Pretnje
54 direktna pogotka-
№ 075
Cloud IAM misconfiguration Cloud IAM misconfiguration means a user, a service account, an application or a role holds more rights than it needs. In the cloud an identity is not merely a l …pretnja · cloud
-
№ 014
Remote access trojan - RAT A RAT gives the attacker remote control of your machine. Once inside they can browse files, switch on the camera and microphone, record what you type and run co …pretnja · malware
-
№ 065
Accidental Data Leak … the wrong people through human error, bad configuration, wrong sharing, a public repository, open cloud storage, or mail sent to the wrong address.pretnja · trust
-
№ 043
Authentication Bypass … uence can be access to a user account, to administration, to internal data, or to a function that changes the state of the system. Authentication therefore has …pretnja · applications
-
№ 074
Cloud storage exposure … e becomes publicly reachable through a bad configuration of a cloud service. That can be S3 buckets, blob storage, backups, logs, documents, images, database ex …pretnja · cloud
-
№ 064
Shadow IT Shadow IT is often a symptom rather than merely a breach. If the official tools do not do the job, employees find their own. But the consequence stays the same: …pretnja · trust
-
№ 062
Shared Account Abuse The whole IT team uses the same administrator account to manage the servers.pretnja · trust
-
№ 003
Spyware … pponents, but the same mechanism shows up in corporate espionage and in domestic abuse.pretnja · malware
-
№ 036
Watering Hole Attack A watering hole attack does not chase the victim directly. The attacker first finds a site the target group visits regularly, then compromises that site or the content loaded through it. The victim then comes to the place of the attack on their own, doing what they normally do.pretnja · social eng.
-
№ 042
API Abuse … e users, the orders, the payments and the administration.pretnja · applications
-
№ 021
Account Takeover … ally follows is a new account and building from scratch, which is particularly painful for business accounts.pretnja · identity
-
№ 056
BGP Hijacking … mes it is a provider's mistake, sometimes a deliberate attack. The user usually does not see that the path changed, only that the service does not work or that …pretnja · availability
-
№ 006
Backdoor … t behind by employees or service providers, deliberately or by accident. Sometimes it surfaces as a software or hardware vulnerability. It always serves the sam …pretnja · malware
-
№ 053
Botnet Attacks A network of compromised cameras and routers generates large DDoS traffic at a public service.pretnja · availability
-
№ 015
Brute-force attack … tool hits a live login, where account lockout and rate limits slow it down. Offline, the attacker works on their own hardware against a stolen database of passw …pretnja · identity
-
№ 063
Contractor Abuse The risk is not only deliberate theft. A private laptop with no protection is enough, or keeping data for the next project, or sharing an account inside the sup …pretnja · trust
-
№ 041
Cross-Site Request Forgery The user is logged into an administrative panel and then opens another page that automatically sends a request to change a setting.pretnja · applications
-
№ 013
Cryptominer A cryptominer steals capacity rather than data — which is why it goes unnoticed for longer.pretnja · malware
-
№ 051
DNS Amplification … ternet with no need to is not merely a bad configuration but part of somebody else's problem.pretnja · availability
-
№ 035
Deepfake Attack A deepfake attack uses an artificially generated voice, image or video so that somebody can pose as a real person. In cyber attacks this usually means the direc …pretnja · social eng.
