HomeSecurityWhat are the tactics used in corporate system breaches?

What are the tactics used in corporate system breaches?

The threat landscape is constantly evolving, with businesses pressured to keep up with ongoing vulnerability disclosures, security updates, and more. The tactics used to breach corporate systems are constantly changing.

Analysts estimate that by 2021, 3.5 million cybersecurity roles will be unfilled, so not only will existing security professionals have to face a seemingly endless battle against cyberattackers, but they will have to do so while departments are understaffed – not to mention the challenges posed by COVID-19.

regular breaches of corporate systems
The tactics used in breaches of corporate systems are constantly changing.

There are tools on the market that can help business executives. Automated scanners, artificial intelligence (AI), algorithms, and machine learning (ML)-based software can manage the security of corporate systems.

There are also frameworks, such as MITRE ATT&CK, which provides a free knowledge base that compiles tactics and techniques observed in current, real-world attacks.

This is the data repository that Cisco examined in a new report that outlines current attack trends on endpoints and enterprise.

On Monday, Cisco published a dataset based on MITRE ATT&CK classifications combined with indicators of compromise (IoCs) from organizations that receive alerts through the company's security solutions within specific time frames.

According to the company, in the first half of 2020, fileless threats were the most common attack vector used against enterprises. Fileless attacks include process injections, registry corruption, and threats such as the Kovter malware or a Trojan.

In second place are dual-purpose tools, including Metasploit, PowerShell, CobaltStrike, and Powersploit. Legitimate penetration testing tools like Metasploit help security as a whole, but unfortunately, cyberattackers can abuse these solutions to their advantage.

Tools like Mimikatz, a legitimate authentication and credential management system, come in third place.

In the first half of 2020, Cisco reports that these attackers accounted for approximately 75% of the critical vulnerabilities observed.

Avoidance of defensive processes occurs in 57% of all IoC notifications and execution reaches 41%.

Malicious code execution stole the top spot from defensive process evasion in critical attacks, with a 14% increase, bringing total IoC alerts to 55%. Defensive process evasion decreased by 12% to 45%, while persistence, lateral movement, and credential access increased by 27%, 18%, and 17%, respectively.

To protect against high-level threats, Cisco recommends that administrators use group policies or whitelists for file execution, and if dual-use tools are required by an organization, temporary access policies should be implemented. Additionally, connections made between endpoints should be monitored to detect breaches.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS