Skip to content

ESET Achieves Certification in AV-Comparatives’ First Anti-Tampering Test – Marking the Importance of These Advanced Security Features in Business Products

Usually, when discussing endpoint security, people dismiss the underlying technology as “techno-babble,” looking more at the performance and cost rather than what makes a cybersecurity solution actually work.

Those underlying technologies or toolsets are actually very important, as each layer protects the endpoint in a specific way, going from cloud-based sandboxing to actual on-device protection to deter any would-be attacker from compromising a network or a system. The combination of all these measures is what makes endpoint security work; however, as in the case of our detection and response blog, some features deserve deeper exploration, as well as the reasons why they exist in the first place – like the case of anti-tampering technologies created to protect against, you guessed it, tampering.

Recently, AV-Comparatives conducted its first Anti-Tampering Certification Test where security products were subjected to advanced techniques and tools in an effort to disable or modify AV/EPP/EDR components or capabilities through tampering. When the test results came in, ESET was one of only four companies that passed – showcasing the effectiveness of ESET’s multi-layered security approach. In the tests, ESET PROTECT Entry demonstrated the ability to effectively detect and prevent tampering attempts and protect its own integrity from malicious actors.

What is tampering?

Once a cybercriminal compromises a network/machine, staying under the radar is the most important hurdle to overcome. This is best achieved by eliminating endpoint security software, likely by using compromised credentials to access the network and then using legitimate tools as much as possible (living off the land).

That is called tampering, and it can happen in a variety of ways, usually by prompting the user with fake pop-ups asking them to disable their antivirus to avoid unnecessary software blocking during installation, for example. Consequently, the attacker has an easier time to compromise one’s system. Attackers might also want to completely and wholly kill security software services, modify Registry keys or configuration files so security tools do not operate properly. Or they may use other methods to interfere with security products, like disabling updates to prevent the latest security patches from reaching a victim’s systems. A successful tampering attack can result in a loss of functionality for the whole security ecosystem, enabling unauthorized access to the internal system (like privilege escalation), which could result in a data breach.

AV-Comparatives describes the hurdle of overcoming endpoint security rather as being about getting past the annoying product, even as a privileged user. Usually, after collecting logs and analyzing them post-incident, an admin can see attempts to disable endpoint security, potentially poor configuration of security products, the existence of vulnerabilities, and which modules in the endpoint security product were eventually disabled due to all the aforementioned weaknesses.

As soon as the criminal actor disables endpoint security software, they likely have limited time before they are detected – IT admin logs into ESET PROTECT in the morning and finds that endpoint protection was disabled or settings changed (likely through an XDR alert, kicking off an incident response).

False positives can happen, but in the case of ESET technology, that is less of a concern, thanks to our track record of regularly realizing the lowest rate of false positives amongst all tested vendors. Hence it is always better to heed the warnings of the endpoint protection platform itself rather than the page you are browsing or the software you are trying to install – always keep your protection enabled.

ESET’s anti-tampering technologies

At ESET, we strive to offer the best product we can, and this has been true for years, as our over 30-year-long cybersecurity history suggests. Anti-tampering functionality has been among our best tools in combating hacking attempts for several years now. It has been over a decade since we introduced several technologies to protect our software from being tampered with – one of the first vendors to do so, in fact.

The most important anti-tampering feature that customers need to be reminded about is setting a strong password/passphrase to protect their settings. Critically, customers should prioritize this step as it pays big dividends toward achieving ultimate protection.

Tech-wise, ESET uses core technologies modules including HIPS and Self-Defense, among others, to deliver self-defense across its products to prevent exploitation of memory corruption vulnerabilities or to block executable code from launching where it is not supposed to. These join trust certificates and other technologies and strategies to limit manipulation of our product.

The above modules work in concert with ESET Anti-Tampering technologies, including Protected Process Light, which controls and protects running processes from being infected by malicious code and possible exploitation by other potentially dangerous processes. Additionally, since the introduction of Windows 8.1 OS and higher, there is also ELAM, or Early Launch Anti-Malware, in the form of an opt-in driver, which helps anti-malware services by being launched as a protected service, only allowing trusted, signed code (Windows or anti-malware vendor signed) to load, as a built-in defense against code injection attacks.