-
№ 050
Denial of Service / DoS … aw in the application, the protocol or the configuration. A small number of specially shaped requests can consume a great deal of memory, hold connections open, …pretnja · availability
-
№ 048
Dependency Confusion … public repository, and becomes a target for registration on a public package registry.pretnja · applications
-
№ 049
Distributed Denial of Service / DDoS … s capacity arranged in advance, scrubbing, a CDN, rate limiting and a clear line to the provider.pretnja · availability
-
№ 011
Fileless malware … oftware has a harder time finding it. While it operates it lives in memory and works with tools the system already has — PowerShell, scripts, built-in commands. …pretnja · malware
-
№ 012
Infostealer … roblems: account takeover, a break-in to the corporate network, ransomware. A large share of breaches begins with credentials some stealer gathered months earli …pretnja · malware
-
№ 058
Insider Threat … can be an employee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized …pretnja · trust
-
№ 022
Kerberoasting … tack starts from any user account at all. Administrator rights are not needed. The attacker requests a ticket for a service account, carries it to their own mac …pretnja · identity
-
№ 024
MFA Fatigue … rove/Deny with a confirmation that requires a generated number to be entered. Safer still is a phishing-resistant factor (FIDO2, passkeys, hardware keys). Along …pretnja · identity
-
№ 073
Model theft / extraction … ct theft of the files, the weights and the configuration, but also controlled extraction through an API, where the model is queried enough times to build an app …pretnja · AI / ML
-
№ 023
Pass-the-Hash To get the hash the attacker needs administrator or SYSTEM rights and a tool such as Mimikatz. Once they have it, they can try logging in to the other machines …pretnja · identity
-
№ 047
Path Traversal … a file path, the attacker can try to read configurations, passwords, source code and system files.pretnja · applications
-
№ 031
Pretexting … mass phishing, pretexting requires thorough preparation. The attacker uses publicly available information, LinkedIn, the company website, job adverts, old emai …pretnja · social eng.
-
№ 020
Privilege Escalation … calation, from an ordinary user to domain administrator, and horizontal, moving from one account to another user's resources at the same level of rights.pretnja · identity
-
№ 061
Privilege Misuse An administrator can read data they should not read, a finance user can start a transaction in their own favor, and technical staff can reach private mail, reco …pretnja · trust
-
№ 072
Prompt injection … he attack is no longer a game with text but an operational incident.pretnja · AI / ML
-
№ 055
Ransom DDoS … ing the service down, or first run a short demonstration attack, and then ask for money for the attack to stop or for a larger one not to happen.pretnja · availability
-
№ 001
Ransomware … rtion. Some ransomware groups sell their whole operation to affiliates as a package (ransomware as a service), so attacks are now run by people with no particul …pretnja · malware
-
№ 038
Remote Code Execution It is reached through configuration mistakes, vulnerable libraries, insecure deserialization, file upload, document parsers, memory handling or wrongly exposed …pretnja · applications
-
№ 052
Resource Exhaustion … arch, a badly written regular expression, the generation of a huge report, the writing of enormous log entries, or connections that stay open too long. The serv …pretnja · availability
-
№ 010
Rootkit … important property. It can settle beneath the operating system and beneath the layer where antivirus software can look: sometimes in drivers or in the kernel, …pretnja · malware
-
№ 070
SCADA/OT Attack … ice life. Much of it was designed for reliable operation, not for a hostile network. When IT and OT networks are joined for monitoring, remote access or efficie …pretnja · physical / IoT
-
№ 025
SIM Swapping … r. The attacker persuades, or bribes, a mobile operator to move the number to a new SIM card, citing a lost phone or a damaged card. They usually come armed wit …pretnja · identity
-
№ 030
SMS phishing - Smishing … r a parcel is often the bait. The amount is deliberately low so that card details are entered more readily.pretnja · social eng.
-
№ 045
SSRF … a function that fetches an image from a URL, generates a link preview or checks a remote resource. If the application accepts a user-supplied address without s …pretnja · applications
-
№ 054
Service Abuse … es. That is why quotas, reputation, anomalies and rate limiting matter more than the syntax of the request.pretnja · availability
-
№ 019
Session Hijacking … has already passed authentication and carry on operating the service in your name.pretnja · identity
-
№ 027
Spear Phishing … y and authority in a message are a sign to verify rather than to comply.pretnja · social eng.
-
№ 060
Supply Chain Attack … s, the attacker uses a supplier's access, an integration or an administrative channel. Either way, trust becomes the channel of attack.pretnja · trust
-
№ 059
Third-Party Compromise … ies often hold VPN access, support accounts, integrations, API keys, access to data, or the job of maintaining systems. If they are less well protected than the …pretnja · trust
-
№ 066
Typosquatting Defensive registration of similar domains helps but does not cover every variant. Monitoring is not optional.pretnja · trust
-
№ 009
Virus … ning processes and applications. That is what separates it from a worm: a virus needs a host and a user, while a worm spreads on its own.pretnja · malware
-
№ 033
Whaling … n set a large payment in motion, open access to strategic documents, compromise negotiations, or serve as the entrance to the rest of the organization. The high …pretnja · social eng.
