Email: 5 tips to protect against attacks
Five practical guidelines to reduce exposure to email-borne threats: phishing, attachment macros, sender spoofing, MFA and user awareness — what works and what does not.
Category
Five practical guidelines to reduce exposure to email-borne threats: phishing, attachment macros, sender spoofing, MFA and user awareness — what works and what does not.
Antivirus evasion techniques in red-team operations: payload encoding, signature avoidance, behavioural-detection bypass and corresponding defensive lessons.
Armitage in offensive security operations: post-exploitation workflows, Metasploit collaboration, lateral movement and defensive lessons for SOC teams.
CVE-2020-0601 (CurveBall): Microsoft Windows certificate validation vulnerability, exploitation primitives, NSA disclosure and remediation steps.
Critical Citrix ADC/NetScaler vulnerability: exploitation primitives, exposure metrics on Italian perimeters and remediation steps for affected appliances.
Phishing campaigns observed during January 2019: lure templates, payload delivery and indicators across waves targeting Italian organisations.
TrickBot is a banking-trojan malware that steals the login credentials of targeted banking sites using webinjects. Since June 2018 TrickBot features lateral movement capabilities in order to propagate itself from an infected client to a vulnerable domain controller. TrickBot Screenshots TrickBot Indicators Of Compromise (IOCs)
Cryptomining as a post-compromise objective: indicators on Linux and Windows endpoints, persistence techniques, network signals and containment workflow.
Russia-Ukraine cyber conflict: spillover operations on Italian organisations, attribution signals, defacement and DDoS waves, intelligence-driven defence priorities.