166 terms ·
75/46/45
64 rezultata za „backup" ·
8 direktnih ·
56 povezanih
Pretnje
5 direktnih pogodaka-
№ 074
Cloud storage exposure … ud service. That can be S3 buckets, blob storage, backups, logs, documents, images, database exports or configuration files.pretnja · cloud
-
№ 065
Accidental Data Leak Cloud storage holding a database backup is left publicly reachable through a wrong setting.pretnja · trust
-
№ 075
Cloud IAM misconfiguration … sources, change networks, assume roles and delete backups.pretnja · cloud
-
№ 001
Ransomware A backup sitting on the same server or in the same cloud is not protection. Ransomware locks that too. Restores are tested before the incident, not after.pretnja · malware
-
№ 007
Wiper Without a sound backup in a separate location, a wiper ends the business. The 3-2-1 backup rule is the difference here between recovery and total loss. With a w …pretnja · malware
Tehnike
1 direktan pogodakOdbrane
2 direktna pogotka-
№ 024
Backup & Recovery Backup and recovery encompasses the processes and technologies for regularly creating copies of data and systems, storing them securely, and enabling reliable r …odbrana · resilience
-
№ 030
Data Encryption At rest: AES-256 for disks, databases, and backups.odbrana · resilience
↳ Povezano
56 stavki koje koriste „backup"-
№ 009
AiTM AiTM sits between the user and the real service. Classic phishing steals a password; AiTM steals the live session. The victim gets a link, lands on a proxy that looks exactly like the real login (because it forwards everything to the real site), enters credentials and even the MFA code — the proxy passes them through, the real service issues a session token, and the attacker captures that token.tehnika · initial access
-
№ 027
Automation & Scripting Automation and scripting involves using scripts, tools, and automated procedures to accelerate and scale activities within a compromised environment. Attackers leverage system scripting interpreters, configuration management tools, and custom scripts.tehnika · discovery
-
№ 033
CSPM CSPM continuously checks how the cloud environment is configured against good-practice and compliance rules: which buckets are public, which identities hold too many rights, where encryption is off, where logging is off. Instead of someone clicking manually through the console, the tool watches the whole account or subscription and flags when a setting drifts into danger.odbrana · resilience
-
№ 024
Cloud lateral movement In the cloud, identities can assume roles — temporarily take on another identity's rights. It's built for legitimate delegation, but it becomes lateral movement when an attacker who got one identity chains the steps: identity A can become B, B can become C with more rights, C reaches another account. No new password at each step — just inherited delegation.tehnika · privileges
-
№ 039
Command & Control Command and control communication involves establishing a persistent channel between the attacker and the compromised system for sending commands and receiving results. The attacker uses this channel to manage malware, launch new attack phases, and retrieve data.tehnika · C2
-
№ 026
Configuration Abuse Configuration abuse involves exploiting misconfigured systems, services, or security controls. Attackers look for default passwords, overly broad permissions, open ports, and services without authentication.tehnika · discovery
-
№ 023
Container Escape Containers are meant to isolate an application from the host and from other containers. Container escape is when an attacker controlling a process inside a container breaks that isolation and reaches the host (or other containers). From an application-level foothold they get host-level reach.tehnika · privileges
-
№ 003
Credential Abuse Credential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate user.tehnika · initial access
-
№ 034
DLP DLP watches where sensitive data goes and stops it where it shouldn't: an employee attaching a client list to a private email, copying a file with personal data to a USB, or pasting a database into a chat. It works by recognizing patterns (national IDs, card numbers, marked documents) and applying rules per channel — mail, web, endpoint, cloud.odbrana · resilience
-
№ 034
Data Destruction Technique of permanently deleting or corrupting data on a compromised system.tehnika · exfiltration / impact
-
№ 031
Data Exfiltration Data exfiltration involves transferring stolen information from the compromised environment to an attacker-controlled location. Data can be sent through encrypted channels, legitimate cloud services, email, or even physical media.tehnika · exfiltration / impact
-
№ 031
Deception Technology Deploying decoy resources (honeypots, honeytokens) to detect attackers.odbrana · resilience
-
№ 021
Digital Forensics Collecting, preserving, and analyzing digital evidence after a cyber incident.odbrana · monitoring / response
-
№ 040
Domain Fronting Technique of hiding C2 traffic behind legitimate CDN domains.tehnika · C2
-
№ 003
EDR EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.odbrana · endpoints
-
№ 002
Email Security Email security encompasses technologies that filter inbound and outbound messages to prevent phishing, malware delivery, and business email compromise. It operates at the server or cloud level before the message reaches the user.odbrana · endpoints
-
№ 042
Encrypted C2 Channels Using HTTPS, DNS-over-HTTPS, or other encrypted protocols for C2.tehnika · C2
-
№ 001
Endpoint Protection Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 068
Evil Twin A fake Wi-Fi network, known as an evil twin, imitates a legitimate wireless network so that users connect to an access point the attacker controls. The network name looks familiar, the signal can be stronger, and the device often suggests or restores the connection by itself.pretnja · physical / IoT
-
№ 010
Exploitation Exploitation involves leveraging a flaw in software, hardware, or configuration to execute unauthorized code or bypass security controls. Vulnerabilities can exist in operating systems, applications, network services, or firmware.tehnika · execution
-
№ 041
Fast-Flux DNS Rapid rotation of IP addresses associated with a C2 domain.tehnika · C2
-
№ 022
IDS/IPS IDS/IPS are systems that monitor network traffic (or host activity) for patterns indicating an attack. An IDS (Intrusion Detection System) only reports suspicious activity; an IPS (Intrusion Prevention System) sits inline and can block it immediately.odbrana · monitoring / response
