166 terms ·
75/46/45
93 rezultata za „physical" ·
11 direktnih ·
82 povezanih
Pretnje
4 direktna pogotka-
№ 071
Physical Access Attack Physical access is the oldest form of compromise: the attacker reaches the device, the room, a port, a cable or a piece of paper. Once somebody can sit down at …pretnja · physical / IoT
-
№ 070
SCADA/OT Attack An attack on SCADA and OT systems targets industrial processes, not only data. These are the systems that run manufacturing, energy, water, transport, buildings, sensors, PLC controllers and HMI stations. When such a system stops or starts working wrongly, the consequences can be fatal.pretnja · physical / IoT
-
№ 069
USB Drop Attack A USB drop attack uses human curiosity and the habit of plugging an unknown device into a computer to see what is on it. The attacker leaves a USB stick or device where an employee will notice it: a car park, a corridor, a reception desk, a meeting room, a bag of promotional material.pretnja · physical / IoT
-
№ 004
Keylogger … in the background, while hardware variants can be physically attached between the keyboard and the computer.pretnja · malware
Tehnike
3 direktna pogotka-
№ 008
Physical Access Using physical access to a device or space as an attack vector.tehnika · initial access
-
№ 031
Data Exfiltration … annels, legitimate cloud services, email, or even physical media.tehnika · exfiltration / impact
-
№ 002
Social Engineering Impersonating a new employee to gain physical access to premisestehnika · initial access
Odbrane
4 direktna pogotka-
№ 024
Backup & Recovery … fferent locations, including at least one that is physically or logically separated from the production network. This protects against ransomware that attempts …odbrana · resilience
-
№ 017
MDR MDR (Managed Detection and Response) is a service where an external security team provides continuous monitoring, threat detection, and incident response on behalf of an organization. It combines technology with human expertise.odbrana · monitoring / response
-
№ 005
Mobile Device Security Managing and protecting mobile devices through MDM and MAM solutions.odbrana · endpoints
-
№ 045
Penetration Testing … etwork, web applications, social engineering, and physical access.odbrana · governance
↳ Povezano
82 stavke koje koriste „physical"-
№ 042
API Abuse API abuse arises when an attacker uses a programming interface in a way the application did not anticipate or did not restrict enough. An API is not merely a technical add-on to the application. It is often the main entrance to the data, the users, the orders, the payments and the administration.pretnja · applications
-
№ 065
Accidental Data Leak An accidental data leak is not an attack in the classic sense, but the consequences can look the same. Data becomes available to the wrong people through human error, bad configuration, wrong sharing, a public repository, open cloud storage, or mail sent to the wrong address.pretnja · trust
-
№ 021
Account Takeover Account takeover is the moment the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail address, the phone number and the second factor, while the real owner is shut out with no technical way back in on their own. Takeover is rarely the first stage of an attack. It is usually the destination of what came before: phishing, credential stuffing, token theft.pretnja · identity
-
№ 043
Authentication Bypass An authentication bypass means the attacker reaches a protected part of the system without logging in the ordinary way. They need not know a password. Sometimes a flaw in the logic is enough, or an unprotected endpoint, a predictable token, a misconfigured proxy, or a gap between two steps of the login.pretnja · applications
-
№ 056
BGP Hijacking BGP hijacking is an attack, or a serious mistake, in which internet traffic is diverted by wrong routing. BGP is the protocol by which autonomous systems on the internet tell each other which path leads to particular IP ranges. If somebody announces another party's range as their own, part of the internet can believe them.pretnja · availability
-
№ 006
Backdoor A backdoor is a hidden way in. Once placed or opened, it lets the attacker return to the machine — with no password, no authorization and no entry in the ordinary records. A backdoor can be opened by malware while it runs, but it can equally be a user account nobody watches, or web shell access left on a server.pretnja · malware
-
№ 028
Business Email Compromise Business email compromise is not an ordinary fake email. The attacker breaks into business correspondence, or imitates it well enough that somebody in the company believes the request comes from the director, from finance, from a supplier, a lawyer or a partner. The aim is usually money, but it can also be a confidential document, a change of payment details, or an opening for the next phase of the attack.pretnja · social eng.