These technologies are important since both malware and manual attackers will always focus on disabling the protection system first, even after attempting a remote login – disabling services for them is of utmost importance.

Testing confirms ESET’s anti-tampering chops

For any endpoint security solution, independent testing done by analysts is how a product receives professional/critical acclaim and certification proving its expert competence.

Regarding anti-tampering, ESET excelled in tests as far back as 2014 and 2015, when independent testing found ESET’s consumer offering 100% successful in preventing tampering attacks, a major milestone compared to the competition of 32 different vendors.

AV-Comparatives’ recent Anti-Tampering Certification Test results mark yet another feather in ESET’s cap – certifying ESET PROTECT Entry with the highest degree of approval while also affirming ESET’s continuous improvements of its anti-tampering technologies, like our password protection for settings, which was the most relevant settings change that AV-Comparatives highlighted in their test.
*Users of ESET Protect Entry are by default also entitled to use ESET Protect Cloud, which can help admins save time and capacity.

For more information on ESET PROTECT Entry, and our full suite of cybersecurity solutions, visit https://www.eset.com/hk/business/protect-platform/

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Verizon 2023 DBIR 揭示 中小企業數據泄漏的關鍵與最佳安全策略

近日,Verizon 發布了最新的 2023 年數據泄漏調查報告(DBIR)。這份報告提供了關於全球數據泄漏事件的詳細分析,以及對中小企業的實用建議。以下是我們從報告中獲得的一些重要結論和中小企業應採取的安全措施。

一、數據泄漏事件仍然居高不下
根據報告顯示,數據泄漏事件在過去一年仍然頻繁發生。雖然大型企業經常成為攻擊目標,但中小企業也面臨著類似的風險。事實上,中小企業在這些事件中可能更容易受到傷害,因為它們通常缺乏足夠的資源和安全措施。因此,中小企業應該重視數據安全,並加強相應的防護措施。

二、內部威脅不容忽視
報告指出,內部威脅是數據泄漏事件中一個重要的因素。內部人員的意圖可能因各種原因而產生,包括不滿、報復或經濟利益等。中小企業應該建立良好的內部監控機制,並確保敏感數據只能被授權人員存取。

三、多重身份驗證是關鍵
多重身份驗證(MFA)被證明是保護數據安全的有效方法之一。報告建議中小企業應該採用 MFA,特別是對於關鍵系統和資源的存取。這樣可以大大降低被黑客入侵的風險。

四、數據加密是必要的
報告指出,大多數數據泄露事件發生時,受害者的數據並未加密。數據加密可以在數據被盜取後保護敏感信息的機密性。中小企業應該確保在儲存和傳輸數據時都進行加密,以防止未經授權的訪問。

五、員工教育與培訓
報告強調員工教育和培訓的重要性。中小企業應該提供相關的培訓,幫助員工識別釣魚郵件、惡意軟件和其他常見的安全風險。這樣可以提高員工的安全意識,減少社交工程攻擊的成功率。

Verizon 2023 DBIR 報告再次提醒我們,數據泄漏事件對中小企業依然構成嚴重威脅。中小企業應該重視數據安全,並根據報告中提供的建議採取相應的措施。加強數據保護、內部監控、多重身份驗證、數據加密和員工教育,將有助於提高中小企業的安全性,減少潛在的風險。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

Verizon 2023 DBIR 揭示 中小企業數據泄漏的關鍵與最佳安全策略

近日,Verizon 發布了最新的 2023 年數據泄漏調查報告(DBIR)。這份報告提供了關於全球數據泄漏事件的詳細分析,以及對中小企業的實用建議。以下是我們從報告中獲得的一些重要結論和中小企業應採取的安全措施。

一、數據泄漏事件仍然居高不下
根據報告顯示,數據泄漏事件在過去一年仍然頻繁發生。雖然大型企業經常成為攻擊目標,但中小企業也面臨著類似的風險。事實上,中小企業在這些事件中可能更容易受到傷害,因為它們通常缺乏足夠的資源和安全措施。因此,中小企業應該重視數據安全,並加強相應的防護措施。