-
№ 009
Identity & Access Management Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.odbrana · identity / access
-
№ 012
Impair Defenses Defense evasion encompasses techniques by which an attacker conceals their activity from security tools, analysts, and automated detection systems. The goal is to remain undetected for as long as possible in the compromised environment.tehnika · execution
-
№ 014
In-Memory Execution Executing malicious code in memory without writing files to disk.tehnika · execution
-
№ 020
Incident Response A planned process of identifying, containing, eradicating, and recovering from cyber incidents.odbrana · monitoring / response
-
№ 046
Indicator Removal A set of techniques for hindering or preventing digital forensics.tehnika · evasion
-
№ 012
Infostealer An infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.pretnja · malware
-
№ 058
Insider Threat An insider threat comes from a person who has, or once had, legitimate access to an organization's systems, data or premises. That can be an employee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized to begin with.pretnja · trust
-
№ 019
Lateral Movement Lateral movement involves an attacker moving from one compromised system to another within the same network. The goal is to expand access to systems containing more valuable data or enabling further escalation.tehnika · privileges
-
№ 015
Living off the Land Using legitimate system tools to execute malicious actions.tehnika · execution
-
№ 043
Log Tampering Deleting, modifying, or disabling logs to hide activity.tehnika · evasion
-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.odbrana · monitoring / response
-
№ 017
MDR MDR (Managed Detection and Response) is a service where an external security team provides continuous monitoring, threat detection, and incident response on behalf of an organization. It combines technology with human expertise.odbrana · monitoring / response
-
№ 038
Malware Delivery Malware delivery encompasses the methods by which malicious software is transferred to a target system. This includes infected attachments, compromised websites, malicious ads, removable media, and compromised software updates.tehnika · C2
-
№ 032
Microsegmentation Finer network division at workload or application level, not just VLANs.odbrana · resilience
-
№ 073
Model theft / extraction Model theft and extraction means an attacker obtains a model an organization trained, bought or adapted to its own needs. That can be direct theft of the files, the weights and the configuration, but also controlled extraction through an API, where the model is queried enough times to build an approximate copy.pretnja · AI / ML
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is to limit an attacker's ability to move through the network after compromising a single system.odbrana · resilience
-
№ 028
Network Sniffing Passively intercepting network traffic to collect sensitive data.tehnika · discovery
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience
-
№ 013
Payload Obfuscation Payload obfuscation involves applying techniques to conceal the content and intent of malicious code. Attackers use encryption, compression, encoding, polymorphism, and packing to evade detection by security tools.tehnika · execution
-
№ 071
Physical Access Attack Physical access is the oldest form of compromise: the attacker reaches the device, the room, a port, a cable or a piece of paper. Once somebody can sit down at a computer, walk up to a server, put a device into a port or carry a laptop away, digital protection no longer helps.pretnja · physical / IoT
-
№ 018
Privilege Escalation Privilege escalation is a technique by which an attacker with limited access gains a higher level of authorization. Vertical escalation means reaching administrator or root level, while horizontal escalation means accessing another user's resources at the same privilege level.tehnika · privileges
-
№ 010
Privileged Access Management Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.odbrana · identity / access
-
№ 025
Reconnaissance Reconnaissance involves the systematic gathering of information about the target environment, both externally before the attack and internally after compromise. The goal is to understand the topology, identify targets, and plan the next stages.tehnika · discovery
-
№ 043
Regulatory Compliance Meeting requirements of regulatory frameworks and standards for cybersecurity.odbrana · governance
-
№ 015
SIEM SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.odbrana · monitoring / response
-
№ 018
SOAR Security Orchestration, Automation and Response — automating security operations.odbrana · monitoring / response
-
№ 014
Secrets Management Applications, scripts, and services need secrets to do their work — passwords, API keys, certificates, database connection strings. The wrong place for them is code, a config file, a repository, or a chat message. Secrets management means a central, protected store (a vault) from which an application fetches a secret exactly when it needs it, instead of carrying it around in plaintext.odbrana · identity / access
-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.odbrana · resilience
-
№ 037
Security Awareness Employee education programs about cyber threats and safe behavior.odbrana · people
-
№ 039
Security Champions An ambassador program for security within development and business teams.odbrana · people
-
№ 042
Security Policies Formal documents defining an organization's cybersecurity rules and standards.odbrana · governance
-
№ 019
Session Hijacking When you log in, the service opens a session — a state that remembers you are you, together with everything that goes with it, such as your preferences and settings. The main benefit is that you do not have to type a password every few minutes as you move through the features. That session is marked by an identifier, usually held in a browser cookie. Session hijacking is the taking over of a session that is already open. The attacker does not attack the login; they slip into a session that has already passed authentication and carry on operating the service in your name.pretnja · identity
-
№ 019
Threat Intelligence Collecting, analyzing, and applying data about current cyber threats.odbrana · monitoring / response
-
№ 004
XDR XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.odbrana · endpoints