The UK's National Cyber Security Centre and their Western European friends today released a report focusing on the most commonly used hacking tools.
The study presents five categories of available hacking tools that are widely used by criminals, spies and hacktivists worldwide. The list below will not come as a surprise to those involved in penetration testing but is valuable to the public who wants to secure their systems.
The PDF lists some of the tools most likely to be used in targeted networks.
Remote Access Trojans (RATs): “invisible” programs for implanting backdoors and removing data
Web Shells: scripts planted on servers to provide remote administrative control
Mimikatz: Steals passwords and other credentials stored in memory
PowerShell Empire: This framework allows hackers to break into sensitive systems
Detection and Control Tools and Extermination Tools: Utilities used to disguise the location of a hacker.
Of course, the popular penetration-testing kits.
Often these tools are not inherently malicious and can be used legitimately for penetration testing to find vulnerabilities. However, they can also be used to maliciously compromise networks. The NCSC says that using the above tools in parallel can yield impressive results, but also make them more difficult to detect.
“Many are used in combination with each other, presenting a huge challenge for the network defender,” GCHQ says.
The NCSC says that a few simple steps could go a long way in preventing potential attacks. Basic defenses include two- or multi-factor authentication, network segmentation, and more, which you can read about in the PDF below.
__________________________
- Internet Archive, the first decentralized Web, is online
- Chrome reset WWW and HTTP
- Tails 3.9.1 ISO just released by the Tails Project
- Google's DeepMind: use of dopamine by neural networks