二、內部威脅不容忽視
報告指出,內部威脅是數據泄漏事件中一個重要的因素。內部人員的意圖可能因各種原因而產生,包括不滿、報復或經濟利益等。中小企業應該建立良好的內部監控機制,並確保敏感數據只能被授權人員存取。

三、多重身份驗證是關鍵
多重身份驗證(MFA)被證明是保護數據安全的有效方法之一。報告建議中小企業應該採用 MFA,特別是對於關鍵系統和資源的存取。這樣可以大大降低被黑客入侵的風險。

四、數據加密是必要的
報告指出,大多數數據泄露事件發生時,受害者的數據並未加密。數據加密可以在數據被盜取後保護敏感信息的機密性。中小企業應該確保在儲存和傳輸數據時都進行加密,以防止未經授權的訪問。

五、員工教育與培訓
報告強調員工教育和培訓的重要性。中小企業應該提供相關的培訓,幫助員工識別釣魚郵件、惡意軟件和其他常見的安全風險。這樣可以提高員工的安全意識,減少社交工程攻擊的成功率。

Verizon 2023 DBIR 報告再次提醒我們,數據泄漏事件對中小企業依然構成嚴重威脅。中小企業應該重視數據安全,並根據報告中提供的建議採取相應的措施。加強數據保護、內部監控、多重身份驗證、數據加密和員工教育,將有助於提高中小企業的安全性,減少潛在的風險。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

Moving to Passwordless Login: 9 Key Considerations

Passwords have long been a weak link in the security chain. They can be easily guessed, stolen, or cracked through various malicious techniques. Passwordless login methods eliminate the reliance on passwords altogether, significantly enhancing security. By employing advanced technologies such as public-key cryptography, companies can implement strong authentication protocols that are resistant to brute-force attacks, phishing attempts, and credential stuffing. passwordless ssh portnox

Considering Passwordless Login? Here’s What You Need to Know…

When implementing passwordless login methods for network authentication, cybersecurity professionals should consider the following key factors:
I. Strong Authentication Protocols
Passwordless authentication should employ strong authentication protocols, such as public key cryptography. These protocols add an extra layer of security beyond just passwords and provide more robust protection against unauthorized access.
II. Secure Credential Storage
With passwordless login, sensitive credentials like private keys can be used. It is crucial to ensure secure storage of these credentials, either through encrypted cloud-based storage solutions or hardware-based security modules if necessary. Unauthorized access to these credentials could lead to serious security breaches.
III. User Experience and Adoption
Passwordless methods should be designed with a focus on user experience to encourage adoption. Complex or cumbersome authentication processes can result in user resistance or workarounds that compromise security. Balancing security and usability is crucial for successful implementation.
IV. Robust Identity Verification
Passwordless login should include robust identity verification mechanisms to ensure that the person requesting access is indeed the legitimate user. This can involve factors such as device attestation or contextual information like location or network patterns to establish trust.
V. Monitoring and Logging
It is essential to implement monitoring and logging mechanisms to track authentication events and detect any suspicious or malicious activities. Security professionals should have visibility into the authentication process to identify potential threats and respond promptly to security incidents.
VI. Continual Security Updates and Patches
Passwordless methods, like any other security solution, may have vulnerabilities that could be exploited by attackers. Vulnerability assessments should be conducted to ensure that the authentication system remains resilient against emerging threats. Cloud-native solutions can help eliminate the need for continuous patching, updating and general system maintenance.
VII. Backup and Recovery Mechanisms
Implementing passwordless login should also include considerations for backup and recovery mechanisms. In the event of system failures or credential loss, there should be processes in place to restore access securely and without compromising security.
VIII. User Education and Awareness
Introducing passwordless methods requires educating users about the new authentication methods, their benefits, and best practices. Users should understand the security implications, potential risks, and how to properly use and protect their credentials to maintain a strong security posture.
IX. Threat Modeling and Risk Assessment
Before implementing passwordless authentication, conducting a comprehensive threat modeling and risk assessment is critical. This helps identify potential threats, vulnerabilities, and risks associated with the chosen authentication methods and allows for the implementation of appropriate security controls.

