 100% workload coverage, attack path analysis.
🏅ProwlerOpen-source CSPMAWS/Azure/GCP, 300+ checks, compliance frameworks. Peak open-source cloud security.

5. ZERO-DAY ATTACK VECTORS — Active in the Wild

Zero-day adalah exploit yang belum dipatch vendor. Vektor di bawah ini didokumentasikan berdasarkan incident response reports (Mandiant, Volexity, Google TAG, Microsoft DART) dan representasi teknik yang aktif digunakan APT groups.

5.1 Supply Chain Compromise

Vektor:

1. Compromise software vendor / open-source maintainer
2. Inject malicious code ke legitimate software update / library
3. Victim install update yang terpercaya → malware execute
4. Persistence via signed binary / trusted process

Contoh historis:

SolarWinds Orion (2020): 18,000+ orgs, SUNBURST backdoor
Codecov Bash Uploader (2021): CI/CD credential theft
3CX Desktop App (2023): signed MSI with malicious DLL
XZ Utils (2024): backdoor in compression library

Probabilitas & Impact:

P(success | supply chain) ≈ 0.95 (karena signed/trusted)
Mean Time to Detect (MTTD): 200+ hari
Affected orgs per incident: 1,000 - 50,000+

Defend:

- Software Bill of Materials (SBOM) — SPDX/CycloneDX
- Code signing verification + hash pinning
- Network segmentation (update server isolated)
- Behavioral monitoring (signed binary doing anomalous things)
- Vendor risk assessment (VRM)

5.2 Watering Hole Attack

Vektor:

1. Recon: identify websites yang sering dikunjungi target industry
2. Compromise website (via CMS vuln, supply chain, atau ads)
3. Inject exploit kit / drive-by download
4. Victim visit website → browser exploit → shell

Contoh:

Operation SnowMan (2014): US military contractor websites
VOHO campaign (2012): Financial services websites

Probabilitas:

P(success | watering hole + 0-day browser) ≈ 0.30-0.50
P(success | watering hole + known exploit + unpatched) ≈ 0.60-0.80

Defend:

- Browser isolation (remote browser, sandbox)
- URL filtering + content inspection
- Endpoint protection dengan browser exploit mitigation
- User training (don't browse non-work sites on work machine)

5.3 Living-off-the-Land (LotL) Binaries

Vektor:

Attacker menggunakan signed Windows binaries untuk malicious actions:
  - certutil.exe: download & decode payload
  - mshta.exe: execute HTML/JS/VBScript
  - rundll32.exe: execute DLL, JavaScript
  - regsvr32.exe: execute COM scriptlet (SCT)
  - wmic.exe: process creation, XSL execution
  - powershell.exe: download cradle, Invoke-Expression
  - bitsadmin.exe: download file
  - certreq.exe: download file

Tidak ada file malware di disk — semua menggunakan Windows native tools.

Probabilitas deteksi:

P(detect | signature-based AV) ≈ 0.05 (signed binary)
P(detect | behavioral EDR) ≈ 0.65-0.85
P(detect | command-line logging + ML) ≈ 0.75-0.90

Defend:

- Application Control (AppLocker / WDAC)
- Attack Surface Reduction (ASR) rules
- Command-line logging (Process Creation Event ID 4688 with cmdline)
- Script block logging (PowerShell)
- Constrained Language Mode (PowerShell)
- Windows Defender Application Control (WDAC)

5.4 Browser Zero-Day Chains

Vektor:

Stage 1: Renderer exploit (V8 JavaScript engine, Type Confusion)
  → Escape Chrome sandbox

Stage 2: Sandbox escape (Windows/macOS kernel exploit)
  → Gain SYSTEM/root

Stage 3: Persistence (WMI event, scheduled task, registry run key)

Contoh aktif (2021-2024):

Chrome V8 Type Confusion (CVE-2021-21220): APT31
Chrome V8 CVE-2022-1096: Commercial exploit broker
WebKit CVE-2023-37450: Predator spyware (Cytrox)
Chrome V8 CVE-2024-0519: Out-of-bounds access

Probabilitas:

P(success | 0-day chain + no EDR) ≈ 0.90+
P(success | 0-day chain + EDR behavioral) ≈ 0.50-0.70
P(success | 0-day chain + browser isolation) ≈ 0.10-0.20

