166 terms ·
75/46/45
63 rezultata za „reputation" ·
6 direktnih ·
57 povezanih
Pretnje
2 direktna pogotkaTehnike
1 direktan pogodakOdbrane
3 direktna pogotka-
№ 002
Email Security These solutions use sender reputation analysis, attachment sandboxing, domain authenticity verification, and suspicious link detection. More advanced variants u …odbrana · endpoints
-
№ 043
Regulatory Compliance … pliance can result in fines, loss of licenses, or reputation.odbrana · governance
-
№ 007
SPF/DKIM/DMARC … o sends in your name. This protects your domain's reputation with others and reduces spoofed internal mail.odbrana · endpoints
↳ Povezano
57 stavki koje koriste „reputation"-
№ 065
Accidental Data Leak An accidental data leak is not an attack in the classic sense, but the consequences can look the same. Data becomes available to the wrong people through human error, bad configuration, wrong sharing, a public repository, open cloud storage, or mail sent to the wrong address.pretnja · trust
-
№ 021
Account Takeover Account takeover is the moment the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail address, the phone number and the second factor, while the real owner is shut out with no technical way back in on their own. Takeover is rarely the first stage of an attack. It is usually the destination of what came before: phishing, credential stuffing, token theft.pretnja · identity
-
№ 043
Authentication Bypass An authentication bypass means the attacker reaches a protected part of the system without logging in the ordinary way. They need not know a password. Sometimes a flaw in the logic is enough, or an unprotected endpoint, a predictable token, a misconfigured proxy, or a gap between two steps of the login.pretnja · applications
-
№ 027
Automation & Scripting Automation and scripting involves using scripts, tools, and automated procedures to accelerate and scale activities within a compromised environment. Attackers leverage system scripting interpreters, configuration management tools, and custom scripts.tehnika · discovery
-
№ 024
Backup & Recovery Backup and recovery encompasses the processes and technologies for regularly creating copies of data and systems, storing them securely, and enabling reliable restoration in the event of loss, corruption, or destruction of original data.odbrana · resilience
-
№ 028
Business Email Compromise Business email compromise is not an ordinary fake email. The attacker breaks into business correspondence, or imitates it well enough that somebody in the company believes the request comes from the director, from finance, from a supplier, a lawyer or a partner. The aim is usually money, but it can also be a confidential document, a change of payment details, or an opening for the next phase of the attack.pretnja · social eng.
-
№ 039
Command & Control Command and control communication involves establishing a persistent channel between the attacker and the compromised system for sending commands and receiving results. The attacker uses this channel to manage malware, launch new attack phases, and retrieve data.tehnika · C2
-
№ 026
Configuration Abuse Configuration abuse involves exploiting misconfigured systems, services, or security controls. Attackers look for default passwords, overly broad permissions, open ports, and services without authentication.tehnika · discovery
-
№ 003
Credential Abuse Credential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate user.tehnika · initial access
-
№ 034
Data Destruction Technique of permanently deleting or corrupting data on a compromised system.tehnika · exfiltration / impact
-
№ 031
Data Exfiltration Data exfiltration involves transferring stolen information from the compromised environment to an attacker-controlled location. Data can be sent through encrypted channels, legitimate cloud services, email, or even physical media.tehnika · exfiltration / impact
-
№ 031
Deception Technology Deploying decoy resources (honeypots, honeytokens) to detect attackers.odbrana · resilience
-
№ 021
Digital Forensics Collecting, preserving, and analyzing digital evidence after a cyber incident.odbrana · monitoring / response
-
№ 040
Domain Fronting Technique of hiding C2 traffic behind legitimate CDN domains.tehnika · C2
-
№ 037
Double Extortion Technique where data is first exfiltrated, then encrypted for ransom.tehnika · exfiltration / impact
-
№ 003
EDR EDR (Endpoint Detection and Response) is a technology that continuously monitors endpoint activity, records events, and enables detection, investigation, and response to threats that bypassed preventive controls.odbrana · endpoints
-
№ 042
Encrypted C2 Channels Using HTTPS, DNS-over-HTTPS, or other encrypted protocols for C2.tehnika · C2
-
№ 001
Endpoint Protection Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 010
Exploitation Exploitation involves leveraging a flaw in software, hardware, or configuration to execute unauthorized code or bypass security controls. Vulnerabilities can exist in operating systems, applications, network services, or firmware.tehnika · execution
-
№ 041
Fast-Flux DNS Rapid rotation of IP addresses associated with a C2 domain.tehnika · C2
-
№ 022
IDS/IPS IDS/IPS are systems that monitor network traffic (or host activity) for patterns indicating an attack. An IDS (Intrusion Detection System) only reports suspicious activity; an IPS (Intrusion Prevention System) sits inline and can block it immediately.odbrana · monitoring / response
-
№ 009
Identity & Access Management Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.odbrana · identity / access
-
№ 012
Impair Defenses Defense evasion encompasses techniques by which an attacker conceals their activity from security tools, analysts, and automated detection systems. The goal is to remain undetected for as long as possible in the compromised environment.tehnika · execution
-
№ 014
In-Memory Execution Executing malicious code in memory without writing files to disk.tehnika · execution
-
№ 020
Incident Response A planned process of identifying, containing, eradicating, and recovering from cyber incidents.odbrana · monitoring / response
-
№ 046
Indicator Removal A set of techniques for hindering or preventing digital forensics.tehnika · evasion
-
№ 058
Insider Threat An insider threat comes from a person who has, or once had, legitimate access to an organization's systems, data or premises. That can be an employee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized to begin with.pretnja · trust
-
№ 019
Lateral Movement Lateral movement involves an attacker moving from one compromised system to another within the same network. The goal is to expand access to systems containing more valuable data or enabling further escalation.tehnika · privileges
-
№ 015
Living off the Land Using legitimate system tools to execute malicious actions.tehnika · execution