The Future of the Passwordless Login Trend

As the workforce adopts new habits and technologies and cyber threats evolve in parallel, the adoption of passwordless login methods for security authentication is gaining momentum. By eliminating the weaknesses of traditional passwords, companies can enhance security, streamline user experience, and meet compliance requirements. Passwordless authentication provides a robust and convenient solution for organizations seeking to protect sensitive data, accommodate mobile workforces, and reduce the costs associated with password management. Embracing this innovative approach empowers companies to strengthen their security defenses, adapt to the changing work environment, and stay resilient in the face of evolving cyber threats.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

The OSINT Framework: How Hackers Can Leverage it to Breach Your Organization

In many ways, the open-source intelligence (OSINT) framework is a double-edged sword. On the one hand, it equips cybersecurity teams with a potent arsenal to detect vulnerabilities and strengthen their organization’s defenses. On the other hand, it also serves as a treasure trove for cybercriminals, enabling them to scan, probe, and breach vulnerable networks with remarkable efficiency. And to further complicate things, the remote work model, which has recently become the norm, only magnifies the risks and potential impact of OSINT-enabled attacks.

With freely available open-source data, malicious actors can often pinpoint and exploit unsecured and misconfigured systems while remaining obfuscated behind the anonymity of the digital world. Consequently, organizations are faced with a perpetual arms race, striving to stay one step ahead of the rapidly evolving cyber threat landscape.

With this in mind, recognizing threat actors’ tactics is paramount. This knowledge provides a solid foundation to fortify cyber defenses, ensuring robust protection of valuable data assets. So, let’s delve into the details of the OSINT framework and how hackers can leverage it to breach your organization.

What Is OSINT in Cybersecurity?

Open-source intelligence (OSINT) refers to the collection and analysis of publicly available data from various mediums like the internet, media, professional and academic publications, and government reports, among others. OSINT involves leveraging this publicly accessible information to identify potential vulnerabilities in systems and networks. It’s a powerful tool for both security professionals aiming to fortify defenses and cybercriminals seeking to exploit weaknesses.

For instance, a security analyst might use OSINT to identify outdated software or improperly configured servers, allowing them to rectify these issues. On the other hand, a cybercriminal could use OSINT to find weak points to launch an attack.

OSINT sources can range from social media posts revealing too much information about a network’s setup, to technical data found in online forums or databases detailing known vulnerabilities in certain software.

Critically, data is not automatically intelligence. Without proper context or analysis, open-source data remain unprocessed raw data. The transformation into intelligence happens when this data is critically analyzed.

For example, OSINT is more than just bookmarking a LinkedIn profile. It’s about extracting relevant, actionable details that can answer a specific intelligence question. It’s about asking, “what makes this data significant?” and delivering insightful intelligence based on the data gathered.

What is the OSINT Framework?

So we’ve covered open-source intelligence, but what is the OSINT framework specifically? Put simply, the OSINT framework is a collection of methodologies and open-source intelligence tools that make your intel and data-gathering tasks easier. The framework includes several stages, from identifying information needs, data collection, and analysis to presenting the findings.

How to Use the OSINT Framework

First, visit the OSINT framework website. You’ll notice a list of categories branching off from the OSINT framework, and by clicking on these branches, you can find tools and resources to help you with specific types of intelligence gathering.

Essentially, it’s your best resource for search engines, resources, and tools publicly available on the Internet.

However, it can also be confusing if you don’t know where to start. That’s the purpose of this post. To give you context on OSINT, how it works, and how both attackers and defenders leverage it to either keep our systems safe or launch ruinous attacks. Armed with this information, you should be better able to defend your networks from cybercriminals.

We’ll dive more into the specifics on how to use the OSINT framework in a later section.

To help you understand how to use the OSINT framework, let’s first dive into the specifics of open-source data gathering.

What are the Different Types of Open Source Data?