-
№ 074
Cloud storage exposure Cloud storage exposure arises when data that ought to be private becomes publicly reachable through a bad configuration of a cloud service. That can be S3 buckets, blob storage, backups, logs, documents, images, database exports or configuration files.pretnja · cloud
-
№ 039
Command & Control Command and control communication involves establishing a persistent channel between the attacker and the compromised system for sending commands and receiving results. The attacker uses this channel to manage malware, launch new attack phases, and retrieve data.tehnika · C2
-
№ 063
Contractor Abuse Contractor access abuse arises when a consultant, a contractor, an external firm or a temporarily engaged person uses access more widely or for longer than the work requires. The access is often granted legitimately, but afterwards it is not monitored, not narrowed and not withdrawn in time.pretnja · trust
-
№ 003
Credential Abuse Credential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate user.tehnika · initial access
-
№ 040
Cross-Site Scripting Cross-site scripting, better known as XSS, arises when a web application allows somebody else's script to be displayed and executed in the user's browser. The attacker does not have to break into the web server. It is enough for their code to end up in a page the victim opens as though it were entirely legitimate.pretnja · applications
-
№ 037
Crypto-wallet drainer A crypto wallet works by signing transactions that move crypto assets. Draining a wallet is the process in which the user, believing they are doing something legitimate, signs a transaction or an approval that hands the attacker control of those assets.pretnja · social eng.
-
№ 034
DLP DLP watches where sensitive data goes and stops it where it shouldn't: an employee attaching a client list to a private email, copying a file with personal data to a USB, or pasting a database into a chat. It works by recognizing patterns (national IDs, card numbers, marked documents) and applying rules per channel — mail, web, endpoint, cloud.odbrana · resilience
-
№ 029
DNS Security DNS security encompasses technologies that protect DNS infrastructure and use DNS traffic as a control point for blocking access to malicious domains and detecting suspicious communications.odbrana · resilience
-
№ 034
Data Destruction Technique of permanently deleting or corrupting data on a compromised system.tehnika · exfiltration / impact
-
№ 030
Data Encryption Protecting data by encrypting it at rest and in transit.odbrana · resilience
-
№ 035
Deepfake Attack A deepfake attack uses an artificially generated voice, image or video so that somebody can pose as a real person. In cyber attacks this usually means the director's voice on a call, a colleague's face in a video meeting, or a recording that feels real enough for the victim to accept the request.pretnja · social eng.
-
№ 037
Double Extortion Technique where data is first exfiltrated, then encrypted for ransom.tehnika · exfiltration / impact
-
№ 003
EDR EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.odbrana · endpoints
-
№ 002
Email Security Email security encompasses technologies that filter inbound and outbound messages to prevent phishing, malware delivery, and business email compromise. It operates at the server or cloud level before the message reaches the user.odbrana · endpoints
-
№ 001
Endpoint Protection Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 068
Evil Twin A fake Wi-Fi network, known as an evil twin, imitates a legitimate wireless network so that users connect to an access point the attacker controls. The network name looks familiar, the signal can be stronger, and the device often suggests or restores the connection by itself.pretnja · physical / IoT
-
№ 010
Exploitation Exploitation involves leveraging a flaw in software, hardware, or configuration to execute unauthorized code or bypass security controls. Vulnerabilities can exist in operating systems, applications, network services, or firmware.tehnika · execution
-
№ 011
Fileless malware Fileless malware never writes itself to disk during the attack, so antivirus software has a harder time finding it. While it operates it lives in memory and works with tools the system already has — PowerShell, scripts, built-in commands. Because it delivers its payload through legitimate tools, its activity is not easy to tell apart from normal work.pretnja · malware
-
№ 035
Firewall A firewall is a control placed at the boundary between networks that permits or blocks traffic according to predefined rules — deciding who may talk to whom, on which ports and protocols.odbrana · resilience
-
№ 022
IDS/IPS IDS/IPS are systems that monitor network traffic (or host activity) for patterns indicating an attack. An IDS (Intrusion Detection System) only reports suspicious activity; an IPS (Intrusion Prevention System) sits inline and can block it immediately.odbrana · monitoring / response
