Pretnje
68 direktnih pogodaka-
№ 028
Business Email Compromise Business email compromise is not an ordinary fake email. The attacker breaks into business correspondence, or imitates it well enough that somebody in the compa …pretnja · social eng.
-
№ 037
Crypto-wallet drainer … y signing transactions that move crypto assets. Draining a wallet is the process in which the user, believing they are doing something legitimate, signs a trans …pretnja · social eng.
-
№ 060
Supply Chain Attack A supply chain attack does not always aim at the final victim directly. The attacker compromises software, hardware, a supplier, a build process or an update me …pretnja · trust
-
№ 053
Botnet Attacks … tnet is used for DDoS, sending spam, phishing campaigns, password spraying, cryptocurrency mining, malware distribution and other work that needs quantity. The …pretnja · availability
-
№ 051
DNS Amplification … r uses open DNS resolvers to multiply the traffic aimed at a victim. The attacker sends relatively small DNS queries but forges the victim's address as the sour …pretnja · availability
-
№ 035
Deepfake Attack A deepfake attack uses an artificially generated voice, image or video so that somebody can pose as a real person. In cyber attacks this usually means the director's voice on a call, a colleague's face in a video meeting, or a recording that feels real enough for the victim to accept the request.pretnja · social eng.
-
№ 050
Denial of Service / DoS DoS is a denial-of-service attack that tries to bring a service down or slow it so far that legitimate users can no longer use it. Unlike DDoS it need not come from a large network of compromised devices. Sometimes one source and a well-chosen vulnerability are enough.pretnja · availability
-
№ 048
Dependency Confusion … y. It is enough to slip into an unchecked build chain.pretnja · applications
-
№ 049
Distributed Denial of Service / DDoS … in web requests until the server is blocked. The aim is not data theft but choking the service into unavailability.pretnja · availability
-
№ 073
Model theft / extraction Model theft and extraction means an attacker obtains a model an organization trained, bought or adapted to its own needs. That can be direct theft of the files, …pretnja · AI / ML
-
№ 071
Physical Access Attack … nters the premises without a card of their own — tailgating.pretnja · physical / IoT
-
№ 072
Prompt injection … tent they are processing. When a model reads an email, a document, a page, a ticket or a message, the attacker can put text into that content which reads like a …pretnja · AI / ML
-
№ 055
Ransom DDoS Ransom DDoS joins an attack on availability to extortion. The attackers threaten to bring the service down, or first run a short demonstration attack, and then …pretnja · availability
-
№ 052
Resource Exhaustion … , threads, the database or processing queues. The aim is not necessarily to send enormous traffic but to make the system spend what it has.pretnja · availability
-
№ 054
Service Abuse … unction can be automated, overloaded, or turned against the service and its users.pretnja · availability
-
№ 066
Typosquatting … r recognizing a name. The attacker registers a domain, an account or a software package that resembles a legitimate name, counting on a user, a developer or a s …pretnja · trust
-
№ 042
API Abuse … nical add-on to the application. It is often the main entrance to the data, the users, the orders, the payments and the administration.pretnja · applications
-
№ 065
Accidental Data Leak … he consequences can look the same. Data becomes available to the wrong people through human error, bad configuration, wrong sharing, a public repository, open c …pretnja · trust
-
№ 021
Account Takeover Account takeover is the moment the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail addres …pretnja · identity
-
№ 056
BGP Hijacking The consequence can be loss of availability, interception of traffic, or its diversion through a network that should never have been on that path. Sometimes it …pretnja · availability
-
№ 006
Backdoor … rst break-in, to secure a way back even when the main entrance is closed. Sometimes it is left behind by employees or service providers, deliberately or by acci …pretnja · malware
-
№ 015
Brute-force attack … ord after password until one takes. It succeeds against short, weak and common passwords, and against systems that put no limit on failed attempts. It is not cl …pretnja · identity
-
№ 074
Cloud storage exposure … rol is not protection but a copy of the incident waiting to be found.pretnja · cloud
-
№ 063
Contractor Abuse … oyees they are often outside the same regime of training, oversight, HR process and discipline. When the contract ends, the account sometimes stays open.pretnja · trust
-
№ 017
Credential stuffing … it tries known ones. With username and password pairs from databases leaked across the internet, the attacker tries the most-used services such as Facebook and …pretnja · identity
-
№ 041
Cross-Site Request Forgery … t an action the user never intended. A change of mail address, password, account settings, an order or a transfer of funds can be set off from another page, thr …pretnja · applications
-
№ 013
Cryptominer … nes are higher than expected. The vendor did not raise prices and you changed nothing.pretnja · malware
-
№ 057
DNS Poisoning … er or a resolver is given a false answer for a domain. The result is that the user types a familiar address into the browser and DNS takes them to the wrong web …pretnja · availability
-
№ 068
Evil Twin … use people expect open networks in hotels, cafés, airports and conference halls.pretnja · physical / IoT
-
№ 011
Fileless malware … n on scheduled tasks and the Windows registry — again with no conspicuous file. A restart clears it from memory, but persistence techniques bring it back.pretnja · malware
-
№ 012
Infostealer … or malicious advertising. It does not linger; the aim is not to settle in but to grab and vanish, often within seconds. Stolen session tokens are the real prize …pretnja · malware
-
№ 046
Insecure Deserialization … e libraries. Once the attacker finds a suitable chain of objects, the application itself does the work it should never have done.pretnja · applications
-
№ 058
Insider Threat … ust towards people but protection of the system against a situation going badly.pretnja · trust
-
№ 022
Kerberoasting Kerberoasting is an attack specific to Windows domain networks and Active Directory (AD). User logins are handled by the Kerberos protocol, which issues tickets …pretnja · identity
-
№ 004
Keylogger Software keylogger installed via an infected email attachmentpretnja · malware
-
№ 005
Loader / Dropper … suspicious invoice does not install ransomware straight away; it starts a small loader that pulls down the tools needed for the next stages of the attack.pretnja · malware
-
№ 032
Malvertising A paid search advert leads to a fake site for popular software, where a Trojan is downloaded instead of the legitimate installer.pretnja · social eng.
-
№ 023
Pass-the-Hash … -the-hash abuses exactly that: if the attacker obtains a user's hash, they can log in with it without ever learning the real password.pretnja · identity
-
№ 016
Password spraying … sight, it never trips the thresholds that watch failed attempts. The attack shows up only in the wider picture — login attempts with the same password across m …pretnja · identity
-
№ 026
Phishing The defense works on two levels. Technical: mail filtering, link checking, two-factor authentication that makes a stolen password unusable. Human: through train …pretnja · social eng.
-
№ 031
Pretexting … ry. The attacker does not simply send a link and wait for a click; they build a scenario in which what they are doing looks normal. They present themselves as a …pretnja · social eng.
-
№ 020
Privilege Escalation … vertical escalation, from an ordinary user to domain administrator, and horizontal, moving from one account to another user's resources at the same level of ri …pretnja · identity
-
№ 061
Privilege Misuse … own favor, and technical staff can reach private mail, records or systems outside the scope of their work. The system often sees a valid account and a permitted …pretnja · trust
-
№ 034
QR phishing - Quishing … rd because it hides the destination well. In an email or a document there is no ordinary link for a filter to read, and the user often carries on working on the …pretnja · social eng.
-
№ 001
Ransomware … data and threatens to publish them if nothing is paid — double extortion. Some ransomware groups sell their whole operation to affiliates as a package (ransomwa …pretnja · malware
-
№ 038
Remote Code Execution … is no longer merely a user on the outside; they gain a way to influence what the server executes.pretnja · applications
-
№ 014
Remote access trojan - RAT … it the attacker can take your data, but can also wait for the right moment to move deeper into the network. Because it works interactively, it is more dangerous …pretnja · malware
-
№ 010
Rootkit … moval is much harder. It is found by comparison against a trusted reference, by checking the integrity of the boot process, and by system behavior that does not …pretnja · malware
-
№ 070
SCADA/OT Attack In attacks like these the aim is not always theft. It can be a halt in production, a change of parameters, damage to equipment, pressure on the operators, or sa …pretnja · physical / IoT
-
№ 025
SIM Swapping … ed card. They usually come armed with personal details from leaked databases and phishing. The moment the number moves to their card, the real phone loses signa …pretnja · identity
-
№ 030
SMS phishing - Smishing … ed, a transaction looks suspicious, a package is waiting on a small charge. Everything is reduced to a few words and one link.pretnja · social eng.
-
№ 039
SQL Injection … something the designer never had in mind, and certainly never intended.pretnja · applications
-
№ 045
SSRF … ernal services which from the outside ought to remain invisible.pretnja · applications
-
№ 019
Session Hijacking … h it, such as your preferences and settings. The main benefit is that you do not have to type a password every few minutes as you move through the features. Tha …pretnja · identity
-
№ 062
Shared Account Abuse … access. The problem is attribution. It cannot be said with any confidence who logged in, who changed the setting, who exported the data, or who passed the passw …pretnja · trust
-
№ 027
Spear Phishing An email that refers to a real, recent internal meeting, with the minutes attached — and the attachment carrying malware.pretnja · social eng.
-
№ 003
Spyware … a trace. That is why they are a favored weapon against journalists, activists and political opponents, but the same mechanism shows up in corporate espionage a …pretnja · malware
-
№ 059
Third-Party Compromise … rations, API keys, access to data, or the job of maintaining systems. If they are less well protected than the organization they reach into, they become the eas …pretnja · trust
-
№ 018
Token Theft … equest, so you do not have to type the password again. Token theft is the taking of that proof. With it in hand, the attacker presents themselves as you — witho …pretnja · identity
-
№ 002
Trojan The surest defense against Trojans is a boring one: software comes only from the official source, and mail attachments are not opened without thinking. A crack …pretnja · malware
-
№ 069
USB Drop Attack … f the network protection. The attacker sends no email and jumps no company firewall; they rely on the victim carrying it in themselves, behind every technical b …pretnja · physical / IoT
-
№ 009
Virus It travels on USB sticks, mail attachments, shared folders and pirated software. Through the nineties and the early two-thousands it was the dominant form of ma …pretnja · malware
-
№ 036
Watering Hole Attack … ndustrial teams, lawyers, journalists or supply chains. The user is not clicking a suspicious email; they are visiting a familiar site. That is exactly why the …pretnja · social eng.
-
№ 033
Whaling Whaling is targeted phishing aimed at senior management, owners, directors and people who can approve large decisions. The target is not chosen by chance. The a …pretnja · social eng.
-
№ 007
Wiper … recovery was never part of the plan, because the aim is damage, not money.pretnja · malware
-
№ 008
Worm … work is enough to bring the whole network down. Against a worm, segmentation is the best defense.pretnja · malware
-
№ 044
Zero-Day Exploitation … overnment institutions, large companies, supply chains, journalists, activists, financial systems or infrastructure. When they do appear in mass use, the window …pretnja · applications
-
№ 029
voice phishing - Vishing … g is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present themsel …pretnja · social eng.
