01Overview
text
Friendly Larry’s Operational Security Manual :*Hat APT-Adversary edition--- Bhavesh M. Dhake======================================================Index :-Category 1 : Physical layerCategory 2 : Hardware layerCategory 3 : Operating System LayerCategory 4 : Network layerCategory 5 : Browser layerCategory 6 : Identity layerCategory 7 : Infrastructure layerCategory 8 : Side Channel layerCategory 9 : Radio Frequency layer======================================================Category 1 : Physical______________________________________________________________1. Residential physical opsec :• Keep ur devices such that they are out of direct visibility from window etc.• Lock doors, windows and any other entry points regularly• Verify unexpected visitors before even letting them have a glance inside• Do not allow unscheduled deliveries or handy man• Seperate work area from guest view• Use curtains at night• stay aware of repeated people from sign of residence2. Movement and Daily routine opsec :• Slightly vary departure timings• Avoid using same seating places in public spaces• Keep awareness of surroundings with paranoia• Do not leave ur devices unattended anywhere else3. Device custody discipline :• Shutdown devices when travelling or leaving them• Use full disk encryption• Lock screens immediately when stepping away• Avoid public space screen exposure4. Peripheral and accessory safety :• use ur own chargers and cables• Avoid unknown usb drivers• Avoid borrowed docks and adapters• Prefer wall power over public charging ports5. Supply chain :• Avoid unknown refurbished hardware• Modified OS images from certs6. Wireless and signal awareness• Turn off bluetooth when not in use• Disable auto join wifi networks• Limit unneccessary Iot devices• Power off devices when extreme privacy is needed7. Sensory and environment awareness• Use shutter webcam or cover• Restrict microphone permissions• Disable always listening assistants• Avoid discussing sensitive info near devices8. Vechile and travel opsec• Dont leave electronics in vechiles• Avoid pradictable parking habits• Occassionaly check belongings for unknown trackers• Seperate sensitive work from travel environments9. Social and behavioural opsec• Oversharing technical capability• Public boasting about offensive skills• Unncessary online attention• Revealing routines or infrastructure======================================================Category 2 : Hardware layer______________________________________________________________1. Trusted hardware procuremt :• Buy directly from manufacturer or authorized retailer• Avoid unknown refurbished devices for sensitive works• Prefer sealed hardware2. Clean re installation of OS• Download OS only from official sources• Do not use modified os even from institutions• Verify cryptographic signatures3. FIrmware security :• Update BIOS/UEFI regularly• Set BIOS administrator password• Disable external boot devices• Disable unused hardware interfaces4. Maintain full disk encryption5. Physical device control• never leave laptop unattended or atleast shutdown or locked• Shut down during travel• Carry devices urself6. DMA attack protection :• Enable kernel DMA protection• Enable IOMMU7. Wireless hardware opsec :• Disable bluetooth• Disable auto connect• Turn off unused radios• Limit iot devices8. Sensor protection• Webcam cover• Microphone permissions• Disable voice assistants9. Storage hardware protection• cryptographic erase• secure erase tools10. Tamper awareness• Loose screws• Casing gaps• Unexpected adapters• New devices appearing in OS====================================================Category 3 : Operating System layer____________________________________________________________1. Secure OS chain and trust chain• Verify checksum of iso files• Verify developer signatures• Fingerprint independently• Use official resources only not even institure altered mods2. Secure boot and boot chain protection• In BIOS enable secure boot• In BIOS enable TPM• In BIOS enable measured boot• Verify boot integrity3. Use full device encryption4. Minimal os installation• Remove unused services• Remove unneccessary packages• Remove unused default apps5. User privilege seperation• Create standard user account• Seperate admin account• Use privilege escalation only when required6. Application isolation / sandboxing7. Software source integrity• Install software from official repositories• Use only signed packages• Get from trusted vendors8. Update discipline• Enable auto update• Stay aware of latest cve patches9. Process and persistence monitoring• Use tools to monitor of active and persistent instances• Process privileges• Check regularly for all startup apps• Check for privileges for apps• Use native AV and EDR’s====================================================Category 4 : Network layer___________________________________________________________1. Router / home network hardening• Change default admin password• Update router firmware• Disable remote administration• Disable WPS• Usa WPA3 or WPA2-AES• Segmentation in network for main , lab , iot , guest2. Firewall control :• Modify iptables / nftables• Monitor and restrict open ports• Use encrypted DNS over HTTPS• Use encrypted DNS over TLS• Enable secure DNS3. Traffic encryption discipline• Use https , ssh , tls , encrypted messaging• Avoid ftp , telnet etc. Insecure protocols4. Public wifi opsec• Use VPN on trusted networks• Disable file sharing• Disable auto connect• Firewall enabled before connecting• Disable discovery5. VPN• Use zero knowledge vpn’s• Trusted brands and non controversial• Using anonymous accounts and payement methods6. Network segmentation• Separate networks for guest , Iot , family and work7. Outbound traffic awareness• Disable unnecessary services• Close unused ports• Check listening services• Restrict and monitor outbound traffic flow8. Enable MAC randomization and private address feature9. Remote access hardening• Key authentication only• Disable only password login• Restrict ip address10. Recon monitoring ur own network11. Keep logs when possible12. Use TOR and DNS proxy such as cloudflare 1.1.1.1======================================================Category 5 : Browser layer______________________________________________________________1. Right choice :• Firefox browser• Brave browser• Mullvad browser• Tor browser2. Seperate browsing identities• Use different account on different browsers• Based on intensity of privacy required• Adjusted browser configurations3. Harden browser• Disable telemetry• Disable third party cookies• Partition storage• Restrict tracking• Bridges for tor• And all other configurable features available for the browser4. Essential security extensions• Block trackers• Block ads• Block cookies• Block malicious domain redirections5. Javascript risk• Disble javascript wherever possible• Use hardened browser modes• Restrict weird sites• Open suspicious links in isolated or defense testing env such asvirustotal/anyrun6. Browser isolation• Use browser via os in virtual machine• Use browser via os in live usb boot• Sandbox execution7. Prevent browser fingerprinting• Prevent fingerprinting signals leak such as screensize ,font , GPU , timezon , extesions , canvas rendering• Keep browser default appearance• Dont use too many fancy extensions• Avoid manual tweaking presenting as unique identity• Browser fingerprinting websites testing and refinement8. Cookie and session hygine• Auto delete cookies on close• Isolate login• Logout unused accounts9. Download safety• download from official sources only• Verify signatures when possible• Scan for suspicious files before interacting and execution10. Phishing safety• Check domains and urls carefully before interacting• Avoid login link and content links from emails etc.• Allow https only mode11. Disable dangerous features• Disable Webrtc ip leakage• Disable automatic download• Set always ask location before downloading• Disable notification permissions• Disable background synchronization• Avoid copying sensitive data to clipboard• Restrict camera and microphone access=====================================================Category 6 : Idenity Layer_____________________________________________________________1. Identity Compartmentalization• Real identity• Professional identity• Research identity• Public identity• Disposable idenity2. Implementation• Email accounts• Browser profiles• Devices• VMs• Phone numbers• Username etc.3. Email opsec• Seperate email per identity• Never use recovery email from another identity• Disable unnecessary recovery options4. Username opsec• Avoid reusing usrnames• Avoid similar naming patterns• Avoid using similar avatars5. Phone number opsec• Avoid linking phone number wherever possible• Use seperate phone numbers for different identities• Have disposable bought numbers based on pseudo identity• Use app based auth instead of sms6. Authentication hygine• Use privacy focused and reputed password managers• Use unique and strong password• Enable multi factor authentication• Use USB stick auth wherever possible7. Social media opsec• Restrict personal details• Avoid posting routine locations or any• Remove unnecessart biography data• Limit friends and visibility8. OSINT self audit9. HUMINT self audit10. Data broker exposure reduction• Avoid unnecessary registrations• Avoid oversharing on forums• Opt out of requests wherever possible• Restrict data access by third party apps11. Document and files matadata