官术网_书友最值得收藏!

Understanding the Cybersecurity Kill Chain

The last chapter, you learned about the incident response process and how it fits into the overall enhancement of a company's security posture. Now it is time to start thinking as an attacker and understand the rationale, the motivation, and the steps of performing an attack. We call this the cybersecurity kill chain, which is something that we briefly covered in Chapter 1, Secure Posture. Today, the most advanced cyber-attacks are reported to involve intrusions inside a target's network that last a long time before doing damage or being discovered. This reveals a unique characteristic of today's attackers: they have an astounding ability to remain undetected until the time is right. This means that they operate on well-structured and scheduled plans. The precision of their attacks has been under study and has revealed that most cyber attackers use a series of similar phases to pull off successful attacks.

To enhance your security posture, you need to ensure that all phases of the cybersecurity kill chain are covered from a protection and detection perspective. But the only way to do that is to ensure that you understand how each phase works, the mindset of an attacker, and the tolls that are taken on each phase.

In this chapter, we're going to be covering the following topics:

  • External reconnaissance
  • Compromising the system
  • Lateral movement
  • Privilege escalation
  • Concluding the mission
主站蜘蛛池模板: 伊通| 上蔡县| 龙泉市| 喀喇沁旗| 苍溪县| 筠连县| 清水县| 广饶县| 杭锦后旗| 赞皇县| 固原市| 寻甸| 丘北县| 临桂县| 昌邑市| 呼伦贝尔市| 南投市| 锡林郭勒盟| 孙吴县| 大同市| 安龙县| 云梦县| 上虞市| 九江市| 随州市| 板桥市| 荆州市| 桐城市| 沙田区| 紫金县| 迁西县| 玉门市| 长春市| 兴隆县| 涟水县| 叙永县| 林甸县| 淳安县| 洮南市| 怀来县| 常州市|