Pretnje
7 direktnih pogodaka-
№ 056
BGP Hijacking … why RPKI, route validation, prefix filtering and monitoring of changes matter so much in the defense. Without them, routes are too fragile for the way the inte …pretnja · availability
-
№ 011
Fileless malware … xecutions and scheduled tasks. Without behavioral monitoring, this malware slips under the radar.pretnja · malware
-
№ 022
Kerberoasting … cannot hold more rights than it needs, along with monitoring for unusual ticket requests, and wrap all of it in strong modern encryption, and the attacker has l …pretnja · identity
-
№ 073
Model theft / extraction Rate limiting, query monitoring and access control protect the asset here, but not availability.pretnja · AI / ML
-
№ 020
Privilege Escalation … separate handling of administrator accounts, and monitoring of privileged actions. The point is to limit the reach of the break-in — if an account has limited …pretnja · identity
-
№ 070
SCADA/OT Attack … e network. When IT and OT networks are joined for monitoring, remote access or efficiency, the attack surface grows.pretnja · physical / IoT
-
№ 066
Typosquatting … r domains helps but does not cover every variant. Monitoring is not optional.pretnja · trust
Tehnike
7 direktnih pogodaka-
№ 027
Automation & Scripting Restricting access to scripting interpreters and monitoring script execution aids in detection.tehnika · discovery
-
№ 031
Data Exfiltration Monitoring unusually large outbound transfers and mass data access helps with early detection.tehnika · exfiltration / impact
-
№ 040
Domain Fronting Network monitoring only sees traffic to the legitimate CDN domain.tehnika · C2
-
№ 014
In-Memory Execution Requires EDR with process behavior monitoring for detection.tehnika · execution
-
№ 019
Lateral Movement Network segmentation and monitoring inter-system authentications significantly hinder lateral movement.tehnika · privileges
-
№ 011
Persistence Monitoring file and configuration integrity is key to detecting persistence mechanisms.tehnika · execution
-
№ 025
Reconnaissance Monitoring unusual scanning and directory service queries can indicate reconnaissance activity.tehnika · discovery
Odbrane
13 direktnih pogodaka-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those r …odbrana · monitoring / response
-
№ 033
CSPM CSPM continuously checks how the cloud environment is configured against good-practice and compliance rules: which buckets are public, which identities hold too many rights, where encryption is off, where logging is off. Instead of someone clicking manually through the console, the tool watches the whole account or subscription and flags when a setting drifts into danger.odbrana · resilience
-
№ 034
DLP DLP watches where sensitive data goes and stops it where it shouldn't: an employee attaching a client list to a private email, copying a file with personal data to a USB, or pasting a database into a chat. It works by recognizing patterns (national IDs, card numbers, marked documents) and applying rules per channel — mail, web, endpoint, cloud.odbrana · resilience
-
№ 013
Certificate Management Includes monitoring third-party certificates and wildcard certificates.odbrana · identity / access
-
№ 003
EDR EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.odbrana · endpoints
-
№ 009
Identity & Access Management Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.odbrana · identity / access
-
№ 017
MDR … ere an external security team provides continuous monitoring, threat detection, and incident response on behalf of an organization. It combines technology with …odbrana · monitoring / response
-
№ 010
Privileged Access Management … s, automatic password rotation, real-time session monitoring, and just-in-time access approval instead of permanent standing access.odbrana · identity / access
-
№ 041
Risk Assessment Systematic process of identifying, analyzing, and prioritizing cyber risks.odbrana · governance
-
№ 015
SIEM … generation based on defined rules, and compliance monitoring against regulatory requirements. It serves as the central visibility point for security operations.odbrana · monitoring / response
-
№ 019
Threat Intelligence … lude OSINT, commercial feeds, ISACs, and dark web monitoring.odbrana · monitoring / response
-
№ 027
WAF … tion-layer attacks. It can operate in blocking or monitoring mode.odbrana · resilience
-
№ 011
Zero Trust … MFA, micro-segmentation, user and device behavior monitoring, and context-based access policies. Zero Trust is not a product but an architectural approach.odbrana · identity / access