-
№ 009
Identity & Access Management Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.odbrana · identity / access
-
№ 012
Impair Defenses Defense evasion encompasses techniques by which an attacker conceals their activity from security tools, analysts, and automated detection systems. The goal is to remain undetected for as long as possible in the compromised environment.tehnika · execution
-
№ 014
In-Memory Execution Executing malicious code in memory without writing files to disk.tehnika · execution
-
№ 020
Incident Response A planned process of identifying, containing, eradicating, and recovering from cyber incidents.odbrana · monitoring / response
-
№ 012
Infostealer An infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.pretnja · malware
-
№ 058
Insider Threat An insider threat comes from a person who has, or once had, legitimate access to an organization's systems, data or premises. That can be an employee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized to begin with.pretnja · trust
-
№ 019
Lateral Movement Lateral movement involves an attacker moving from one compromised system to another within the same network. The goal is to expand access to systems containing more valuable data or enabling further escalation.tehnika · privileges
-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.odbrana · monitoring / response
-
№ 024
MFA Fatigue MFA fatigue is social-engineering pressure applied to two-factor authentication. The attacker has the password, leaked or phished, but is stopped at the second factor — a confirmation the user has to approve on their phone. So the attacker starts the login over and over, burying the phone in approval requests. The arithmetic is simple: out of irritation, confusion, or the thought that it must be some glitch, the user approves one at some point — and the attacker is through the whole authentication.pretnja · identity
-
№ 038
Malware Delivery Malware delivery encompasses the methods by which malicious software is transferred to a target system. This includes infected attachments, compromised websites, malicious ads, removable media, and compromised software updates.tehnika · C2
-
№ 073
Model theft / extraction Model theft and extraction means an attacker obtains a model an organization trained, bought or adapted to its own needs. That can be direct theft of the files, the weights and the configuration, but also controlled extraction through an API, where the model is queried enough times to build an approximate copy.pretnja · AI / ML
-
№ 008
Multi-Factor Authentication Multi-factor authentication requires two or more independent proofs of identity at login. It typically combines something the user knows (password), something they possess (phone, hardware key), and something they are (biometrics).odbrana · identity / access
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is to limit an attacker's ability to move through the network after compromising a single system.odbrana · resilience
-
№ 012
Password Manager Tool for generating, storing, and auto-filling strong, unique passwords.odbrana · identity / access
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience
-
№ 047
Path Traversal Path traversal is an attack in which the attacker tries to step out of the permitted directory and reach files the application should never display. The best-known pattern is a sequence such as `../`, which walks the path back up the file system level by level.pretnja · applications
-
№ 011
Persistence Persistence encompasses techniques by which an attacker ensures their access or malicious code survives system reboots, password changes, or other interruptions. The goal is to maintain a foothold in the environment over an extended period.tehnika · execution
-
№ 001
Phishing Phishing as a technique involves sending fraudulent emails, SMS messages, or chat messages to trick the victim into clicking a malicious link, opening an infected attachment, or entering credentials on a fake page.tehnika · initial access
-
№ 026
Phishing Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a message that appears to come from a known organization — a bank, a courier, a government service, a colleague — and leads the victim into doing one of three things: clicking a link, opening an attachment, or entering their credentials somewhere.pretnja · social eng.
-
№ 038
Phishing Simulations Regular testing of employees with simulated phishing messages.odbrana · people
-
№ 031
Pretexting Pretexting is social engineering with a prepared story. The attacker does not simply send a link and wait for a click; they build a scenario in which what they are doing looks normal. They present themselves as a colleague, technical support, an auditor, a bank, a supplier, a courier or an official.pretnja · social eng.