To extract valuable insights from data, you first need to know where to look. Open-source data comes in many forms. Much of it is already publically accessible, and the rest can often be obtained by request. OSINT sources can include:

  • Media reports, newspapers, and magazine articles: These can provide valuable insights into ongoing events, public sentiment, and trends. For example, a company may use them to learn about security breaches in their industry.
  • Academic papers and published research: These offer in-depth knowledge about specific topics. A cybersecurity professional could find a research paper detailing a new type of cyberattack or vulnerability.
  • Social media activity: This can reveal personal information, affiliations, behavior patterns, or even inadvertent disclosure of sensitive data. For instance, a hacker might identify a potential phishing target through social media.
  • Census data: This provides demographic details which can be used in threat modeling or understanding potential target audiences for social engineering attacks. For companies, it can provide valuable insights into which groups are likely to be targeted in future attacks.
  • Telephone directories: These can reveal contact information that could be used for spear-phishing or other targeted attacks.
  • Court filings and arrest records: These can provide information about legal disputes and criminal activities that might indicate potential vulnerabilities or targets.
  • Public trading data: This can offer insights into a company’s financial health, which might inform attack motivations.
  • Public surveys: These can reveal trends, public opinion, or other valuable data. They can also inadvertently expose sensitive information if not adequately anonymized.
  • Location context data: Information, like geotags, can disclose a person’s or device’s location, potentially revealing patterns or valuable details.
  • Breach or compromise disclosure information: This can help organizations understand how breaches occur and learn from others’ mistakes, while attackers may use it to replicate successful attacks.
  • Publicly shared cyberattack indicators like IP addresses, domains, or file hashes: These can help organizations identify potential threats and proactively protect their systems.
  • Certificate or Domain registration data: This information can reveal an organization’s online assets, which can be monitored for potential security issues.
  • Application or system vulnerability data: This is often found in public databases or forums detailing known vulnerabilities, which both attackers can use to exploit weaknesses and defenders to patch vulnerabilities.

How do Attackers Leverage OSINT?

As we’ve already touched on, both attackers (cyber criminals) and defenders (cybersecurity professionals) can use OSINT to further their own agendas. Here we’re going to be focusing on how attackers leverage OSINT.

Attackers increasingly leverage Open Source Intelligence to plan and execute cyberattacks. They use OSINT to gather information about potential targets, identify vulnerabilities, and plan their attack strategies. Here’s how:

Target Identification

Cybercriminals use OSINT to identify valuable targets. For example, they might mine social media platforms or professional networking sites like LinkedIn to find individuals with access to sensitive information.

Vulnerability Identification

Once they’ve identified a target, attackers use OSINT to find potential weaknesses. They could, for example, use data from public vulnerability databases, technical forums, or bug bounty platforms to learn about unpatched software vulnerabilities in the target’s infrastructure.

Attack Planning

OSINT also aids in planning attacks. Cybercriminals can use information from news articles, blog posts, or even the target’s disclosures to understand their security posture and technologies in use. This helps them select the most effective attack method.

Social Engineering Attacks

OSINT plays a crucial role in social engineering attacks. Threat actors might use information gleaned from an individual’s social media profiles, such as personal interests or travel plans, to craft convincing phishing emails.

Advanced Search Techniques – Google Dorks

Google Dorks, a technique used to refine search results, is another method cybercriminals employ for OSINT collection. By crafting specific search terms, threat actors can locate hard-to-find intelligence sources. For example, an attacker could combine “filetype:PDF” with the company’s domain name to find a list of all publicly available PDFs associated with that company. The results may contain PDFs that were inadvertently made publicly available due to misconfigured permissions.

Domain Analysis

Cybercriminals often use WHOIS databases to retrieve information about the owners, administrative contacts, and IP addresses associated with domain names. This data can help them craft spear-phishing attacks or locate potential points of entry into the network.

Geolocation Tracking

Information about a person’s whereabouts can also be used maliciously. Cybercriminals can analyze posts on social media platforms, such as vacation photos or check-ins, to determine when an individual or key company personnel are away, making it an optimal time to strike.

Infrastructure Analysis

Attackers can leverage network mapping tools like Shodan or Censys to discover exposed network services or Internet of Things (IoT) devices. These services and devices often have vulnerabilities that can be exploited for unauthorized access or to launch attacks. We’ll dive more into the specifics of OSINT tools later.

Code Repository Mining

Open-source code repositories like GitHub can be a gold mine for cybercriminals. Developers may leave sensitive information like API keys, passwords, or secret tokens in public repositories. Attackers can find this data and use it to gain unauthorized access to systems or services.