-
№ 005
Loader / Dropper Loaders and droppers are couriers. Their only job is to deliver the infection to the machine. A dropper carries the payload with it and writes it to the system; a loader is usually smaller and pulls the payload from the internet only once it has landed. Neither does anything more than that — and that is their advantage.pretnja · malware
-
№ 043
Log Tampering Deleting, modifying, or disabling logs to hide activity.tehnika · evasion
-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.odbrana · monitoring / response
-
№ 017
MDR MDR (Managed Detection and Response) is a service where an external security team provides continuous monitoring, threat detection, and incident response on behalf of an organization. It combines technology with human expertise.odbrana · monitoring / response
-
№ 038
Malware Delivery Malware delivery encompasses the methods by which malicious software is transferred to a target system. This includes infected attachments, compromised websites, malicious ads, removable media, and compromised software updates.tehnika · C2
-
№ 032
Microsegmentation Finer network division at workload or application level, not just VLANs.odbrana · resilience
-
№ 025
Network Segmentation Network segmentation is the practice of dividing network infrastructure into smaller, isolated segments with controlled communication between them. The goal is to limit an attacker's ability to move through the network after compromising a single system.odbrana · resilience
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience
-
№ 013
Payload Obfuscation Payload obfuscation involves applying techniques to conceal the content and intent of malicious code. Attackers use encryption, compression, encoding, polymorphism, and packing to evade detection by security tools.tehnika · execution
-
№ 026
Phishing Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a message that appears to come from a known organization — a bank, a courier, a government service, a colleague — and leads the victim into doing one of three things: clicking a link, opening an attachment, or entering their credentials somewhere.pretnja · social eng.
-
№ 001
Phishing Phishing as a technique involves sending fraudulent emails, SMS messages, or chat messages to trick the victim into clicking a malicious link, opening an infected attachment, or entering credentials on a fake page.tehnika · initial access
-
№ 034
QR phishing - Quishing Quishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake page for a login, a payment, a document download or an account confirmation.pretnja · social eng.
-
№ 038
Remote Code Execution Remote code execution is one of the most dangerous classes of vulnerability, because it lets an attacker run their own code on a vulnerable system from somewhere else entirely. If the application runs on a server, the attacker is no longer merely a user on the outside; they gain a way to influence what the server executes.pretnja · applications
-
№ 032
Resource Exhaustion Resource exhaustion as a technique involves deliberately overloading target systems to make them unavailable to legitimate users. The attacker targets CPU, memory, network bandwidth, disk, or connection limits.tehnika · exfiltration / impact
-
№ 015
SIEM SIEM (Security Information and Event Management) is a system that collects logs and events from diverse sources across the entire infrastructure, centralizes them, and applies correlation rules to detect suspicious patterns and security incidents.odbrana · monitoring / response
-
№ 018
SOAR Security Orchestration, Automation and Response — automating security operations.odbrana · monitoring / response
-
№ 039
SQL Injection SQL injection usually arises when a web application passes user input blindly to the database on the web server. Instead of ordinary text, the attacker can put part of an SQL command into a login, search or filter field. If the application does not stop it, the database can execute something the designer never had in mind, and certainly never intended.pretnja · applications
-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.odbrana · resilience
-
№ 033
Service Abuse Service abuse as a technique involves using legitimate system functionalities in unintended ways to cause damage, gain unauthorized access, or achieve financial gain.tehnika · exfiltration / impact
-
№ 002
Social Engineering Social engineering as a technique involves manipulating human behavior to obtain information, access, or the execution of actions that benefit the attacker. It relies on trust, authority, urgency, or fear.tehnika · initial access
-
№ 027
Spear Phishing Spear phishing is phishing cut to fit one person or a small group of users. Instead of sending the same message to thousands of addresses, the attacker first gathers information about the victim — where they work, who they work with, what they are working on right now, how the company addresses its clients — and then writes a message that reads as if it came from that world.pretnja · social eng.
-
№ 019
Threat Intelligence Collecting, analyzing, and applying data about current cyber threats.odbrana · monitoring / response
-
№ 002
Trojan A Trojan does not break in; the victim opens the door. It usually presents itself as something useful — a program or a document, a fake installer, a cracked application, or a harmless-looking tool for speeding up the computer. The user runs what they meant to run, and the attacker gets what they were after.pretnja · malware
-
№ 066
Typosquatting Typosquatting exploits small mistakes in typing, reading or recognizing a name. The attacker registers a domain, an account or a software package that resembles a legitimate name, counting on a user, a developer or a system to miss one letter, swap a character or overlook the difference.pretnja · trust
-
№ 009
Virus A virus embeds itself in other executable files and runs together with them. It starts when the user launches the application or opens the infected file, and often attaches itself to other running processes and applications. That is what separates it from a worm: a virus needs a host and a user, while a worm spreads on its own.pretnja · malware
-
№ 027
WAF WAF (Web Application Firewall) is a firewall that filters, monitors, and blocks HTTP/HTTPS traffic to web applications. It sits between users and the web server, analyzing each request against defined rules.odbrana · resilience
-
№ 033
Whaling Whaling is targeted phishing aimed at senior management, owners, directors and people who can approve large decisions. The target is not chosen by chance. The attacker knows who they are after and why that person is worth more than an ordinary account.pretnja · social eng.
-
№ 004
XDR XDR (Extended Detection and Response) unifies data from endpoints, network, email, and cloud.odbrana · endpoints