Tehnike
32 direktna pogotka-
№ 023
Container Escape Containers are meant to isolate an application from the host and from other containers. Container escape is when an attacker controlling a process inside a cont …tehnika · privileges
-
№ 025
Reconnaissance Reconnaissance involves the systematic gathering of information about the target environment, both externally before the attack and internally after compromise. …tehnika · discovery
-
№ 006
Supply Chain Compromise … jecting malicious code into the software supply chain.tehnika · initial access
-
№ 009
AiTM AiTM sits between the user and the real service. Classic phishing steals a password; AiTM steals the live session. The victim gets a link, lands on a proxy that …tehnika · initial access
-
№ 029
Domain Account Discovery Does not require privileged access — any domain user can enumerate AD.tehnika · discovery
-
№ 040
Domain Fronting … que of hiding C2 traffic behind legitimate CDN domains.tehnika · C2
-
№ 012
Impair Defenses … nd automated detection systems. The goal is to remain undetected for as long as possible in the compromised environment.tehnika · execution
-
№ 030
OSINT … thering information about targets from publicly available sources before an attack.tehnika · discovery
-
№ 027
Automation & Scripting … that automatically harvests passwords from all domain workstationstehnika · discovery
-
№ 004
Brute Force … of a large number of credential combinations to gain unauthorized access. It includes classic exhaustive testing, dictionary attacks with common passwords, and …tehnika · initial access
-
№ 024
Cloud lateral movement … movement when an attacker who got one identity chains the steps: identity A can become B, B can become C with more rights, C reaches another account. No new pa …tehnika · privileges
-
№ 003
Credential Abuse … se involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate u …tehnika · initial access
-
№ 036
DNS Tunneling Data is encoded in DNS requests (subdomains) and responses (TXT, CNAME).tehnika · exfiltration / impact
-
№ 031
Data Exfiltration … encrypted channels, legitimate cloud services, email, or even physical media.tehnika · exfiltration / impact
-
№ 007
Drive-by Download … mmon vector in malvertising and watering hole campaigns.tehnika · initial access
-
№ 010
Exploitation … ates known vulnerabilities but does not protect against zero-day exploits.tehnika · execution
-
№ 041
Fast-Flux DNS … rotation of IP addresses associated with a C2 domain.tehnika · C2
-
№ 022
Forge Kerberos Tickets All require access to an AD environment as a domain user or administrator.tehnika · privileges
-
№ 019
Lateral Movement … work. The goal is to expand access to systems containing more valuable data or enabling further escalation.tehnika · privileges
-
№ 038
Malware Delivery Infected email attachment disguised as an invoicetehnika · C2
-
№ 028
Network Sniffing Can capture credentials, session tokens, email content, and API keys.tehnika · discovery
-
№ 021
Pass-the-Hash Using NTLM hashes instead of plaintext passwords for authentication.tehnika · privileges
-
№ 013
Payload Obfuscation … ss all attack phases, from malware delivery via email to communication with command servers.tehnika · execution
-
№ 011
Persistence … changes, or other interruptions. The goal is to maintain a foothold in the environment over an extended period.tehnika · execution
-
№ 001
Phishing … hing as a technique involves sending fraudulent emails, SMS messages, or chat messages to trick the victim into clicking a malicious link, opening an infected a …tehnika · initial access
-
№ 008
Physical Access … ffective in combination with social engineering (tailgating).tehnika · initial access
-
№ 018
Privilege Escalation … chnique by which an attacker with limited access gains a higher level of authorization. Vertical escalation means reaching administrator or root level, while ho …tehnika · privileges
-
№ 032
Resource Exhaustion … ately overloading target systems to make them unavailable to legitimate users. The attacker targets CPU, memory, network bandwidth, disk, or connection limits.tehnika · exfiltration / impact
-
№ 017
Rootkit Installation Requires previously obtained administrative or kernel privileges.tehnika · execution
-
№ 033
Service Abuse … ctionalities in unintended ways to cause damage, gain unauthorized access, or achieve financial gain.tehnika · exfiltration / impact
-
№ 002
Social Engineering … hnique involves manipulating human behavior to obtain information, access, or the execution of actions that benefit the attacker. It relies on trust, authority, …tehnika · initial access
-
№ 005
Watering Hole Effective against groups with strict email security but free web access.tehnika · initial access
Odbrane
37 direktnih pogodaka-
№ 002
Email Security Email security encompasses technologies that filter inbound and outbound messages to prevent phishing, malware delivery, and business email compromise. It opera …odbrana · endpoints
-
№ 028
DDoS Protection DDoS protection encompasses technologies and services that detect and mitigate distributed denial-of-service attacks before malicious traffic reaches or overwhelms the target infrastructure.odbrana · resilience
