Pretnje
34 direktna pogotka-
№ 053
Botnet Attacks … ised devices the attacker controls remotely. That network can hold computers, servers, routers, cameras, NAS devices, phones and IoT equipment. The owner of the …pretnja · availability
-
№ 051
DNS Amplification DNS amplification is a reflected DDoS attack in which the attacker uses open DNS resolvers to multiply the traffic aimed at a victim. The attacker sends relatively small DNS queries but forges the victim's address as the source.pretnja · availability
-
№ 057
DNS Poisoning A local network uses a compromised DNS server that redirects popular domains to false addresses.pretnja · availability
-
№ 049
Distributed Denial of Service / DDoS The attack can hit network capacity, the transport layer, or the application itself. Sometimes a huge volume of traffic is sent to congest the link, sometimes c …pretnja · availability
-
№ 008
Worm To spread it uses what connects computers: the network, shared resources, unpatched vulnerabilities. It can carry extra cargo — ransomware, a backdoor, a remote …pretnja · malware
-
№ 021
Account Takeover … hanges the recovery address and phone on a social network, the owner rarely gets the account back, if at all. What usually follows is a new account and building …pretnja · identity
-
№ 056
BGP Hijacking … terception of traffic, or its diversion through a network that should never have been on that path. Sometimes it is a provider's mistake, sometimes a deliberate …pretnja · availability
-
№ 006
Backdoor … ose — permanent access to the victim's machine or network, regardless of patching, changed credentials or a reinstalled system.pretnja · malware
-
№ 075
Cloud IAM misconfiguration … ermission to read data, spin up resources, change networks, assume roles and delete backups.pretnja · cloud
-
№ 063
Contractor Abuse … he external associate becomes a blind spot in the network of trust.pretnja · trust
-
№ 050
Denial of Service / DoS … use it. Unlike DDoS it need not come from a large network of compromised devices. Sometimes one source and a well-chosen vulnerability are enough.pretnja · availability
-
№ 068
Evil Twin A fake Wi-Fi network, known as an evil twin, imitates a legitimate wireless network so that users connect to an access point the attacker controls. The network …pretnja · physical / IoT
-
№ 012
Infostealer … ms: account takeover, a break-in to the corporate network, ransomware. A large share of breaches begins with credentials some stealer gathered months earlier.pretnja · malware
-
№ 067
IoT Device Compromise … controllers and all the equipment connected to a network that does not behave like a classic computer. The problem is that these devices are often forgotten th …pretnja · physical / IoT
-
№ 022
Kerberoasting … eroasting is an attack specific to Windows domain networks and Active Directory (AD). User logins are handled by the Kerberos protocol, which issues tickets as …pretnja · identity
-
№ 032
Malvertising Malvertising uses ad networks as a delivery channel for attacks. The user does not have to be on a dubious site; a malicious advert can appear on a legitimate p …pretnja · social eng.
-
№ 023
Pass-the-Hash … y can try logging in to the other machines on the network. Wherever the same account exists, Windows accepts the login as legitimate. That way an attacker can c …pretnja · identity
-
№ 016
Password spraying … e hit is enough for the attacker to be inside the network.pretnja · identity
-
№ 047
Path Traversal A vulnerable VPN or network device allows files holding sessions or credentials to be read through path manipulation.pretnja · applications
-
№ 020
Privilege Escalation … o widen their rights in order to move through the network. Escalation is rarely the first stage — it comes after entry through, say, an ordinary user account or …pretnja · identity
-
№ 014
Remote access trojan - RAT … wait for the right moment to move deeper into the network. Because it works interactively, it is more dangerous than malware programmed in advance for a fixed s …pretnja · malware
-
№ 052
Resource Exhaustion … tem cannot work without: processor, memory, disk, network connections, threads, the database or processing queues. The aim is not necessarily to send enormous t …pretnja · availability
-
№ 010
Rootkit … kernel rootkit hides the attacker's processes and network connections, so the administrator looks at a clean system while the malware operates beneath the secur …pretnja · malware
-
№ 070
SCADA/OT Attack … esigned for reliable operation, not for a hostile network. When IT and OT networks are joined for monitoring, remote access or efficiency, the attack surface gr …pretnja · physical / IoT
-
№ 025
SIM Swapping A phone suddenly shows no network where there should be one — a possible sign that a number transfer is already in progress.pretnja · identity
-
№ 045
SSRF … addresses is rarely enough. Better an allowlist, network separation, and the rule that an application may call only what it genuinely needs.pretnja · applications
-
№ 019
Session Hijacking … cepts a session cookie on an unprotected wireless network and carries on using the victim's account without logging in once.pretnja · identity
-
№ 027
Spear Phishing … g — it is their cheapest way into a well-defended network.pretnja · social eng.
-
№ 059
Third-Party Compromise … er and uses its account to reach a large client's network.pretnja · trust
-
№ 069
USB Drop Attack … ot gone away, because it steps around part of the network protection. The attacker sends no email and jumps no company firewall; they rely on the victim carryin …pretnja · physical / IoT
-
№ 009
Virus … document moves from file to file across a company network, multiplying each time somebody opens an infected document.pretnja · malware
-
№ 036
Watering Hole Attack … licious script only for users coming from certain networks.pretnja · social eng.
