Antivirus
Software that looks for known-bad and obvious malice, then tries to stop and clean it. Necessary. Not sufficient.
34 entries
Software that looks for known-bad and obvious malice, then tries to stop and clean it. Necessary. Not sufficient.
Border Gateway Protocol. How networks exchange routes. A hijack shows up as an unexpected origin ASN or RPKI invalid.
Regular callbacks from a host that should be quieter. Interval plus jitter, not a perfect metronome.
C2. How the operator talks to a compromised host after they are in. DNS, HTTPS, and traffic that looks like SaaS are common.
A fake DNS answer wins. Cache poisoning is the recursive version. Logging and resolver choice matter.
Data moved through DNS queries and answers. Detection is odd volume, long labels, and unusual types.
DLP. Stop or log sensitive data leaving through the paths you actually instrumented. Policy plus telemetry, not a magic classifier.
Malware derives many domains so blockers lag. Hunt high NXDOMAIN and labels that look generated, not a brand.
Endpoint detection and response. Behaviour plus the ability to isolate. An agent without an owner is inventory.
Data leaving. Bulk, slow, or stuffed into a protocol nobody is watching. DLP is a control; logs are how you know.
A hostname whose A or NS answers keep rotating. A resilience trick used by some botnets. Short TTL plus churn.
A decoy built to attract hostile attention so you can study it. Not a substitute for patching production.
A written path for a class of incident. Roles, decisions, and evidence. Not a novel, and not a blank page at 2 a.m.
An artefact that suggests a compromise: a hash, a name, an address, an email. Useful. Not a strategy.
Watches for unwanted activity and tells someone. Host or network. Alert without an owner is a screensaver.
IDS with a fist. Identifies unwanted traffic and can block it in the moment. Mis-tune it and you become the outage.
After the first box, they walk. Credentials, remote admin, and trust you already granted.
Use the admin tools already on the box. PowerShell, WMI, bash, cloud CLIs. No new malware required.
Time-stamped records of what happened. Collect what can answer a question. If it never gets queried, it is storage spend.
Bombard the user's phone with push prompts until they tap Allow. MFA still on. Judgement off.
A knowledge base of adversary tactics and techniques. Use it to find detection gaps, not to decorate a slide.
Who talked to whom, when, how much. Metadata, not payload. Cheap enough to keep.
NDR. Watch the wire or the flow for threat behaviour, not just known signatures. Complements EDR. Does not replace it.
The packets, on disk. Ground truth for a window of time. Heavy, precise, and easy to collect too late.
Historical DNS answers observed by sensors. Pivot on an IOC. Not a replacement for a live lookup.
Still there after reboot, password change, or the first cleanup. Scheduled tasks, tokens, and legitimate-looking remote access.
Security information and event management: collect, normalise, correlate, alert. Useless if nobody owns the queue.
Orchestration and response. Automate the boring. Keep a person on steps that isolate a host or disable an account.
A paddock for untrusted code. If it explodes, the paddock takes it. Production is not a paddock.
People, detections, and a queue. A room full of screens is optional. Ownership of after-hours is not.
How they work, not just which IP they used today. ATT&CK is the common catalogue.
Assume they are already in. Ask a question of your logs. Not a dashboard tour.
Context that changes a decision. IoCs expire. TTPs last. A feed you never action is a newsletter.
WAF. A reverse proxy that tries to stop common web attacks before the app. Rules, not a rewrite of the application.
Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary