Pretnje
9 direktnih pogodaka-
№ 066
Typosquatting … g or recognizing a name. The attacker registers a domain, an account or a software package that resembles a legitimate name, counting on a user, a developer or …pretnja · trust
-
№ 028
Business Email Compromise … . Then the message does not come from a lookalike domain but from the real account, inside a real conversation, at the right moment. The attacker reads the corr …pretnja · social eng.
-
№ 017
Credential stuffing … of credentials from the same company and the same domain on a dark web market, the odds that the leaked credentials still work rise sharply.pretnja · identity
-
№ 057
DNS Poisoning … user or a resolver is given a false answer for a domain. The result is that the user types a familiar address into the browser and DNS takes them to the wrong …pretnja · availability
-
№ 022
Kerberoasting Kerberoasting is an attack specific to Windows domain networks and Active Directory (AD). User logins are handled by the Kerberos protocol, which issues tickets …pretnja · identity
-
№ 023
Pass-the-Hash … t and the passing of collected hashes towards the domain controller.pretnja · identity
-
№ 020
Privilege Escalation … ns: vertical escalation, from an ordinary user to domain administrator, and horizontal, moving from one account to another user's resources at the same level of …pretnja · identity
-
№ 054
Service Abuse … end a large number of emails to one person or one domain.pretnja · availability
-
№ 029
voice phishing - Vishing … There is little time to check a sender address, a domain, a link or a message header. If the call is convincing enough, if the number looks familiar, and if a l …pretnja · social eng.
Tehnike
9 direktnih pogodaka-
№ 029
Domain Account Discovery Does not require privileged access — any domain user can enumerate AD.tehnika · discovery
-
№ 040
Domain Fronting … hnique of hiding C2 traffic behind legitimate CDN domains.tehnika · C2
-
№ 009
AiTM … -resistant factors (FIDO2 keys, bound to the real domain) are the answer; SMS and app codes don't help here.tehnika · initial access
-
№ 027
Automation & Scripting … pt that automatically harvests passwords from all domain workstationstehnika · discovery
-
№ 036
DNS Tunneling Data is encoded in DNS requests (subdomains) and responses (TXT, CNAME).tehnika · exfiltration / impact
-
№ 041
Fast-Flux DNS … pid rotation of IP addresses associated with a C2 domain.tehnika · C2
-
№ 022
Forge Kerberos Tickets All require access to an AD environment as a domain user or administrator.tehnika · privileges
-
№ 019
Lateral Movement … ng an administrator password hash to access other domain serverstehnika · privileges
-
№ 025
Reconnaissance Enumerating users and groups in a domain environment after compromising one workstationtehnika · discovery
Odbrane
8 direktnih pogodaka-
№ 029
DNS Security … a control point for blocking access to malicious domains and detecting suspicious communications.odbrana · resilience
-
№ 002
Email Security … ender reputation analysis, attachment sandboxing, domain authenticity verification, and suspicious link detection. More advanced variants use machine learning t …odbrana · endpoints
-
№ 022
IDS/IPS IDS/IPS are systems that monitor network traffic (or host activity) for patterns indicating an attack. An IDS (Intrusion Detection System) only reports suspicious activity; an IPS (Intrusion Prevention System) sits inline and can block it immediately.odbrana · monitoring / response
-
№ 009
Identity & Access Management Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.odbrana · identity / access
-
№ 012
Password Manager … ng risk because autofill only works on legitimate domains.odbrana · identity / access
-
№ 010
Privileged Access Management Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.odbrana · identity / access
-
№ 007
SPF/DKIM/DMARC By default, anyone can put your domain in the sender field — that's how spoofed mail 'from the director' works. SPF, DKIM, and DMARC are three records you publi …odbrana · endpoints
-
№ 019
Threat Intelligence Collecting, analyzing, and applying data about current cyber threats.odbrana · monitoring / response