-
№ 007
Wiper … lities it can bring down hundreds or thousands of networks within hours. Unlike ransomware it offers no ransom; recovery was never part of the plan, because the …pretnja · malware
-
№ 044
Zero-Day Exploitation A vulnerability in a network device is exploited before the vendor publishes a patch.pretnja · applications
Tehnike
16 direktnih pogodaka-
№ 028
Network Sniffing Passively intercepting network traffic to collect sensitive data.tehnika · discovery
-
№ 009
AiTM AiTM sits between the user and the real service. Classic phishing steals a password; AiTM steals the live session. The victim gets a link, lands on a proxy that looks exactly like the real login (because it forwards everything to the real site), enters credentials and even the MFA code — the proxy passes them through, the real service issues a session token, and the attacker captures that token.tehnika · initial access
-
№ 020
Access Token Manipulation … pting a session cookie on an unprotected wireless networktehnika · privileges
-
№ 027
Automation & Scripting Automated network scanning and information collection on all active systemstehnika · discovery
-
№ 024
Cloud lateral movement Here you don't breach the network, you walk through permissions — the movement is quiet because the system considers it allowed.tehnika · privileges
-
№ 039
Command & Control … mmunication is often disguised to resemble normal network traffic, using standard protocols, encryption, and legitimate services as intermediaries.tehnika · C2
-
№ 026
Configuration Abuse Using default admin credentials on a network devicetehnika · discovery
-
№ 040
Domain Fronting Network monitoring only sees traffic to the legitimate CDN domain.tehnika · C2
-
№ 007
Drive-by Download Malvertising campaigns via compromised ad networkstehnika · initial access
-
№ 042
Encrypted C2 Channels Standard network inspection cannot read the communication content.tehnika · C2
-
№ 010
Exploitation … ies can exist in operating systems, applications, network services, or firmware.tehnika · execution
-
№ 019
Lateral Movement … one compromised system to another within the same network. The goal is to expand access to systems containing more valuable data or enabling further escalation.tehnika · privileges
-
№ 021
Pass-the-Hash Effective in networks using NTLM instead of Kerberos authentication.tehnika · privileges
-
№ 008
Physical Access … ludes USB devices, external media boot, or direct network connection.tehnika · initial access
-
№ 025
Reconnaissance … entification. Internal reconnaissance encompasses network mapping, user and group enumeration, and shared resource discovery.tehnika · discovery
-
№ 032
Resource Exhaustion … gitimate users. The attacker targets CPU, memory, network bandwidth, disk, or connection limits.tehnika · exfiltration / impact
Odbrane
23 direktna pogotka-
№ 036
Virtual Private Network A VPN (virtual private network) creates an encrypted tunnel between a device and the network it connects to. For an organization this primarily means controlled …odbrana · resilience
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is …odbrana · resilience
-
№ 028
DDoS Protection These solutions operate at the network and application layers, filtering malicious traffic while allowing legitimate requests through. They can be implemented a …odbrana · resilience
-
№ 029
DNS Security … nology provides broad coverage because nearly all network traffic depends on DNS resolution, making it an effective point for enforcing security policies.odbrana · resilience
-
№ 035
Firewall … ewall is a control placed at the boundary between networks that permits or blocks traffic according to predefined rules — deciding who may talk to whom, on whic …odbrana · resilience
-
№ 022
IDS/IPS IDS/IPS are systems that monitor network traffic (or host activity) for patterns indicating an attack. An IDS (Intrusion Detection System) only reports suspicio …odbrana · monitoring / response
-
№ 024
Backup & Recovery … ically or logically separated from the production network. This protects against ransomware that attempts to encrypt backup copies as well.odbrana · resilience
-
№ 033
CSPM CSPM continuously checks how the cloud environment is configured against good-practice and compliance rules: which buckets are public, which identities hold too many rights, where encryption is off, where logging is off. Instead of someone clicking manually through the console, the tool watches the whole account or subscription and flags when a setting drifts into danger.odbrana · resilience
-
№ 030
Data Encryption Protecting data by encrypting it at rest and in transit.odbrana · resilience
-
№ 040
DevSecOps Integrating security into all phases of the software development lifecycle.odbrana · people
-
№ 021
Digital Forensics Includes disk, memory, network, and mobile device forensics.odbrana · monitoring / response
-
№ 003
EDR … y. It records detailed telemetry about processes, network connections, file changes, and registry activity.odbrana · endpoints
-
№ 001
Endpoint Protection … el of protection that should be supplemented with network and identity controls.odbrana · endpoints
-
№ 016
Logging & Monitoring … ic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security inci …odbrana · monitoring / response
-
№ 017
MDR … ervice typically includes monitoring endpoint and network telemetry, alert triage, investigation of suspicious activity, and coordinated response to confirmed i …odbrana · monitoring / response
-
№ 032
Microsegmentation Finer network division at workload or application level, not just VLANs.odbrana · resilience
-
№ 005
Mobile Device Security Managing and protecting mobile devices through MDM and MAM solutions.odbrana · endpoints
-
№ 045
Penetration Testing Covers network, web applications, social engineering, and physical access.odbrana · governance
-
№ 010
Privileged Access Management Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.odbrana · identity / access
-
№ 015
SIEM SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.odbrana · monitoring / response
-
№ 027
WAF WAF (Web Application Firewall) is a firewall that filters, monitors, and blocks HTTP/HTTPS traffic to web applications. It sits between users and the web server, analyzing each request against defined rules.odbrana · resilience
-
№ 004
XDR … ection and Response) unifies data from endpoints, network, email, and cloud.odbrana · endpoints
-
№ 011
Zero Trust … security concept that assumes no user, device, or network segment should be automatically trusted, regardless of whether it is inside or outside the corporate n …odbrana · identity / access