Tempered Automation: Forging Tradecraft Through Bespoke Tooling

Explore the trade-offs of stealth, automation, and discrete tooling in intelligence collection.

Share
A dark smithy with a networking rack powering a data hearth in a blended physical/digital environment.
Forging Tradecraft. A Ravenwood composite; sources via Unsplash (J. Kettle-Williams, J. Murray, M. Spiske, Resource Database, Sufyan)

This is the final installment in our a five part tradecraft series on managed attribution strategies. Don't forget to check out parts onetwo, three, and four.

Our subscribers can download a zine at the bottom of this article for helpful reminders on the go. It's free to sign up!


The final use case we’ll cover in this series is by far the hardest to defend—and the one many jump to first. When it becomes impractical to manually browse and collect information, or infeasible to use an existing service provider's API, organizations may turn to scanning and automation techniques to identify and collect potential intelligence information. Once again, know your legal limits before proceeding. For this article, we’ll assume the collection environment is both hostile and legally unobjectionable for these purposes.

Scanning and Automation

This type of activity requires significantly greater technical understanding, as well as additional tooling, before proceeding. Anyone can fire up Kali Linux and turn on one of dozens of tools designed to bang away at the internet. However, these tools are not designed (or at least not configured by default) with stealth in mind. Attempting to scan, crawl, and index a hostile adversary’s digital infrastructure is sure to set off more than a few alerts and may result in blocked access or manipulated results. In a worst case scenario, an organization could be de-platformed by their ISP.

There are two general approaches to consider. If stealth is deemed unnecessary, you may opt for a distributed approach. There are several existing tools that provide distributed forward proxy capabilities, allowing you to leverage hundreds of cloud microservices simultaneously instead of a single VPN provider. These tools are relatively cheap to deploy and may provide some level of deniability, but they will not mask the fact that an activity occurred. In fact, an attentive defender should quickly and easily identify a high volume of singleton requests from different cloud IPs. Throttling may help but will not hold up under scrutiny if the events don’t reflect normal browsing patterns.

Alternatively, stealth may be the preferable approach. Such a scenario is likely far outside the scope of small organizations simply seeking a secure research platform. Stealth requires intentionality, which commercially available tools rarely provide. Custom tooling takes time to build, talent to operate, and more time to maintain. It necessitates yet another layer of compartmentalized infrastructure. Moreover, if a custom tool is built, deployed, and compromised, it may ultimately lead to correlation and discovery of other efforts using the same methodology. For this reason, bespoke tools are closely guarded and often limited to a singular use case.

Thrifty organizations may choose a middle path that balances the risk of discovery with the approachability of lightly modified open-source software projects and a healthy understanding of their operational boundaries. In many cases, a semi-automated, human-driven approach may be more practical. In reality, the majority of organizations don’t require the stealth of compartmentalized intelligence operations, nor can they afford to approach automation with reckless abandon. These organizations will find the most cost-effective success where their collection needs are flexible and short-term in nature. Rapid prototyping can often provide a small number of operators with an 80% solution in a reasonable timeframe, allowing an organization to determine whether a sustained investment is warranted.

Conclusion: We've Only Just Begun

We've got more than white lace and promises. We've got over 30 years of combined field experience.

Over the course of this series, we've gone over a broad range of topics from establishing guardrails and policies to compartmentalizing workflows for operational security. If there's one overarching takeaway, it's that managed attribution isn't something you can buy: it's deliberate, holistic tradecraft. Whether your organization is looking for a low-key approach to threat research, or you're trying to scale up collection on dark web forums, your strategy must be tailored to your employees' needs and matched to your organizational security posture.