Pretnje
2 direktna pogotka-
№ 010
Rootkit … me layer, a classic antivirus is a poor opponent. Detection is possible; removal is much harder. It is found by comparison against a trusted reference, by check …pretnja · malware
-
№ 044
Zero-Day Exploitation … cing the attack surface, segmentation, behavioral detection, limited rights and a response plan. When you do not know the exact flaw, you have to limit what its …pretnja · applications
Tehnike
12 direktnih pogodaka-
№ 027
Automation & Scripting … erpreters and monitoring script execution aids in detection.tehnika · discovery
-
№ 036
DNS Tunneling Transfer speed is low, but detection without specialized tools is difficult.tehnika · exfiltration / impact
-
№ 031
Data Exfiltration … d transfers and mass data access helps with early detection.tehnika · exfiltration / impact
-
№ 042
Encrypted C2 Channels … equires TLS inspection or behavioral analysis for detection.tehnika · C2
-
№ 012
Impair Defenses … vity from security tools, analysts, and automated detection systems. The goal is to remain undetected for as long as possible in the compromised environment.tehnika · execution
-
№ 014
In-Memory Execution Requires EDR with process behavior monitoring for detection.tehnika · execution
-
№ 046
Indicator Removal Detection and analysis require advanced forensic tools and expertise.tehnika · evasion
-
№ 015
Living off the Land Hampers detection because signed system binaries are used.tehnika · execution
-
№ 043
Log Tampering Detection requires centralized logging on a protected server.tehnika · evasion
-
№ 013
Payload Obfuscation … ion, encoding, polymorphism, and packing to evade detection by security tools.tehnika · execution
-
№ 033
Service Abuse … buses the normal behavior of services. This makes detection difficult because the activities themselves are considered legitimate.tehnika · exfiltration / impact
-
№ 006
Supply Chain Compromise Detection is difficult because the signature and distribution appear legitimate.tehnika · initial access
Odbrane
23 direktna pogotka-
№ 031
Deception Technology Deploying decoy resources (honeypots, honeytokens) to detect attackers.odbrana · resilience
-
№ 003
EDR EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and re …odbrana · endpoints
-
№ 001
Endpoint Protection … ties. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 022
IDS/IPS … patterns indicating an attack. An IDS (Intrusion Detection System) only reports suspicious activity; an IPS (Intrusion Prevention System) sits inline and can b …odbrana · monitoring / response
-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.odbrana · monitoring / response
-
№ 017
MDR MDR (Managed Detection and Response) is a service where an external security team provides continuous monitoring, threat detection, and incident response on beh …odbrana · monitoring / response
-
№ 015
SIEM SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.odbrana · monitoring / response
-
№ 004
XDR XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.odbrana · endpoints
-
№ 024
Backup & Recovery Backup and recovery encompasses the processes and technologies for regularly creating copies of data and systems, storing them securely, and enabling reliable restoration in the event of loss, corruption, or destruction of original data.odbrana · resilience
-
№ 029
DNS Security DNS security encompasses technologies that protect DNS infrastructure and use DNS traffic as a control point for blocking access to malicious domains and detecting suspicious communications.odbrana · resilience
-
№ 021
Digital Forensics Collecting, preserving, and analyzing digital evidence after a cyber incident.odbrana · monitoring / response
-
№ 002
Email Security … in authenticity verification, and suspicious link detection. More advanced variants use machine learning to recognize new attack patterns.odbrana · endpoints
-
№ 020
Incident Response A planned process of identifying, containing, eradicating, and recovering from cyber incidents.odbrana · monitoring / response
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is to limit an attacker's ability to move through the network after compromising a single system.odbrana · resilience
-
№ 010
Privileged Access Management Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.odbrana · identity / access
-
№ 041
Risk Assessment Systematic process of identifying, analyzing, and prioritizing cyber risks.odbrana · governance
-
№ 018
SOAR Security Orchestration, Automation and Response — automating security operations.odbrana · monitoring / response
-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.odbrana · resilience
-
№ 037
Security Awareness Employee education programs about cyber threats and safe behavior.odbrana · people
-
№ 039
Security Champions An ambassador program for security within development and business teams.odbrana · people
-
№ 042
Security Policies Formal documents defining an organization's cybersecurity rules and standards.odbrana · governance
-
№ 019
Threat Intelligence … grate into SIEM, EDR, and firewalls for proactive detection.odbrana · monitoring / response
-
№ 011
Zero Trust Zero Trust is a security concept that assumes no user, device, or network segment should be automatically trusted, regardless of whether it is inside or outside the corporate network. Every access request is verified before approval.odbrana · identity / access