Pretnje
15 direktnih pogodaka-
№ 028
Business Email Compromise Business email compromise is not an ordinary fake email. The attacker breaks into business correspondence, or imitates it well enough that somebody in the company believes the request comes from the director, from finance, from a supplier, a lawyer or a partner. The aim is usually money, but it can also be a confidential document, a change of payment details, or an opening for the next phase of the attack.pretnja · social eng.
-
№ 037
Crypto-wallet drainer … a fake page of a well-known project, a message on social media, an advert, an NFT offer or a "connect wallet" button. The signature being asked for often looks …pretnja · social eng.
-
№ 024
MFA Fatigue MFA fatigue is social-engineering pressure applied to two-factor authentication. The attacker has the password, leaked or phished, but is stopped at the second …pretnja · identity
-
№ 026
Phishing Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a messa …pretnja · social eng.
-
№ 031
Pretexting Pretexting is social engineering with a prepared story. The attacker does not simply send a link and wait for a click; they build a scenario in which what they …pretnja · social eng.
-
№ 030
SMS phishing - Smishing Smishing is phishing over SMS or messaging apps. The attacker sends a short message with a link, a request to confirm something, or an instruction for an urgent action, counting on messages being read quickly on a phone and without much checking.pretnja · social eng.
-
№ 027
Spear Phishing Spear phishing is phishing cut to fit one person or a small group of users. Instead of sending the same message to thousands of addresses, the attacker first gathers information about the victim — where they work, who they work with, what they are working on right now, how the company addresses its clients — and then writes a message that reads as if it came from that world.pretnja · social eng.
-
№ 002
Trojan A Trojan does not break in; the victim opens the door. It usually presents itself as something useful — a program or a document, a fake installer, a cracked application, or a harmless-looking tool for speeding up the computer. The user runs what they meant to run, and the attacker gets what they were after.pretnja · malware
-
№ 029
voice phishing - Vishing Vishing is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present themselves as a bank, technical support, a courier, the police, the tax office, or somebody from the company, while trying to extract details or lead the victim into doing something they otherwise would not.pretnja · social eng.
-
№ 021
Account Takeover … acker changes the recovery address and phone on a social network, the owner rarely gets the account back, if at all. What usually follows is a new account and b …pretnja · identity
-
№ 063
Contractor Abuse External associates can hold access to code, production systems, client data, the VPN, support tools or documentation. Unlike employees they are often outside t …pretnja · trust
-
№ 035
Deepfake Attack … technical curiosity. Deepfakes strengthen classic social engineering because they give the attacker what used to be largely out of reach: a convincing voice, fa …pretnja · social eng.
-
№ 058
Insider Threat … ployee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized to begin wit …pretnja · trust
-
№ 059
Third-Party Compromise … r, a partner, a service provider or an external associate who already holds some form of trust and authorized access. Instead of forcing the front door, the att …pretnja · trust
-
№ 036
Watering Hole Attack … , an internal application, a forum, an industry association, or a resource used by one specific group of people.pretnja · social eng.
Tehnike
5 direktnih pogodaka-
№ 002
Social Engineering Social engineering as a technique involves manipulating human behavior to obtain information, access, or the execution of actions that benefit the attacker. It …tehnika · initial access
-
№ 030
OSINT … s LinkedIn profiles, DNS records, Shodan, GitHub, social media.tehnika · discovery
-
№ 041
Fast-Flux DNS Rapid rotation of IP addresses associated with a C2 domain.tehnika · C2
-
№ 008
Physical Access Effective in combination with social engineering (tailgating).tehnika · initial access
-
№ 025
Reconnaissance … g publicly available employee information through social mediatehnika · discovery
Odbrane
11 direktnih pogodaka-
№ 018
SOAR Reduces mean time to respond (MTTR) and offloads SOC analysts from repetitive tasks.odbrana · monitoring / response
-
№ 006
Browser Isolation Executing web content in an isolated environment separate from the local system.odbrana · endpoints
-
№ 002
Email Security Email security encompasses technologies that filter inbound and outbound messages to prevent phishing, malware delivery, and business email compromise. It operates at the server or cloud level before the message reaches the user.odbrana · endpoints
-
№ 001
Endpoint Protection Endpoint protection encompasses software solutions that protect computers, servers, and mobile devices from malicious software and unauthorized activities. It combines classic signature-based malware detection with heuristic analysis and behavior-based detection.odbrana · endpoints
-
№ 008
Multi-Factor Authentication Multi-factor authentication requires two or more independent proofs of identity at login. It typically combines something the user knows (password), something they possess (phone, hardware key), and something they are (biometrics).odbrana · identity / access
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience
-
№ 045
Penetration Testing Covers network, web applications, social engineering, and physical access.odbrana · governance
-
№ 010
Privileged Access Management Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.odbrana · identity / access
-
№ 043
Regulatory Compliance Includes GDPR, NIS2, ISO 27001, SOC 2, PCI DSS, and local regulations.odbrana · governance
-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.odbrana · resilience
-
№ 019
Threat Intelligence … TI informs management, operational TI informs the SOC team.odbrana · monitoring / response