-
№ 007
Wiper Without a sound backup in a separate location, a wiper ends the business. The 3-2-1 backup rule is the difference here between recovery and total loss. With a w …pretnja · malware
-
№ 029
voice phishing - Vishing … tle urgency is added, a person easily starts cooperating with the attacker, thinking they are solving a sudden problem.pretnja · social eng.
Tehnike
22 direktna pogotka-
№ 031
Data Exfiltration Data exfiltration involves transferring stolen information from the compromised environment to an attacker-controlled location. Data can be sent through encrypt …tehnika · exfiltration / impact
-
№ 026
Configuration Abuse Configuration abuse involves exploiting misconfigured systems, services, or security controls. Attackers look for default passwords, overly broad permissions, o …tehnika · discovery
-
№ 036
DNS Tunneling Technique of exfiltrating data or C2 communication through DNS queries.tehnika · exfiltration / impact
-
№ 005
Watering Hole Technique of compromising websites that the target group regularly visits.tehnika · initial access
-
№ 020
Access Token Manipulation Extracting an access key from a configuration file on a compromised servertehnika · privileges
-
№ 027
Automation & Scripting … scripts, tools, and automated procedures to accelerate and scale activities within a compromised environment. Attackers leverage system scripting interpreters, …tehnika · discovery
-
№ 004
Brute Force Login attempt rate limiting and multi-factor authentication are the most effective countermeasures.tehnika · initial access
-
№ 023
Container Escape … nerability, or a too-permissive runtime or orchestrator. Once on the host, the attacker reaches every container on it, and often the whole cluster.tehnika · privileges
-
№ 003
Credential Abuse Logging into a corporate VPN with credentials stolen via an infostealertehnika · initial access
-
№ 016
DLL Sideloading Exploits the DLL search order in the Windows operating system.tehnika · execution
-
№ 029
Domain Account Discovery … uire privileged access — any domain user can enumerate AD.tehnika · discovery
-
№ 037
Double Extortion Technique where data is first exfiltrated, then encrypted for ransom.tehnika · exfiltration / impact
-
№ 042
Encrypted C2 Channels DNS-over-HTTPS for data exfiltration past firewallstehnika · C2
-
№ 010
Exploitation … everaging a flaw in software, hardware, or configuration to execute unauthorized code or bypass security controls. Vulnerabilities can exist in operating system …tehnika · execution
-
№ 022
Forge Kerberos Tickets … to an AD environment as a domain user or administrator.tehnika · privileges
-
№ 019
Lateral Movement Using an administrator password hash to access other domain serverstehnika · privileges
-
№ 011
Persistence Adding a malicious entry to the operating system's autostart registrytehnika · execution
-
№ 018
Privilege Escalation … ation. Vertical escalation means reaching administrator or root level, while horizontal escalation means accessing another user's resources at the same privileg …tehnika · privileges
-
№ 025
Reconnaissance … encompasses network mapping, user and group enumeration, and shared resource discovery.tehnika · discovery
-
№ 032
Resource Exhaustion Resource exhaustion as a technique involves deliberately overloading target systems to make them unavailable to legitimate users. The attacker targets CPU, memo …tehnika · exfiltration / impact
-
№ 017
Rootkit Installation Can operate at user-space, kernel, or firmware (UEFI) level.tehnika · execution
-
№ 035
Website Defacement … CMS vulnerabilities, web server flaws, or administrator credentials.tehnika · exfiltration / impact
Odbrane
37 direktnih pogodaka-
№ 045
Penetration Testing Simulation of real attacks to identify vulnerabilities that automated tools miss.odbrana · governance
-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the a …odbrana · resilience
-
№ 033
CSPM In practice you get a list of concrete misconfigurations ranked by risk — 'this bucket is public', 'this role can be assumed by anyone', 'these databases aren't …odbrana · resilience
-
№ 034
DLP DLP watches where sensitive data goes and stops it where it shouldn't: an employee attaching a client list to a private email, copying a file with personal data to a USB, or pasting a database into a chat. It works by recognizing patterns (national IDs, card numbers, marked documents) and applying rules per channel — mail, web, endpoint, cloud.odbrana · resilience
-
№ 018
SOAR Security Orchestration, Automation and Response — automating security operations.odbrana · monitoring / response