Harga 0-day browser chain di pasar gelap:
  Chrome full chain: $500K - $2.5M
  Safari full chain: $500K - $1.5M
  Firefox full chain: $100K - $400K

Defend:

- Browser isolation (Citrix, Menlo, Cloudflare RBI)
- Rapid patching (Chrome auto-update within 24-48h)
- Site Isolation (Chrome per-site process)
- Enhanced Safe Browsing (Google)
- EDR dengan browser exploit detection

5.5 Firmware & Hardware Rootkits

Vektor:

UEFI/BIOS rootkit:
  - Flash SPI chip directly
  - Persist sebelum OS boot
  - Bypass disk encryption (hook bootloader)
  - Tidak terdeteksi oleh OS-level AV/EDR

BMC (Baseboard Management Controller) rootkit:
  - IPMI/KVM access independen dari OS
  - Persist even if OS reinstalled
  - Network access via dedicated NIC

PCIe DMA attack:
  - Thunderbolt/FireWire/PCIe device with DMA access
  - Read/write physical memory directly
  - Bypass OS memory protection

Contoh:

LoJax (2018): UEFI rootkit by APT28 (Fancy Bear)
MosaicRegressor (2020): UEFI bootkit via compromised supply chain
iLOBleed (2021): HP iLO BMC firmware rootkit

Probabilitas deteksi:

P(detect | OS-level EDR) ≈ 0.01-0.05
P(detect | firmware integrity check) ≈ 0.60-0.80
P(detect | hardware TPM attestation) ≈ 0.85-0.95

Defend:

- Secure Boot + TPM 2.0
- Intel Boot Guard / AMD Hardware-Validated Boot
- SPI flash write protection (BLE/SMM_BWP)
- Firmware integrity monitoring (CHIPSEC, Eclypsium)
- BMC network isolation (dedicated management VLAN)
- Thunderbolt security level: User Authorization / Secure Connect

5.6 Cloud Metadata Service Abuse

Vektor:

AWS/Azure/GCP metadata endpoint: http://169.254.169.254/
  → Contains IAM credentials, user-data scripts, instance identity

SSRF (Server-Side Request Forgery) → request metadata endpoint
  → Steal temporary IAM credentials
  → Pivot ke cloud infrastructure

Contoh:

Capital One breach (2019): SSRF → metadata → S3 bucket access
Wiz SSRF research (2021): Multiple cloud metadata abuse patterns

Probabilitas:

P(success | SSRF vulnerability + cloud instance) ≈ 0.80-0.95
P(detect | cloud trail + anomaly detection) ≈ 0.60-0.75

Defend:

- IMDSv2 (AWS) — session-based, requires PUT request + token
- Metadata hop limit = 1 (prevent container escape)
- Least privilege IAM (no wildcard permissions)
- SSRF protection (input validation, URL whitelist)
- CloudTrail + GuardDuty (anomaly detection)

5.7 Kernel Driver / BYOVD (Bring Your Own Vulnerable Driver)

Vektor:

1. Attacker install signed but vulnerable driver
   Contoh: dbutil_2_3.sys (Dell), gdrv.sys (Gigabyte), RTCore64.sys

2. Exploit driver vulnerability untuk:
   - Read/write physical memory
   - Disable SMEP/SMAP
   - Execute arbitrary code in kernel mode

3. Use kernel access untuk:
   - Disable EDR (unhook callbacks)
   - Hide malware (DKOM — Direct Kernel Object Manipulation)
   - Persist (kernel driver rootkit)

Probabilitas:

P(success | BYOVD + Windows) ≈ 0.90+
P(detect | HVCI/Memory Integrity) ≈ 0.70-0.85
P(detect | driver blocklist) ≈ 0.40-0.60

Defend:

- HVCI (Hypervisor-Protected Code Integrity) / Memory Integrity
- Vulnerable Driver Blocklist (Microsoft)
- Driver signature enforcement (strict)
- Application Control (block unknown drivers)
- EDR kernel callbacks (tapi bisa di-unhook oleh attacker)

5.8 Zero-Click Exploits (Mobile)

Vektor:

iMessage zero-click (FORCEDENTRY / BLASTPASS):
  - Malformed image/GIF/PDF dikirim via iMessage
  - iOS process attachment tanpa user interaction
  - Exploit NSExpression / CoreGraphics / ImageIO
  → Gain code execution

