Pretnje
75 direktnih pogodaka-
№ 067
IoT Device Compromise IoT device compromise hits cameras, routers, sensors, smart televisions, locks, controllers and all the equipment connected to a network that does not behave li …pretnja · physical / IoT
-
№ 014
Remote access trojan - RAT A RAT gives the attacker remote control of your machine. Once inside they can browse files, switch on the camera and microphone, record what you type and run co …pretnja · malware
-
№ 070
SCADA/OT Attack An attack on SCADA and OT systems targets industrial processes, not only data. These are the systems that run manufacturing, energy, water, transport, buildings …pretnja · physical / IoT
-
№ 053
Botnet Attacks A botnet is a set of compromised devices the attacker controls remotely. That network can hold computers, servers, routers, cameras, NAS devices, phones and IoT …pretnja · availability
-
№ 038
Remote Code Execution Remote code execution is one of the most dangerous classes of vulnerability, because it lets an attacker run their own code on a vulnerable system from somewher …pretnja · applications
-
№ 010
Rootkit A rootkit is hard to see, and that is its most important property. It can settle beneath the operating system and beneath the layer where antivirus software can …pretnja · malware
-
№ 006
Backdoor Blocking the initial way in is not the end of the fight. Until you establish which backdoor was opened during the attack, the job is not finished.pretnja · malware
-
№ 058
Insider Threat … or a partner. The trouble is that the access was not necessarily unauthorized to begin with.pretnja · trust
-
№ 024
MFA Fatigue … confirms by pressing an Approve button. It does not work where numbers have to be typed from the login screen, nor where hardware keys are in use.pretnja · identity
-
№ 007
Wiper A wiper does not exist to steal or to extort — a wiper destroys data. It erases and overwrites, breaks file systems, and combined with worms and zero-day vulner …pretnja · malware
-
№ 042
API Abuse … ogramming interface in a way the application did not anticipate or did not restrict enough. An API is not merely a technical add-on to the application. It is of …pretnja · applications
-
№ 065
Accidental Data Leak An accidental data leak is not an attack in the classic sense, but the consequences can look the same. Data becomes available to the wrong people through human …pretnja · trust
-
№ 021
Account Takeover … the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail address, the phone number and the se …pretnja · identity
-
№ 043
Authentication Bypass … hentication bypass means the attacker reaches a protected part of the system without logging in the ordinary way. They need not know a password. Sometimes a fla …pretnja · applications
-
№ 056
BGP Hijacking … raffic is diverted by wrong routing. BGP is the protocol by which autonomous systems on the internet tell each other which path leads to particular IP ranges. I …pretnja · availability
-
№ 015
Brute-force attack … tems that put no limit on failed attempts. It is not clever — it is only fast, and it can run for days.pretnja · identity
-
№ 028
Business Email Compromise Business email compromise is not an ordinary fake email. The attacker breaks into business correspondence, or imitates it well enough that somebody in the compa …pretnja · social eng.
-
№ 075
Cloud IAM misconfiguration … ights than it needs. In the cloud an identity is not merely a login. An identity is permission to read data, spin up resources, change networks, assume roles an …pretnja · cloud
-
№ 074
Cloud storage exposure … mistakes constantly, so exposure rarely stays unnoticed.pretnja · cloud
-
№ 063
Contractor Abuse … often granted legitimately, but afterwards it is not monitored, not narrowed and not withdrawn in time.pretnja · trust
-
№ 017
Credential stuffing Credential stuffing does not go after unknown passwords; it tries known ones. With username and password pairs from databases leaked across the internet, the at …pretnja · identity
-
№ 041
Cross-Site Request Forgery … the user is already logged in. The attacker does not need to know the password. It is enough to lead the user down the wrong path.pretnja · applications
-
№ 040
Cross-Site Scripting … xecuted in the user's browser. The attacker does not have to break into the web server. It is enough for their code to end up in a page the victim opens as thou …pretnja · applications
-
№ 037
Crypto-wallet drainer Here a password is usually not stolen and no encryption is broken. The victim signs an action they do not understand. Once the transaction executes on the chain …pretnja · social eng.