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is to limit an attacker's ability to move through the network after compromising a single system.odbrana · resilience
-
№ 023
Patch Management … disciplined process because unpatched systems remain vulnerable to known exploits.odbrana · resilience
-
№ 038
Phishing Simulations Results are used for targeted additional training.odbrana · people
-
№ 007
SPF/DKIM/DMARC By default, anyone can put your domain in the sender field — that's how spoofed mail 'from the director' works. SPF, DKIM, and DMARC are three records you publi …odbrana · endpoints
-
№ 024
Backup & Recovery … ated from the production network. This protects against ransomware that attempts to encrypt backup copies as well.odbrana · resilience
-
№ 006
Browser Isolation Executing web content in an isolated environment separate from the local system.odbrana · endpoints
-
№ 033
CSPM … checks how the cloud environment is configured against good-practice and compliance rules: which buckets are public, which identities hold too many rights, whe …odbrana · resilience
-
№ 034
DLP … n employee attaching a client list to a private email, copying a file with personal data to a USB, or pasting a database into a chat. It works by recognizing pa …odbrana · resilience
-
№ 029
DNS Security … control point for blocking access to malicious domains and detecting suspicious communications.odbrana · resilience
-
№ 030
Data Encryption In transit: TLS 1.3 for web, email, and API communication.odbrana · resilience
-
№ 040
DevSecOps … anning (SAST), dependency analysis (SCA), and container scanning in CI/CD.odbrana · people
-
№ 021
Digital Forensics Evidence must satisfy chain of custody for legal proceedings.odbrana · monitoring / response
-
№ 003
EDR … visibility and response capability. It records detailed telemetry about processes, network connections, file changes, and registry activity.odbrana · endpoints
-
№ 001
Endpoint Protection Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 035
Firewall A firewall is a control placed at the boundary between networks that permits or blocks traffic according to predefined rules — deciding who may talk to whom, on which ports and protocols.odbrana · resilience
-
№ 022
IDS/IPS … DS/IPS is worth exactly as much as the attention paid to what it reports. A system generating alerts no one reads is noise, not defense; signatures must be main …odbrana · monitoring / response
-
№ 009
Identity & Access Management … d access, privilege accumulation, and accounts remaining active after they are no longer needed.odbrana · identity / access
-
№ 020
Incident Response A planned process of identifying, containing, eradicating, and recovering from cyber incidents.odbrana · monitoring / response
-
№ 016
Logging & Monitoring … ires defining what is recorded, how long it is retained, where it is stored, and who has access to the records. Logs must be protected from unauthorized modific …odbrana · monitoring / response
-
№ 017
MDR MDR (Managed Detection and Response) is a service where an external security team provides continuous monitoring, threat detection, and incident response on behalf of an organization. It combines technology with human expertise.odbrana · monitoring / response
-
№ 005
Mobile Device Security Detects jailbreak/root and unauthorized applications.odbrana · endpoints
-
№ 012
Password Manager Available as application, browser extension, or enterprise solution.odbrana · identity / access
-
№ 045
Penetration Testing Simulation of real attacks to identify vulnerabilities that automated tools miss.odbrana · governance
-
№ 010
Privileged Access Management Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.odbrana · identity / access
-
№ 041
Risk Assessment Methodologies include NIST RMF, ISO 27005, FAIR, and OCTAVE.odbrana · governance
-
№ 015
SIEM … sed on defined rules, and compliance monitoring against regulatory requirements. It serves as the central visibility point for security operations.odbrana · monitoring / response
-
№ 014
Secrets Management … n it needs it, instead of carrying it around in plaintext.odbrana · identity / access
-
№ 026
Secure Configuration … sible attack vectors, but it requires continuous maintenance as new vulnerabilities and recommendations necessitate updating the standards.odbrana · resilience
-
№ 037
Security Awareness Delivered through training, posters, internal campaigns, and quizzes.odbrana · people
-
№ 039
Security Champions … hampions are employees with additional security training who mentor colleagues.odbrana · people
-
№ 019
Threat Intelligence Collecting, analyzing, and applying data about current cyber threats.odbrana · monitoring / response
-
№ 036
Virtual Private Network … laptop carries the problem through the tunnel straight into the corporate network.odbrana · resilience
-
№ 027
WAF … sers and the web server, analyzing each request against defined rules.odbrana · resilience
-
№ 004
XDR … Response) unifies data from endpoints, network, email, and cloud.odbrana · endpoints
-
№ 011
Zero Trust Zero Trust is a security concept that assumes no user, device, or network segment should be automatically trusted, regardless of whether it is inside or outside the corporate network. Every access request is verified before approval.odbrana · identity / access