WhatsApp zero-click (2019):
  - Malformed MP4 via call
  - Buffer overflow di RTP processing
  → Pegasus spyware install

Probabilitas:

P(success | 0-click + no patch) ≈ 0.95+
P(detect | Lockdown Mode iOS) ≈ 0.80-0.90
P(detect | network monitoring + C2 beacon) ≈ 0.30-0.50

Harga 0-click mobile:
  iMessage 0-click: $5M - $15M
  WhatsApp 0-click: $1M - $5M

Defend:

- Lockdown Mode (iOS) — disable iMessage attachment processing
- Rapid OS patching (auto-update)
- Network monitoring (C2 detection)
- Mobile threat defense (Lookout, Zimperium)
- Disable iMessage/FaceTime jika tidak diperlukan

5.9 Summary: Zero-Day Defense Matrix

VektorP(eksploitasi)MTTDPeak Defense
Supply Chain0.95200+ hariSBOM + code signing + behavioral
Watering Hole0.40-0.8030-90 hariBrowser isolation + URL filtering
LotL Binaries0.90+7-30 hariAppLocker + ASR + cmdline logging
Browser 0-day0.90+1-7 hariBrowser isolation + rapid patching
Firmware Rootkit0.90+365+ hariSecure Boot + TPM + Boot Guard
Cloud Metadata0.80-0.951-14 hariIMDSv2 + hop limit + least privilege
BYOVD0.90+7-60 hariHVCI + driver blocklist
Mobile 0-click0.95+1-30 hariLockdown Mode + rapid patching

6. PURPLE TEAM — When Red Meets Blue

Purple team adalah kolaborasi red + blue untuk validate defense.

ToolFungsiLevel Rating / KejaranganKenapa Peak
Atomic Red TeamTTP testing library500+ atomic tests mapped ke MITRE ATT&CK, portable, detectable. Peak untuk TTP validation.
CalderaAutomated adversary emulationMITRE’s framework, 100+ abilities, autonomous operation. Peak untuk automated purple team.
Prelude OperatorContinuous security testingSchedule TTPs, measure detection coverage, reporting.
Vectra AINetwork detection validationValidate NDR detection dengan red team activity.
MITRE ATT&CK NavigatorCoverage mappingVisualisasi detection coverage per TTP, identify gaps. Peak untuk coverage analysis.

Purple Team Metrics:

Detection Coverage = (Detected TTPs / Total Executed TTPs) × 100

Target: >80% for critical TTPs (Initial Access, Execution, Persistence)
Target: >60% for all TTPs

Mean Time to Detect (MTTD) = average time dari TTP execution → alert
Target: <15 minutes untuk critical

Mean Time to Respond (MTTR) = average time dari alert → containment
Target: <1 hour untuk critical

7. References

  1. MITRE Corporation. (2024). MITRE ATT&CK Framework. attack.mitre.org. — TTP taxonomy.

  2. Mandiant (Google Cloud). (2024). M-Trends 2024. — Incident response statistics & MTTD.

  3. CrowdStrike. (2024). Global Threat Report 2024. — APT activity & threat landscape.

  4. Volexity. (2024). Threat Research Blog. — 0-day analysis & APT campaigns.

  5. Google Threat Analysis Group (TAG). (2024). Year in Review. — 0-day exploitation trends.

  6. Microsoft Security Response Center. (2024). Security Update Guide. — Patch analysis.

  7. Zerodium. (2024). Exploit Acquisition Price List. — 0-day market pricing.

  8. SANS Institute. (2024). DFIR Posters & Cheat Sheets. — Forensics reference.

  9. Europol. (2024). Internet Organised Crime Threat Assessment (IOCTA). — Cybercrime trends.

  10. Chainalysis. (2024). Crypto Crime Report. — Financial crime on blockchain.

Koneksi ke Vault

CatatanKoneksi
osint-resource-indexOSINT tools overlap
threat-directoryThreat actor profiles & TTPs
advanced-anti-forensics-counter-surveillanceInversi dari forensics tools
underground-financial-crime-ecosystemFinancial crime tools & economics
crawl-ambil-data-publikOSINT data collection pipeline
endpoint-securityEDR/XDR defense stack
network-securityNDR & network forensics
incident-response-frameworkIR playbook & case management