hygine• Strip metadata or alter with false metadata• Avoid platforms which use original metadata12. Reputation and visibility control===================================================Category 7 : Infrastructure layer___________________________________________________________1. Separate Infrastructure• Different administrative accounts• Dedicated management environments• Role seperation between personal accout and infrastructure usage2. Secure account access to infrastructure• Strong unique passwords• MFA everywhere• Hardware security keys wherever possible3. Harden cloud and server access• Restrict administrative access• Disable unused services• Minimize exosed ports• Firewall rules• Ip allow lists• Vpn base admin acess4. Network segmentation• Production• Testing• Research• Management• VLAN segmentation5. Domain and DNS opsec• Eliminate risk for Ownership and lookup exposure,• Infrastrucure mapping ,• Targetting through DNS records• Enable resgister account protection• Use registry lock when possible• Protect dns management account with mfa6. Logging and monitoring• Monitor authentication attempts• Log configuration changes• Check for unusual traffic7. Patch and update infrastructure maintenance for• OS updates• Container update• Dependency updates• Service patches8. Backup infra• Encrypted backups• Offline and cloud backup copies and mirrors• Recovery testing9. Infra metadata awareness• Restrict instance permissions• Apply least privilege access roles10. Secure remote administration• Vpn based management access• Key based authentication• Restrict admin end points11. Supply chain protection• Compromised libraries• Malicious updates• Verify packages• Monitor dependancies• Restrict trust of external code12. Provider trust awareness• Provider can see metadata• Infra actions are recorder======================================================Category 8 : Side channel layer_______________________________________________________________1. Physical proximity control :• Control who can physically approach ur device• Avoid sensitive work in public environment• Keep unknown electronics away• Avoid shared desks for sensitive tasks2. Electromagnetic emission reduction• Keep systems away from windows facing public areas• Avoid placing laptops near external walls• Reduce using unnecessary cables as antennas• Use shielded rooms• Use grounded equipments• Use filtered power lines3. Power analysis risk reduction• Use quality power supplies• Avoid shared unknown power sources• Prefer battery operation for sensitive tasks• Use surge-protected grounded outlets.4. Acoustic leakage reduction• Avoid sensitive work near recording devices.• Disable always-listening smart assistants.• Reduce nearby microphones or IoT speakers.• Maintain moderate ambient noise.5. Wireless emission discipline• disable Bluetooth• disable Wi-Fi if unnecessary• disconnect unused radios.======================================================Category 9 : Radio Frequency layer_______________________________________________________________1. Common RF sources:• Wi-Fi• Bluetooth• Cellular• NFC• GPS receivers• IoT radios (Zigbee / Thread / proprietary)• Wireless peripherals2. Control radio emissions• Turn off Bluetooth, wifi , nfc, hotspot sharing , unused wireless adapters3. Prevent device tracking via identifiers• Enable MAC address randomization• Disable auto connect networks• Forget networks not in use4. Secure wifi usage• Avoid connecting automatically.• Prefer trusted networks.• Disable probe broadcasting where possible.• Remove saved networks periodically.5. Bluetooth opsec• Keep Bluetooth off by default• Disable device discoverability• Remove old paired devices• Avoid persistent wearable pairing when unnecessary.6. Cellular radio discipline• Disable unused SIM/eSIM profiles.• Disable location sharing apps.• Power off device when true radio silence is required.7. Reduce RF leakage from workspace• Workstation away from windows• Router centrally placed• No unnecessary transmitters nearby8. Control iot radio surface• Reduce or isolate smart speakers , cameras , wireless sensors etc. Smart IoTs9. Rogue access point awareness• manually select networks• verify network names• disable automatic joining.10. Wireless peripheral safety• prefer encrypted wireless peripherals• avoid unknown dongles• remove unused receivers.11. RF environment awareness• SDR receivers (for learning RF environment)• spectrum visualization software• Wi-Fi scanning tools.12. GPS and location signal opsec• disable unnecessary location permissions• restrict background location access• remove geotags from photos.13. Reduce continuous beacon devices• smartwatches• earbuds• trackers• fitness devices.======================================================