-
№ 024
Backup & Recovery … storing them securely, and enabling reliable restoration in the event of loss, corruption, or destruction of original data.odbrana · resilience
-
№ 006
Browser Isolation … cuting web content in an isolated environment separate from the local system.odbrana · endpoints
-
№ 013
Certificate Management Managing the lifecycle of digital certificates — issuance, renewal, revocation.odbrana · identity / access
-
№ 028
DDoS Protection These solutions operate at the network and application layers, filtering malicious traffic while allowing legitimate requests through. They can be implemented a …odbrana · resilience
-
№ 029
DNS Security … ffic analysis can reveal tunneling and data exfiltration via DNS queries.odbrana · resilience
-
№ 040
DevSecOps Integrating security into all phases of the software development lifecycle.odbrana · people
-
№ 003
EDR EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.odbrana · endpoints
-
№ 002
Email Security … re delivery, and business email compromise. It operates at the server or cloud level before the message reaches the user.odbrana · endpoints
-
№ 001
Endpoint Protection Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 035
Firewall … ion address, port, and connection state. Next-generation firewalls (NGFW) add application awareness and user identity, so policy becomes "this application, for …odbrana · resilience
-
№ 022
IDS/IPS … e attention paid to what it reports. A system generating alerts no one reads is noise, not defense; signatures must be maintained and rules tuned to the specifi …odbrana · monitoring / response
-
№ 009
Identity & Access Management … nt, password policies, and directory service integration.odbrana · identity / access
-
№ 020
Incident Response Covers phases: preparation, identification, containment, eradication, recovery, lessons learned.odbrana · monitoring / response
-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.odbrana · monitoring / response
-
№ 017
MDR … sources or expertise to run their own security operations center. The service provider leverages advanced tools and experience from monitoring many environments …odbrana · monitoring / response
-
№ 032
Microsegmentation Finer network division at workload or application level, not just VLANs.odbrana · resilience
-
№ 005
Mobile Device Security Separates business and personal data on BYOD devices.odbrana · endpoints
-
№ 008
Multi-Factor Authentication Multi-factor authentication requires two or more independent proofs of identity at login. It typically combines something the user knows (password), something they possess (phone, hardware key), and something they are (biometrics).odbrana · identity / access
-
№ 025
Network Segmentation … efined network policies. Critical systems are separated from less sensitive ones, and access is permitted only as needed.odbrana · resilience
-
№ 012
Password Manager Tool for generating, storing, and auto-filling strong, unique passwords.odbrana · identity / access
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience
-
№ 038
Phishing Simulations Measures click rates, reporting rates, and credential submissions by department.odbrana · people
-
№ 010
Privileged Access Management … ccounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers …odbrana · identity / access
-
№ 043
Regulatory Compliance Meeting requirements of regulatory frameworks and standards for cybersecurity.odbrana · governance
-
№ 041
Risk Assessment Systematic process of identifying, analyzing, and prioritizing cyber risks.odbrana · governance
-
№ 015
SIEM … is, and visualization of security data, alert generation based on defined rules, and compliance monitoring against regulatory requirements. It serves as the cen …odbrana · monitoring / response
-
№ 037
Security Awareness … surable results include phishing simulation click rates.odbrana · people
-
№ 019
Threat Intelligence Feeds integrate into SIEM, EDR, and firewalls for proactive detection.odbrana · monitoring / response
-
№ 036
Virtual Private Network … ces protect traffic on untrusted networks; a corporate VPN opens a door into the company network — and that is where the similarity ends.odbrana · resilience
-
№ 027
WAF … y, and other application-layer attacks. It can operate in blocking or monitoring mode.odbrana · resilience
-
№ 004
XDR … tigue through centralized analysis instead of separate consoles.odbrana · endpoints
-
№ 011
Zero Trust … dless of whether it is inside or outside the corporate network. Every access request is verified before approval.odbrana · identity / access