-
№ 018
Privilege Escalation Privilege escalation is a technique by which an attacker with limited access gains a higher level of authorization. Vertical escalation means reaching administrator or root level, while horizontal escalation means accessing another user's resources at the same privilege level.tehnika · privileges
-
№ 061
Privilege Misuse Privilege misuse arises when somebody uses rights they genuinely hold for actions they have no business reason to take. Unlike privilege escalation, the attacker or insider here does not have to acquire new authority. The trouble is that the existing authority is enough to do damage.pretnja · trust
-
№ 045
Process Injection Injecting malicious code into the address space of a legitimate process.tehnika · evasion
-
№ 072
Prompt injection Prompt injection exploits the weakness of language models in telling an instruction apart from the content they are processing. When a model reads an email, a document, a page, a ticket or a message, the attacker can put text into that content which reads like an instruction.pretnja · AI / ML
-
№ 034
QR phishing - Quishing Quishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake page for a login, a payment, a document download or an account confirmation.pretnja · social eng.
-
№ 001
Ransomware Ransomware locks a company's data and demands payment to release it. The ransom is asked in cryptocurrency because it makes the money harder to follow — which is exactly why attackers use it.pretnja · malware
-
№ 025
Reconnaissance Reconnaissance involves the systematic gathering of information about the target environment, both externally before the attack and internally after compromise. The goal is to understand the topology, identify targets, and plan the next stages.tehnika · discovery
-
№ 043
Regulatory Compliance Meeting requirements of regulatory frameworks and standards for cybersecurity.odbrana · governance
-
№ 038
Remote Code Execution Remote code execution is one of the most dangerous classes of vulnerability, because it lets an attacker run their own code on a vulnerable system from somewhere else entirely. If the application runs on a server, the attacker is no longer merely a user on the outside; they gain a way to influence what the server executes.pretnja · applications
-
№ 014
Remote access trojan - RAT A RAT gives the attacker remote control of your machine. Once inside they can browse files, switch on the camera and microphone, record what you type and run commands — all of it live, as if sitting in front of your screen. It resembles remote support tools, only on the wrong side of the law.pretnja · malware
-
№ 010
Rootkit A rootkit is hard to see, and that is its most important property. It can settle beneath the operating system and beneath the layer where antivirus software can look: sometimes in drivers or in the kernel, out of reach of protective mechanisms, sometimes in the boot phase, even in the motherboard firmware. From there it hides itself and everything else the attacker does, so an infected system looks perfectly clean.pretnja · malware
-
№ 015
SIEM SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.odbrana · monitoring / response
-
№ 025
SIM Swapping SIM swapping does not attack the phone but the phone number. The attacker persuades, or bribes, a mobile operator to move the number to a new SIM card, citing a lost phone or a damaged card. They usually come armed with personal details from leaked databases and phishing. The moment the number moves to their card, the real phone loses signal and every call and message goes to the attacker.pretnja · identity
-
№ 030
SMS phishing - Smishing Smishing is phishing over SMS or messaging apps. The attacker sends a short message with a link, a request to confirm something, or an instruction for an urgent action, counting on messages being read quickly on a phone and without much checking.pretnja · social eng.
