166 terms ·
75/46/45
32 rezultata za „command and control" ·
3 direktna ·
29 povezanih
Pretnje
1 direktan pogodakOdbrane
2 direktna pogotka-
№ 029
DNS Security … s to known malicious domains, phishing sites, and command-and-control servers before a connection is established. DNS traffic analysis can reveal tunneling and …odbrana · resilience
-
№ 035
Firewall … e only when a compromised host tries to reach its command-and-control server. If outbound traffic is left open "just in case", the firewall has done half its jo …odbrana · resilience
↳ Povezano
29 stavki koje koriste „command and control"-
№ 027
Automation & Scripting Automation and scripting involves using scripts, tools, and automated procedures to accelerate and scale activities within a compromised environment. Attackers leverage system scripting interpreters, configuration management tools, and custom scripts.tehnika · discovery
-
№ 006
Backdoor A backdoor is a hidden way in. Once placed or opened, it lets the attacker return to the machine — with no password, no authorization and no entry in the ordinary records. A backdoor can be opened by malware while it runs, but it can equally be a user account nobody watches, or web shell access left on a server.pretnja · malware
-
№ 015
Brute-force attack A brute-force attack breaks into an account by trying to log in over and over: automated tools work through password after password until one takes. It succeeds against short, weak and common passwords, and against systems that put no limit on failed attempts. It is not clever — it is only fast, and it can run for days.pretnja · identity
-
№ 039
Command & Control Command and control communication involves establishing a persistent channel between the attacker and the compromised system for sending commands and receiving results. The attacker uses this channel to manage malware, launch new attack phases, and retrieve data.tehnika · C2
-
№ 028
DDoS Protection DDoS protection encompasses technologies and services that detect and mitigate distributed denial-of-service attacks before malicious traffic reaches or overwhelms the target infrastructure.odbrana · resilience
-
№ 051
DNS Amplification DNS amplification is a reflected DDoS attack in which the attacker uses open DNS resolvers to multiply the traffic aimed at a victim. The attacker sends relatively small DNS queries but forges the victim's address as the source.pretnja · availability
-
№ 057
DNS Poisoning DNS poisoning is an attack in which a user or a resolver is given a false answer for a domain. The result is that the user types a familiar address into the browser and DNS takes them to the wrong web server. On paper the name is the same. In reality the road leads somewhere else.pretnja · availability
-
№ 036
DNS Tunneling Technique of exfiltrating data or C2 communication through DNS queries.tehnika · exfiltration / impact
-
№ 031
Data Exfiltration Data exfiltration involves transferring stolen information from the compromised environment to an attacker-controlled location. Data can be sent through encrypted channels, legitimate cloud services, email, or even physical media.tehnika · exfiltration / impact
-
№ 049
Distributed Denial of Service / DDoS DDoS is a distributed denial-of-service attack. Instead of attacking from one place, the attacker uses a large number of compromised devices, rented infrastructure and reflected traffic to bury the target in web requests until the server is blocked. The aim is not data theft but choking the service into unavailability.pretnja · availability
-
№ 040
Domain Fronting Technique of hiding C2 traffic behind legitimate CDN domains.tehnika · C2
-
№ 042
Encrypted C2 Channels Using HTTPS, DNS-over-HTTPS, or other encrypted protocols for C2.tehnika · C2
-
№ 010
Exploitation Exploitation involves leveraging a flaw in software, hardware, or configuration to execute unauthorized code or bypass security controls. Vulnerabilities can exist in operating systems, applications, network services, or firmware.tehnika · execution
-
№ 041
Fast-Flux DNS Rapid rotation of IP addresses associated with a C2 domain.tehnika · C2
-
№ 022
IDS/IPS IDS/IPS are systems that monitor network traffic (or host activity) for patterns indicating an attack. An IDS (Intrusion Detection System) only reports suspicious activity; an IPS (Intrusion Prevention System) sits inline and can block it immediately.odbrana · monitoring / response
-
№ 067
IoT Device Compromise IoT device compromise hits cameras, routers, sensors, smart televisions, locks, controllers and all the equipment connected to a network that does not behave like a classic computer. The problem is that these devices are often forgotten the moment they are switched on.pretnja · physical / IoT
-
№ 019
Lateral Movement Lateral movement involves an attacker moving from one compromised system to another within the same network. The goal is to expand access to systems containing more valuable data or enabling further escalation.tehnika · privileges
-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.odbrana · monitoring / response
-
№ 032
Malvertising Malvertising uses ad networks as a delivery channel for attacks. The user does not have to be on a dubious site; a malicious advert can appear on a legitimate portal too, because ad space often arrives through several intermediaries.pretnja · social eng.
-
№ 038
Malware Delivery Malware delivery encompasses the methods by which malicious software is transferred to a target system. This includes infected attachments, compromised websites, malicious ads, removable media, and compromised software updates.tehnika · C2
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is to limit an attacker's ability to move through the network after compromising a single system.odbrana · resilience
-
№ 026
Phishing Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a message that appears to come from a known organization — a bank, a courier, a government service, a colleague — and leads the victim into doing one of three things: clicking a link, opening an attachment, or entering their credentials somewhere.pretnja · social eng.
-
№ 025
Reconnaissance Reconnaissance involves the systematic gathering of information about the target environment, both externally before the attack and internally after compromise. The goal is to understand the topology, identify targets, and plan the next stages.tehnika · discovery
-
№ 014
Remote access trojan - RAT A RAT gives the attacker remote control of your machine. Once inside they can browse files, switch on the camera and microphone, record what you type and run commands — all of it live, as if sitting in front of your screen. It resembles remote support tools, only on the wrong side of the law.pretnja · malware
-
№ 032
Resource Exhaustion Resource exhaustion as a technique involves deliberately overloading target systems to make them unavailable to legitimate users. The attacker targets CPU, memory, network bandwidth, disk, or connection limits.tehnika · exfiltration / impact
-
№ 070
SCADA/OT Attack An attack on SCADA and OT systems targets industrial processes, not only data. These are the systems that run manufacturing, energy, water, transport, buildings, sensors, PLC controllers and HMI stations. When such a system stops or starts working wrongly, the consequences can be fatal.pretnja · physical / IoT
-
№ 033
Service Abuse Service abuse as a technique involves using legitimate system functionalities in unintended ways to cause damage, gain unauthorized access, or achieve financial gain.tehnika · exfiltration / impact
-
№ 066
Typosquatting Typosquatting exploits small mistakes in typing, reading or recognizing a name. The attacker registers a domain, an account or a software package that resembles a legitimate name, counting on a user, a developer or a system to miss one letter, swap a character or overlook the difference.pretnja · trust
-
№ 008
Worm A worm spreads on its own. Unlike a virus it needs no host file and no click from the user — once it is on one machine it immediately looks for the next, and the next, and thousands of devices can be infected within minutes. Replication is its purpose, speed is its weapon, and whatever it carries is the real threat.pretnja · malware