Pretnje
15 direktnih pogodaka-
№ 034
QR phishing - Quishing Quishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake pa …pretnja · social eng.
-
№ 026
Phishing Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a messa …pretnja · social eng.
-
№ 030
SMS phishing - Smishing Smishing is phishing over SMS or messaging apps. The attacker sends a short message with a link, a request to confirm something, or an instruction for an urgent …pretnja · social eng.
-
№ 027
Spear Phishing Spear phishing is phishing cut to fit one person or a small group of users. Instead of sending the same message to thousands of addresses, the attacker first ga …pretnja · social eng.
-
№ 029
voice phishing - Vishing Vishing is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present t …pretnja · social eng.
-
№ 066
Typosquatting … imilar domains around a brand and uses them for a phishing campaign.pretnja · trust
-
№ 033
Whaling Whaling is targeted phishing aimed at senior management, owners, directors and people who can approve large decisions. The target is not chosen by chance. The a …pretnja · social eng.
-
№ 021
Account Takeover … t is usually the destination of what came before: phishing, credential stuffing, token theft.pretnja · identity
-
№ 053
Botnet Attacks A botnet is used for DDoS, sending spam, phishing campaigns, password spraying, cryptocurrency mining, malware distribution and other work that needs quantity. …pretnja · availability
-
№ 024
MFA Fatigue … generated number to be entered. Safer still is a phishing-resistant factor (FIDO2, passkeys, hardware keys). Alongside that, consecutive requests should be lim …pretnja · identity
-
№ 031
Pretexting Unlike mass phishing, pretexting requires thorough preparation. The attacker uses publicly available information, LinkedIn, the company website, job adverts, ol …pretnja · social eng.
-
№ 025
SIM Swapping … d with personal details from leaked databases and phishing. The moment the number moves to their card, the real phone loses signal and every call and message go …pretnja · identity
-
№ 018
Token Theft … from application memory. Adversary-in-the-middle phishing, where a fake page forwards your login to the real service in real time, catches the token at the mom …pretnja · identity
-
№ 036
Watering Hole Attack The difference from phishing is that the victim does not have to be lured. They come on their own, suspecting nothing.pretnja · social eng.
-
№ 007
Wiper It arrives by the usual routes — phishing, a compromised account, an exploited vulnerability — and sometimes pretends to be ransomware, to buy time and do more …pretnja · malware
Tehnike
4 direktna pogotka-
№ 001
Phishing Phishing as a technique involves sending fraudulent emails, SMS messages, or chat messages to trick the victim into clicking a malicious link, opening an infect …tehnika · initial access
-
№ 009
AiTM … ts between the user and the real service. Classic phishing steals a password; AiTM steals the live session. The victim gets a link, lands on a proxy that looks …tehnika · initial access
-
№ 041
Fast-Flux DNS Used for botnet infrastructure and phishing campaigns.tehnika · C2
-
№ 030
OSINT Foundation for targeted attacks like spear-phishing and watering hole.tehnika · discovery
Odbrane
13 direktnih pogodaka-
№ 038
Phishing Simulations Regular testing of employees with simulated phishing messages.odbrana · people
-
№ 037
Security Awareness Cover phishing recognition, password management, and incident reporting.odbrana · people
-
№ 006
Browser Isolation Executing web content in an isolated environment separate from the local system.odbrana · endpoints
-
№ 029
DNS Security … ring can block access to known malicious domains, phishing sites, and command-and-control servers before a connection is established. DNS traffic analysis can r …odbrana · resilience
-
№ 002
Email Security … t filter inbound and outbound messages to prevent phishing, malware delivery, and business email compromise. It operates at the server or cloud level before the …odbrana · endpoints
-
№ 035
Firewall A firewall is a control placed at the boundary between networks that permits or blocks traffic according to predefined rules — deciding who may talk to whom, on which ports and protocols.odbrana · resilience
-
№ 005
Mobile Device Security Protects against mobile phishing, malware, and device theft.odbrana · endpoints
-
№ 008
Multi-Factor Authentication … rdware keys and on-device authenticators are more phishing-resistant than SMS codes, but any form of MFA is significantly better than a password alone.odbrana · identity / access
-
№ 012
Password Manager Reduces phishing risk because autofill only works on legitimate domains.odbrana · identity / access
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience
-
№ 010
Privileged Access Management Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.odbrana · identity / access
-
№ 007
SPF/DKIM/DMARC By default, anyone can put your domain in the sender field — that's how spoofed mail 'from the director' works. SPF, DKIM, and DMARC are three records you publish for your domain that let a recipient check whether mail claiming to be from you actually came from your systems. SPF says which servers may send for you, DKIM signs the message, and DMARC tells the recipient what to do with mail that fails the check and sends you reports.odbrana · endpoints
-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.odbrana · resilience