-
№ 013
Cryptominer … ping into your water and power while you suspect nothing until the bills arrive.pretnja · malware
-
№ 051
DNS Amplification … resolvers then send their answers to the victim, not to the attacker. If the answer is much larger than the query, the attacker gains amplification: a little of …pretnja · availability
-
№ 057
DNS Poisoning … a certificate warning in an attack like this is not something to click past.pretnja · availability
-
№ 035
Deepfake Attack This is not merely a technical curiosity. Deepfakes strengthen classic social engineering because they give the attacker what used to be largely out of reach: a …pretnja · social eng.
-
№ 050
Denial of Service / DoS … users can no longer use it. Unlike DDoS it need not come from a large network of compromised devices. Sometimes one source and a well-chosen vulnerability are …pretnja · availability
-
№ 048
Dependency Confusion … ization's internal package, or with the name of another public and valid package, counting on the fetching tool choosing their version over the real one.pretnja · applications
-
№ 049
Distributed Denial of Service / DDoS … requests until the server is blocked. The aim is not data theft but choking the service into unavailability.pretnja · availability
-
№ 068
Evil Twin … rly well, because people expect open networks in hotels, cafés, airports and conference halls.pretnja · physical / IoT
-
№ 011
Fileless malware … ayload through legitimate tools, its activity is not easy to tell apart from normal work.pretnja · malware
-
№ 012
Infostealer … s, attachments or malicious advertising. It does not linger; the aim is not to settle in but to grab and vanish, often within seconds. Stolen session tokens are …pretnja · malware
-
№ 046
Insecure Deserialization … ough it were safe. At that point the attacker is not sending mere data but a specially prepared structure that can change the flow of execution.pretnja · applications
-
№ 022
Kerberoasting … y (AD). User logins are handled by the Kerberos protocol, which issues tickets as proof of identity. In a domain environment there are non-user accounts — servi …pretnja · identity
-
№ 004
Keylogger … ords, payment card numbers, private messages, and other sensitive information. The attacker periodically retrieves the log or it is automatically sent to a remo …pretnja · malware
-
№ 005
Loader / Dropper … ted vulnerability. Because they are small and do nothing suspicious at first, they slip past protection more easily. Once settled they fetch what they were sent …pretnja · malware
-
№ 032
Malvertising … as a delivery channel for attacks. The user does not have to be on a dubious site; a malicious advert can appear on a legitimate portal too, because ad space of …pretnja · social eng.
-
№ 073
Model theft / extraction … rect theft resembles ordinary data theft: badly protected storage, a repository, a developer's laptop or a cloud bucket. Extraction is different. The attacker s …pretnja · AI / ML
-
№ 023
Pass-the-Hash So that it does not keep the password in readable form, Windows remembers its cryptographic fingerprint — the hash. With older Windows authentication (NTLM), th …pretnja · identity
-
№ 016
Password spraying … tried against hundreds of accounts before anyone notices anything.pretnja · identity
-
№ 047
Path Traversal The problem is not only the `../` characters. Paths can be encoded, normalized and bypassed in several ways if the application has no clearly bounded permission …pretnja · applications
-
№ 026
Phishing The strength of phishing is not in the technique but in the psychology. The message creates pressure — your account is suspended, the parcel could not be delive …pretnja · social eng.
-
№ 071
Physical Access Attack … ice into a port or carry a laptop away, digital protection no longer helps.pretnja · physical / IoT
-
№ 031
Pretexting … neering with a prepared story. The attacker does not simply send a link and wait for a click; they build a scenario in which what they are doing looks normal. T …pretnja · social eng.
-
№ 020
Privilege Escalation … tor, and horizontal, moving from one account to another user's resources at the same level of rights.pretnja · identity
-
№ 061
Privilege Misuse … ge escalation, the attacker or insider here does not have to acquire new authority. The trouble is that the existing authority is enough to do damage.pretnja · trust
-
№ 072
Prompt injection A chatbot connected to a database receives a request to ignore its previous rules and print another user's data.pretnja · AI / ML
-
№ 034
QR phishing - Quishing … en carries on working on the phone, outside the protections that exist on the computer. A QR code feels like a fast and modern way in, so it is less often taken …pretnja · social eng.
-
№ 055
Ransom DDoS … money for the attack to stop or for a larger one not to happen.pretnja · availability
-
№ 001
Ransomware … ies of the data and threatens to publish them if nothing is paid — double extortion. Some ransomware groups sell their whole operation to affiliates as a packag …pretnja · malware
-
№ 052
Resource Exhaustion Resource exhaustion targets what a system cannot work without: processor, memory, disk, network connections, threads, the database or processing queues. The aim …pretnja · availability
-
№ 025
SIM Swapping SIM swapping does not attack the phone but the phone number. The attacker persuades, or bribes, a mobile operator to move the number to a new SIM card, citing a …pretnja · identity
-
№ 030
SMS phishing - Smishing … e offers a simple reason to click: the parcel cannot be delivered, the account is blocked, a transaction looks suspicious, a package is waiting on a small charg …pretnja · social eng.
-
№ 039
SQL Injection … search or filter field. If the application does not stop it, the database can execute something the designer never had in mind, and certainly never intended.pretnja · applications
-
№ 045
SSRF … hoosing. The distinction matters: the request is not sent by the user's browser but by the server. That opens the door to internal services which from the outsi …pretnja · applications
-
№ 054
Service Abuse … a system in an unforeseen way. The attacker does not have to find a classic vulnerability. It is enough to work out how a normal function can be automated, over …pretnja · availability
-
№ 019
Session Hijacking … es and settings. The main benefit is that you do not have to type a password every few minutes as you move through the features. That session is marked by an id …pretnja · identity
-
№ 064
Shadow IT … or approval of the IT team. Employees usually do not bring them in to cause a problem but to get the work done faster: a file needs sharing, a team needs a chat …pretnja · trust
-
№ 062
Shared Account Abuse … which for accountability is the same as knowing nothing.pretnja · trust
-
№ 027
Spear Phishing … successful than the mass kind. The message does not smell of fraud: it refers to a real project, a real name, a real deadline. The attacker knows they do not h …pretnja · social eng.
-
№ 003
Spyware … through the microphone and camera. The point is not damage to the device but a record of the person, which can later be turned to any number of uses.pretnja · malware
-
№ 060
Supply Chain Attack A supply chain attack does not always aim at the final victim directly. The attacker compromises software, hardware, a supplier, a build process or an update me …pretnja · trust
-
№ 059
Third-Party Compromise … -party compromise happens when the attacker does not go at an organization directly but at a supplier, a partner, a service provider or an external associate wh …pretnja · trust
-
№ 018
Token Theft … omatically with every further request, so you do not have to type the password again. Token theft is the taking of that proof. With it in hand, the attacker pre …pretnja · identity
-
№ 002
Trojan A Trojan does not break in; the victim opens the door. It usually presents itself as something useful — a program or a document, a fake installer, a cracked app …pretnja · malware
-
№ 066
Typosquatting … ack because it uses speed and routine. People do not read every letter of a domain, and build systems do not consider a package's intent. One wrong character ca …pretnja · trust
-
№ 069
USB Drop Attack … ves a USB stick or device where an employee will notice it: a car park, a corridor, a reception desk, a meeting room, a bag of promotional material.pretnja · physical / IoT
-
№ 009
Virus A virus embeds itself in other executable files and runs together with them. It starts when the user launches the application or opens the infected file, and of …pretnja · malware
-
№ 036
Watering Hole Attack A watering hole attack does not chase the victim directly. The attacker first finds a site the target group visits regularly, then compromises that site or the …pretnja · social eng.
-
№ 033
Whaling … e who can approve large decisions. The target is not chosen by chance. The attacker knows who they are after and why that person is worth more than an ordinary …pretnja · social eng.
-
№ 008
Worm … carry extra cargo — ransomware, a backdoor, a remote access tool — so what begins on one machine soon floods the whole network. It can do damage with no cargo …pretnja · malware
-
№ 044
Zero-Day Exploitation … y for which the vendor has no patch yet, or does not know exists. The name says how much time the defense had to prepare: zero days. In practice a victim can be …pretnja · applications
-
№ 029
voice phishing - Vishing … ails or lead the victim into doing something they otherwise would not.pretnja · social eng.
