官术网_书友最值得收藏!

Understanding the Cybersecurity Kill Chain

The last chapter, you learned about the incident response process and how it fits into the overall enhancement of a company's security posture. Now it is time to start thinking as an attacker and understand the rationale, the motivation, and the steps of performing an attack. We call this the cybersecurity kill chain, which is something that we briefly covered in Chapter 1, Secure Posture. Today, the most advanced cyber-attacks are reported to involve intrusions inside a target's network that last a long time before doing damage or being discovered. This reveals a unique characteristic of today's attackers: they have an astounding ability to remain undetected until the time is right. This means that they operate on well-structured and scheduled plans. The precision of their attacks has been under study and has revealed that most cyber attackers use a series of similar phases to pull off successful attacks.

To enhance your security posture, you need to ensure that all phases of the cybersecurity kill chain are covered from a protection and detection perspective. But the only way to do that is to ensure that you understand how each phase works, the mindset of an attacker, and the tolls that are taken on each phase.

In this chapter, we're going to be covering the following topics:

  • External reconnaissance
  • Compromising the system
  • Lateral movement
  • Privilege escalation
  • Concluding the mission
主站蜘蛛池模板: 浪卡子县| 登封市| 青阳县| 汝南县| 岳阳县| 樟树市| 东宁县| 九寨沟县| 临夏县| 南投市| 松桃| 泾阳县| 江川县| 饶平县| 万盛区| 卓资县| 深水埗区| 内丘县| 剑阁县| 塔河县| 秭归县| 榆社县| 应城市| 融水| 红桥区| 宜宾县| 平定县| 南雄市| 辛集市| 恩施市| 文安县| 灵宝市| 五家渠市| 新昌县| 武鸣县| 和政县| 宁安市| 永兴县| 本溪| 柞水县| 手游|