.@potatowar and before the Kill Chain, we just called it footprinting :) #TrendChat
Thanks for participating! #TrendChat
This is your favourite tweet, look into my eyes #TrendChat
Build defences that recognise attacks at multiple layers, strive for resiliency #TrendChat
A10: Constant vigilance providing actionable intelligence is key. Security must be built based on "breach will happen" #TrendChat
A10: traffic spikes, unusual db queries, patch mgmt, user education all play a part #TrendChat
A10: traditional defense is blind to targeted attacks, netowrk inspection, anomalous behaviour on legit accounts, (cont) #TrendChat
A9: For the victim, attacker intent, internal weaknesses in architecture and system design as long as traffic is noticed! #TrendChat
A9: For the attacker, netowrk architecture, resources, user accounts, severs databases of interest #TrendChat
.@gianlucaSB Depends on the objective, but in most cases yes lateral movment & extraction is non-automated #TrendChat
.@japalm MDM, AV URL filt, Encryption and policy enforcement. Unfortunately OS architecture makes true security difficult 4 most #TrendChat
Like most malware, attackers are Windows focussed but SabPab and LuckyCat .apks show wider intent #TrendChat
LuckyCat attacks show evidence that attackers are already investigating Mobile OS, we found .apk files on C&C servers #TrendChat
Yep and looking for self signed cert traffic is a good flag to raise #TrendChat
A6: C&C traffic at the firewall was a good indicator of compromise, keeping it internal keeps it lower profile #TrendChat
One important evolution we noted recently was the siting of C&C *inside* compromised orgs, cutting down on perimeter traffic #TrendChat
.@cyberwar and before the Kill Chain, we just called it footprinting :) #TrendChat
LinkedIn is not a social network, everyone know shtat, it's a *professional* network and therefore safe to share info </sarcasm> #TrendChat
Open Source Intelligence, basically TMI :) Information overshare in public, helps in creating credible delivery vehicles #TrendChat
Not to mention the industrialisation of cybercrime and maturity of toolkits #TrendChat
One thing that has really enabled targeted attacks in the last decade is the abundance of OSINT available though online search #TrendChat
RSA over $60m cost due to APT, DigiNotar out of business, the effects are material and measurable #TrendChat
A3: Materially, through loss of IP, loss of competitiveness, share price, reputational damage #TrendChat
A2: Persistency is about the ability to maintina a presence even in the face of victim's attempts to clean up and detect #TrendChat!
A2: Advanced is for me is more about the research & targeting than the malware or exploit in many cases #TrendChat!
A1: Depends who and where you are, consumers face an array of threats, as does industry. For industry the landscape has changed…#TrendChat!
Shame to see SourceFire bidding for sponsored ads on our #TrendChat :( #notcricket chaps #notcricketatall