Tehnike
31 direktan pogodak-
№ 017
Rootkit Installation Technique of installing a rootkit to deeply hide presence on a system.tehnika · execution
-
№ 034
Data Destruction Used for sabotage, evidence destruction, or geopolitically motivated attacks.tehnika · exfiltration / impact
-
№ 041
Fast-Flux DNS Rapid rotation of IP addresses associated with a C2 domain.tehnika · C2
-
№ 020
Access Token Manipulation Intercepting a session cookie on an unprotected wireless networktehnika · privileges
-
№ 004
Brute Force … for cracking user account passwords, decrypting protected files, and breaking encrypted communications. Effectiveness depends on the attacker's computational re …tehnika · initial access
-
№ 024
Cloud lateral movement … entities can assume roles — temporarily take on another identity's rights. It's built for legitimate delegation, but it becomes lateral movement when an attacke …tehnika · privileges
-
№ 039
Command & Control … resemble normal network traffic, using standard protocols, encryption, and legitimate services as intermediaries.tehnika · C2
-
№ 023
Container Escape … to isolate an application from the host and from other containers. Container escape is when an attacker controlling a process inside a container breaks that is …tehnika · privileges
-
№ 003
Credential Abuse … redential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a …tehnika · initial access
-
№ 036
DNS Tunneling Can be used for both exfiltration and C2.tehnika · exfiltration / impact
-
№ 029
Domain Account Discovery Does not require privileged access — any domain user can enumerate AD.tehnika · discovery
-
№ 037
Double Extortion If the victim does not pay, public data release is threatened.tehnika · exfiltration / impact
-
№ 042
Encrypted C2 Channels Using HTTPS, DNS-over-HTTPS, or other encrypted protocols for C2.tehnika · C2
-
№ 010
Exploitation Exploiting a network protocol vulnerability for remote code executiontehnika · execution
-
№ 022
Forge Kerberos Tickets A set of techniques exploiting the Kerberos protocol in Active Directory.tehnika · privileges
-
№ 046
Indicator Removal … la term covering log-tampering, timestomping, and other trace removal techniques.tehnika · evasion
-
№ 019
Lateral Movement … attacker moving from one compromised system to another within the same network. The goal is to expand access to systems containing more valuable data or enabli …tehnika · privileges
-
№ 015
Living off the Land … erShell, certutil, mshta, regsvr32, rundll32, and other Windows tools.tehnika · execution
-
№ 043
Log Tampering Detection requires centralized logging on a protected server.tehnika · evasion
-
№ 038
Malware Delivery … ed approach combining email filtering, endpoint protection, and media control is most effective.tehnika · C2
-
№ 021
Pass-the-Hash Differs from kerberos-attacks in the targeted protocol.tehnika · privileges
-
№ 011
Persistence … heir access or malicious code survives system reboots, password changes, or other interruptions. The goal is to maintain a foothold in the environment over an e …tehnika · execution
-
№ 001
Phishing The technique is used for both mass campaigns and highly personalized attacks. Successful phishing typically serves as the entry point for further escalation wi …tehnika · initial access
-
№ 008
Physical Access Includes USB devices, external media boot, or direct network connection.tehnika · initial access
-
№ 018
Privilege Escalation … ical escalation means reaching administrator or root level, while horizontal escalation means accessing another user's resources at the same privilege level.tehnika · privileges
-
№ 025
Reconnaissance … ing of information about the target environment, both externally before the attack and internally after compromise. The goal is to understand the topology, iden …tehnika · discovery
-
№ 032
Resource Exhaustion … s and rate limiting provides the most effective protection.tehnika · exfiltration / impact
-
№ 033
Service Abuse … ke vulnerability exploitation, the attacker does not use code flaws but abuses the normal behavior of services. This makes detection difficult because the activ …tehnika · exfiltration / impact
-
№ 006
Supply Chain Compromise Covers both dependency confusion and trojanized updates.tehnika · initial access
-
№ 005
Watering Hole Technique (how it is done), not threat (what happens).tehnika · initial access
-
№ 035
Website Defacement Motivation can be political, revenge, or capability demonstration.tehnika · exfiltration / impact
Odbrane
35 direktnih pogodaka-
№ 028
DDoS Protection DDoS protection encompasses technologies and services that detect and mitigate distributed denial-of-service attacks before malicious traffic reaches or overwhe …odbrana · resilience
-
№ 001
