Pretnje
26 direktnih pogodaka-
№ 011
Fileless malware Fileless malware never writes itself to disk during the attack, so antivirus software has a harder time finding it. While it operates it lives in memory and wor …pretnja · malware
-
№ 006
Backdoor … the ordinary records. A backdoor can be opened by malware while it runs, but it can equally be a user account nobody watches, or web shell access left on a serv …pretnja · malware
-
№ 013
Cryptominer A cryptominer steals what we rarely think of as a target: our computing power and our electricity. In the background it uses our processors and graphics cards to mine cryptocurrency for the attacker while we pay the bill. It has no interest in our data, only in our resources and how much of them there is.pretnja · malware
-
№ 012
Infostealer An infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.pretnja · malware
-
№ 004
Keylogger A keylogger is a program or hardware device that records every keystroke. Software keyloggers run covertly in the background, while hardware variants can be physically attached between the keyboard and the computer.pretnja · malware
-
№ 005
Loader / Dropper … somware, infostealers, remote access tools, other malware. Loaders are now rented out as a service — attackers pay to have their cargo smuggled in.pretnja · malware
-
№ 014
Remote access trojan - RAT … it works interactively, it is more dangerous than malware programmed in advance for a fixed set of functions.pretnja · malware
-
№ 010
Rootkit … e administrator looks at a clean system while the malware operates beneath the security tools.pretnja · malware
-
№ 003
Spyware On a computer it usually arrives alongside other malware or through an exploited vulnerability. On a phone it is worse — advanced surveillance tools can install …pretnja · malware
-
№ 002
Trojan A Trojan does not break in; the victim opens the door. It usually presents itself as something useful — a program or a document, a fake installer, a cracked application, or a harmless-looking tool for speeding up the computer. The user runs what they meant to run, and the attacker gets what they were after.pretnja · malware
-
№ 009
Virus … e early two-thousands it was the dominant form of malware; today it has been pushed aside, because attackers prefer quiet threats that bring money to noisy ones …pretnja · malware
-
№ 007
Wiper A wiper does not exist to steal or to extort — a wiper destroys data. It erases and overwrites, breaks file systems, and combined with worms and zero-day vulnerabilities it can bring down hundreds or thousands of networks within hours. Unlike ransomware it offers no ransom; recovery was never part of the plan, because the aim is damage, not money.pretnja · malware
-
№ 008
Worm A worm spreads on its own. Unlike a virus it needs no host file and no click from the user — once it is on one machine it immediately looks for the next, and the next, and thousands of devices can be infected within minutes. Replication is its purpose, speed is its weapon, and whatever it carries is the real threat.pretnja · malware
-
№ 042
API Abuse … e they look like normal traffic. There need be no malware, no link, no file. There are only requests, tokens, parameters and a pace that suddenly resembles a sc …pretnja · applications
-
№ 021
Account Takeover … to malicious content, send fake invoices, deliver malware — all while the owner's contacts trust it, because the account is genuine. The most dangerous part is …pretnja · identity
-
№ 053
Botnet Attacks … paigns, password spraying, cryptocurrency mining, malware distribution and other work that needs quantity. The strength of a botnet is not in one device but in …pretnja · availability
-
№ 028
Business Email Compromise … ous. No attachment, no malicious link, no obvious malware. The message can be short, polite and businesslike. "Can this go out today?", "The supplier has change …pretnja · social eng.
-
№ 057
DNS Poisoning … fake page, intercept communication, or distribute malware from somewhere that resembles the legitimate source.pretnja · availability
-
№ 026
Phishing … voice or a purchase order, which actually carries malware.pretnja · social eng.
-
№ 070
SCADA/OT Attack Malware in an OT environment interrupts the HMI stations and makes it harder for operators to control the process.pretnja · physical / IoT
-
№ 019
Session Hijacking … e site that allows the cookie to be read, or with malware. Identifiers can also be predicted when the service generates them by a weak and foreseeable pattern. …pretnja · identity
-
№ 027
Spear Phishing … he minutes attached — and the attachment carrying malware.pretnja · social eng.
-
№ 018
Token Theft Tokens are mostly stolen in three ways. Malware on the device reads them straight from the browser store or from application memory. Adversary-in-the-middle phi …pretnja · identity
-
№ 066
Typosquatting … but ends up on a fake page for credential theft, malware distribution or advertising. With software packages, a developer installs a package whose name resembl …pretnja · trust
-
№ 069
USB Drop Attack … he USB need not be ordinary storage. It can carry malware, a fake document, a script, or a device that presents itself to the computer as a keyboard and types c …pretnja · physical / IoT
-
№ 036
Watering Hole Attack … or a narrow professional group is used to deliver malware unnoticed to targeted visitors.pretnja · social eng.
Tehnike
13 direktnih pogodaka-
№ 038
Malware Delivery Malware delivery encompasses the methods by which malicious software is transferred to a target system. This includes infected attachments, compromised websites …tehnika · C2
-
№ 027
Automation & Scripting … ing a configuration management tool to distribute malware to all serverstehnika · discovery
-
№ 039
Command & Control … results. The attacker uses this channel to manage malware, launch new attack phases, and retrieve data.tehnika · C2
-
№ 016
DLL Sideloading PlugX malware delivered via DLL sideloadingtehnika · execution
-
№ 034
Data Destruction Wiper malware implements this technique as its primary function.tehnika · exfiltration / impact
-
№ 007
Drive-by Download Drive-by download is automatic malware download when visiting a compromised site.tehnika · initial access
-
№ 042
Encrypted C2 Channels Most modern malware uses HTTPS for C2 communication.tehnika · C2
-
№ 014
In-Memory Execution Execution technique for fileless-malware threat.tehnika · execution
-
№ 046
Indicator Removal Use of RAM-only malware that leaves no traces on disk.tehnika · evasion
-
№ 015
Living off the Land Does not require downloading additional malware — uses what is already on the system.tehnika · execution
-
№ 013
Payload Obfuscation … chnique is applied across all attack phases, from malware delivery via email to communication with command servers.tehnika · execution
-
№ 045
Process Injection … owing — replacing legitimate process content with malwaretehnika · evasion
-
№ 005
Watering Hole It may use drive-by downloads or exploit kits for malware delivery.tehnika · initial access
Odbrane
8 direktnih pogodaka-
№ 006
Browser Isolation … s drive-by downloads, exploit kits, and web-based malware from reaching the endpoint.odbrana · endpoints
-
№ 029
DNS Security DNS security encompasses technologies that protect DNS infrastructure and use DNS traffic as a control point for blocking access to malicious domains and detecting suspicious communications.odbrana · resilience
-
№ 030
Data Encryption Protecting data by encrypting it at rest and in transit.odbrana · resilience
-
№ 031
Deception Technology Deploying decoy resources (honeypots, honeytokens) to detect attackers.odbrana · resilience
-
№ 002
Email Security … nbound and outbound messages to prevent phishing, malware delivery, and business email compromise. It operates at the server or cloud level before the message r …odbrana · endpoints
-
№ 001
Endpoint Protection … d activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 032
Microsegmentation Finer network division at workload or application level, not just VLANs.odbrana · resilience
-
№ 005
Mobile Device Security Protects against mobile phishing, malware, and device theft.odbrana · endpoints