-
№ 018
SOAR Security Orchestration, Automation and Response — automating security operations.odbrana · monitoring / response
-
№ 007
SPF/DKIM/DMARC By default, anyone can put your domain in the sender field — that's how spoofed mail 'from the director' works. SPF, DKIM, and DMARC are three records you publish for your domain that let a recipient check whether mail claiming to be from you actually came from your systems. SPF says which servers may send for you, DKIM signs the message, and DMARC tells the recipient what to do with mail that fails the check and sends you reports.odbrana · endpoints
-
№ 039
SQL Injection SQL injection usually arises when a web application passes user input blindly to the database on the web server. Instead of ordinary text, the attacker can put part of an SQL command into a login, search or filter field. If the application does not stop it, the database can execute something the designer never had in mind, and certainly never intended.pretnja · applications
-
№ 045
SSRF SSRF is a vulnerability in which the attacker gets a web server to send a request to an address of the attacker's choosing. The distinction matters: the request is not sent by the user's browser but by the server. That opens the door to internal services which from the outside ought to remain invisible.pretnja · applications
-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.odbrana · resilience
-
№ 037
Security Awareness Employee education programs about cyber threats and safe behavior.odbrana · people
-
№ 039
Security Champions An ambassador program for security within development and business teams.odbrana · people
-
№ 042
Security Policies Formal documents defining an organization's cybersecurity rules and standards.odbrana · governance
-
№ 064
Shadow IT Shadow IT is the use of applications, cloud services, accounts and tools without the knowledge or approval of the IT team. Employees usually do not bring them in to cause a problem but to get the work done faster: a file needs sharing, a team needs a chat, marketing needs a tool, sales needs a PDF now.pretnja · trust
-
№ 027
Spear Phishing Spear phishing is phishing cut to fit one person or a small group of users. Instead of sending the same message to thousands of addresses, the attacker first gathers information about the victim — where they work, who they work with, what they are working on right now, how the company addresses its clients — and then writes a message that reads as if it came from that world.pretnja · social eng.
-
№ 003
Spyware Spyware watches the user and what they do. Hidden, it can spend months collecting what you type, what is on your screen, where you are, who calls you, and what you say through the microphone and camera. The point is not damage to the device but a record of the person, which can later be turned to any number of uses.pretnja · malware
-
№ 060
Supply Chain Attack A supply chain attack does not always aim at the final victim directly. The attacker compromises software, hardware, a supplier, a build process or an update mechanism before the product or service reaches the user. The victim then carries the problem into their own environment, because it comes from a source they trust.pretnja · trust
-
№ 059
Third-Party Compromise Third-party compromise happens when the attacker does not go at an organization directly but at a supplier, a partner, a service provider or an external associate who already holds some form of trust and authorized access. Instead of forcing the front door, the attacker looks for a side entrance somebody else has already opened.pretnja · trust
-
№ 018
Token Theft A token is proof that you have already logged in. When you sign in and confirm your identity with a second factor, the service issues a token, stored in the browser, which vouches that you have already been checked the next time round. The token is sent automatically with every further request, so you do not have to type the password again. Token theft is the taking of that proof. With it in hand, the attacker presents themselves as you — without your password and without the second factor, because both have already been approved.pretnja · identity
-
№ 066
Typosquatting Typosquatting exploits small mistakes in typing, reading or recognizing a name. The attacker registers a domain, an account or a software package that resembles a legitimate name, counting on a user, a developer or a system to miss one letter, swap a character or overlook the difference.pretnja · trust
-
№ 033
Whaling Whaling is targeted phishing aimed at senior management, owners, directors and people who can approve large decisions. The target is not chosen by chance. The attacker knows who they are after and why that person is worth more than an ordinary account.pretnja · social eng.
-
№ 007
Wiper A wiper does not exist to steal or to extort — a wiper destroys data. It erases and overwrites, breaks file systems, and combined with worms and zero-day vulnerabilities it can bring down hundreds or thousands of networks within hours. Unlike ransomware it offers no ransom; recovery was never part of the plan, because the aim is damage, not money.pretnja · malware
-
№ 004
XDR XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.odbrana · endpoints
-
№ 044
Zero-Day Exploitation Zero-day exploitation uses a vulnerability for which the vendor has no patch yet, or does not know exists. The name says how much time the defense had to prepare: zero days. In practice a victim can be doing everything right, keeping systems and applications up to date, and still be exposed.pretnja · applications
-
№ 029
voice phishing - Vishing Vishing is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present themselves as a bank, technical support, a courier, the police, the tax office, or somebody from the company, while trying to extract details or lead the victim into doing something they otherwise would not.pretnja · social eng.