Endpoint Protection Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It c …odbrana · endpoints
-
№ 024
Backup & Recovery … lly separated from the production network. This protects against ransomware that attempts to encrypt backup copies as well.odbrana · resilience
-
№ 034
DLP … nsitive. Without a clear picture of what you're protecting and where it lives, DLP either blocks everything (and people route around it) or blocks nothing.odbrana · resilience
-
№ 030
Data Encryption Protecting data by encrypting it at rest and in transit.odbrana · resilience
-
№ 031
Deception Technology Deploying decoy resources (honeypots, honeytokens) to detect attackers.odbrana · resilience
-
№ 036
Virtual Private Network … n organization this primarily means controlled remote access to internal resources — from home, on the road, in the field. Traffic inside the tunnel cannot be r …odbrana · resilience
-
№ 006
Browser Isolation Can be remote (cloud), local (VM), or client-side isolation.odbrana · endpoints
-
№ 033
CSPM … gap between 'we changed something' and 'someone noticed it's dangerous'.odbrana · resilience
-
№ 029
DNS Security DNS security encompasses technologies that protect DNS infrastructure and use DNS traffic as a control point for blocking access to malicious domains and detect …odbrana · resilience
-
№ 040
DevSecOps … roach: vulnerabilities are found in development, not production.odbrana · people
-
№ 003
EDR Unlike traditional endpoint protection that focuses on prevention, EDR emphasizes visibility and response capability. It records detailed telemetry about proces …odbrana · endpoints
-
№ 035
Firewall … ciding who may talk to whom, on which ports and protocols.odbrana · resilience
-
№ 022
IDS/IPS … re false positives). Serious deployments combine both.odbrana · monitoring / response
-
№ 009
Identity & Access Management Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.odbrana · identity / access
-
№ 020
Incident Response A planned process of identifying, containing, eradicating, and recovering from cyber incidents.odbrana · monitoring / response
-
№ 016
Logging & Monitoring This technology is the foundation for all other detective controls. Without adequate logging, it is impossible to determine what happened during an incident, wh …odbrana · monitoring / response
-
№ 032
Microsegmentation … twork division at workload or application level, not just VLANs.odbrana · resilience
-
№ 005
Mobile Device Security Managing and protecting mobile devices through MDM and MAM solutions.odbrana · endpoints
-
№ 008
Multi-Factor Authentication Different factors provide different levels of protection. Hardware keys and on-device authenticators are more phishing-resistant than SMS codes, but any form of …odbrana · identity / access
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is to limit an attacker's ability to move through the network after compromising a single system.odbrana · resilience
-
№ 012
Password Manager Tool for generating, storing, and auto-filling strong, unique passwords.odbrana · identity / access
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience
-
№ 038
Phishing Simulations Regular testing of employees with simulated phishing messages.odbrana · people
-
№ 010
Privileged Access Management … s administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical …odbrana · identity / access
-
№ 043
Regulatory Compliance Compliance is not the same as security — it is possible to be compliant but insecure.odbrana · governance
-
№ 041
Risk Assessment … ication of assets, threats, vulnerabilities, and potential impact.odbrana · governance
-
№ 015
SIEM SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.odbrana · monitoring / response
-
№ 007
SPF/DKIM/DMARC … nd reports showing who sends in your name. This protects your domain's reputation with others and reduces spoofed internal mail.odbrana · endpoints
-
№ 014
Secrets Management … at message. Secrets management means a central, protected store (a vault) from which an application fetches a secret exactly when it needs it, instead of carryi …odbrana · identity / access
-
№ 037
Security Awareness Employee education programs about cyber threats and safe behavior.odbrana · people
-
№ 044
Vulnerability Management Continuous process of discovering, classifying, prioritizing, and remediating vulnerabilities.odbrana · governance
-
№ 027
WAF WAF protects against common web application attacks such as SQL injection, cross-site scripting, request forgery, and other application-layer attacks. It can op …odbrana · resilience
-
№ 004
XDR XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.odbrana · endpoints
-
№ 011
Zero Trust … and context-based access policies. Zero Trust is not a product but an architectural approach.odbrana · identity / access