1/58
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Vulnerability
Asset Value
Ease of Exploit
Threat
Internal/External
Malicious/Accidental
Threat Actor
Threat Vector
Risk
(Impact * Likelihood)
Attributes of Threat Actors (1)
Known threats vs adversary behaviours
Internal/External (Attributes of Threat Actors 2)
Attribute of an attacker, not where an attack takes place
Internal Threats
Have authorized access already
Level of sophistication/Capability
Low Capability Actors
High Capability Actors
Access to Military Assets
(Attribute of Threat Actors 3)
Low Capability Actors
Rely on Commodity tools
High Capability Actors
Can develop new attack
Resources/funding
Attributes of Threat Actors (4)
Motivations of Threat Actors (1)
Intent/Motivation
Chaotic Motivation, Financial Motivations, Political Motivations
Three types of motivations of Threat Actors
Intent/Motivation (Motivation of Threat Actors)
Maliciously Targeted versus opportunistic
Accidental/Unintentional
Strategies (Motivations of Threat Actors)
Service disruption, data exfiltration, and disinformation
Financial Motivations
Blackmail, extortion, and fraud
Political Motivation
Whistleblowers, campaign groups, nation-state actors
Lone Hacker
White hats vs black hats
Authorized vs non-authorized
Unskilled Attacker
Script Kiddies
Lone Hacker, Unskilled Attacker, Hacker Teams, and Hacktivists
Four types of hacker and hacktivists
APT
Advance Persistent Threat
Nation-State Actors and Advanced Persistent Threats
Attached to military/secret services
High Level of Capability
APT
Espionage and strategic advantage
Deniability
False Flag Operations
Organized Crime
Operates under legal jurisdiction
Motivated by criminal profit
Can be well-resourced and funded
Competitors
Cyber espionage and disinformation
Combine with insider threat
Malicious Internal Threat and Unintentional Insider Threat
Two Types of Internal Threat Actors
Malicious Internal Threat
Has or had Authorized Access
Employees, Contractors, Partners
Sabotage, Financial Gain, Business Advantage
Unintentional Insider Threat
Weak Policies and procedures
Weak Adherence to policies and procedures
Lack of Training/Security Awareness
Shadow IT
Attack Surface
Points where an attacker can discover/exploit vulnerabilities
Physical, Network, Application, and Human Surfaces
Whole Organization or single system/app scope
Threat Vectors
High-capability actors can expand the attack surface by developing novel vectors
Vulnerable Software
Faults in code or design
Delays and difficulties in patching
Client-Based vs Agentless
Characteristic of automated vulnerability scanners
Vulnerable Software, Unsupported System and Application, Client-Based vs Agentless
Three Vulnerable Software Vectors
Remote vs local exploit techniques, Unsecure Networks, and Specific Vectors
Three Network Vectors
Unsecure Networks
Lack of Confidentiality, Integrity, and Availability
Specific Vectors
Direct Access and Wired (Physical Ports)
Remote, Wireless, Cloud, and Bluetooth
Default Credentials
Open Service Port (TCP and UDP ports)
Lure-Based Vectors
Bait That Will tempt the target into opening it
Removable Device, Executable File, Document Files, Image Files
Four Kinds of Lure-Based Vectors
Removable Device
Drop Attack
Executable File
Trojan Horse Malware
Document Files
Macro and Scripting technologies
Image Files
Viewer/Browser vulnerabilities
Email, Short Message Service (SMS), Instant Messaging (IM), Web and Social Media, Voice Call
Five Message-Based Vectors
Supply-Chain Attack Surface
End-to-end process of designing, manufacturing, and distributing goods and services to a customer
Procurement Management
Suppliers, Vendors, and Business Partners
Whole Supply Chain can be Highly Complex
Managed Service Providers (MSPs)
Social Engineering
“Hacking The Human”
Reconnaissance and eliciting information, Intrusion and gaining unauthorized access
Purposes of Social Engineering
Persuade a user to run a malicious file
Scenarios for social engineering (1)
Contact a help desk and solicit information
Scenarios for social engineering (2)
Gain Access to premises and install a monitoring device
Scenarios for social engineering (3)
Impersonation
Pretending to be someone else
Persuasiveness/consensus/liking approach
Coercion/Threat/Urgency Approach
Pretexting
Exploit Situations where identity-proofing is difficult
Using a scenario with convincing additional detail
Obtain or spoof data that supports the identity claim
Phishing
Tricks target into using a malicious resource
Spoof legitimate communications and site
Vishing
Using a voice channel
SMishing
Using text messaging
Pharming
Redirection by DNS Spoofing
Passive Techniques
Have less risk of detection
Typosquatting
Cousin domains that look like a trusted domain
Pose as colleague, Business Partner, or vendor
Targets of Pishing/Vishing/Smishing to a specific individual
Spear phishing, whaling, CEO Fraud, and Angler Phishing
Four types of phishing on BUSINESS EMAIL COMPROMISE
Brand Impersonation and Disinformation
Making convincing fake phishing messages, business correspondence, and pharming websites
Disinformation vs Misinformation
Watering Hole Attack
Compromise a third-party site that the threat actor knows is used by the target