Competitor Analysis

Just as businesses use OSINT for competitive intelligence, so do cybercriminals. They may analyze breaches experienced by similar targets to learn about successful tactics and apply them in their own attacks.

Example of OSINT in Action

Suppose an attacker is targeting an employee at a technology firm. They might start by researching the employee on LinkedIn, finding out their role, the projects they’re working on, and who they report to. Then, they might look at the employee’s Twitter or Facebook feed, where they discover that the employee is attending a cybersecurity conference.

Using this information, the attacker crafts a phishing email. The email appears to come from the conference organizers, complete with a convincing logo and signature. It states that there’s a last-minute change to the schedule and asks the recipient to click on a link to see the updated information. In reality, the link leads to a malicious site designed to steal the employee’s login credentials.

This example illustrates how cybercriminals can use OSINT to make their phishing attempts highly personalized and convincing, increasing the chances that the recipient will fall for the scam.

How to Use the OSINT Framework – Empowering Cybersecurity Teams

OSINT is a powerful resource for cybersecurity teams. It allows for comprehensive and effective identification, prevention, and mitigation of cyber threats. Here’s how they can leverage OSINT to strengthen their organizations’ cybersecurity:

  • Identifying Vulnerabilities: Cybersecurity teams can use OSINT to discover vulnerabilities in their networks and systems. For example, companies can use information from forums, blogs, or databases detailing known software vulnerabilities to patch these weaknesses cybercriminals exploit them.
  • Threat Intelligence: By monitoring public data like social media, blogs, and forums, teams can identify emerging threats and trends. They can watch for mentions of their organization or relevant industry keywords, helping them anticipate potential attacks and respond proactively.
  • Employee Training: OSINT can reveal what kind of information about the organization and its employees is publicly available. This can inform employee training, teaching them about the risks of oversharing on social media or how to identify phishing attempts, as these often leverage publicly available information.
  • Supply Chain Security: OSINT can help monitor the digital footprint of supply chain partners. For instance, teams can watch for news of data breaches or public disclosures of vulnerabilities in their partners’ systems, helping them manage supply chain cyber risk.
  • Incident Response: In the event of a cyber incident, OSINT can help teams understand the nature of the attack. By comparing indicators of compromise like IP addresses, domain names, or file hashes with public databases, teams can identify the type of malware used or possibly even the attacker’s identity.
  • Competitor Analysis: Cybersecurity teams can use OSINT to learn from competitors’ experiences. They can analyze competitors’ breaches, understand how they happened, what their impacts were, and how they were mitigated, improving their organization’s readiness.
  • Predictive Analysis: By studying patterns in cyberattacks and breaches on a broader scale, teams can predict potential threats and take preventive measures.
  • Compliance Auditing: Organizations can use OSINT to ensure they’re not unintentionally disclosing sensitive data. Regular audits of publicly available information about the organization can ensure they comply with data protection regulations.

In a nutshell, OSINT serves as the eyes and ears of cybersecurity teams in the public sphere. By effectively leveraging it, you can transform raw data into actionable intelligence, strengthening your organization’s cybersecurity posture. It helps you stay one step ahead of the attackers.

While OSINT is a powerful tool, organizations should leverage it as part of a comprehensive cybersecurity strategy, complementing other tools and tactics such as secure architecture, Zero Trust, intrusion detection systems, regular patching, and employee training.

Dark Web OSINT

The dark web – a part of the internet not indexed by search engines – also plays a crucial role in OSINT, offering a peek into the cybercriminal underground.

The dark web houses various illicit activities, including hacking forums, black marketplaces, and encrypted communication platforms, making it a valuable source of information for cybersecurity professionals.

Tactical Threat Intelligence

Threat actors often share their tactics, techniques, and procedures (TTP) in dark web forums or marketplaces. These can provide insights into the latest attack strategies against specific industries or technologies. By monitoring these platforms, cybersecurity teams can anticipate potential threats and bolster their defenses accordingly. For example, if a particular type of ransomware is being discussed in relation to healthcare systems, security professionals can alert hospitals and clinics to strengthen their cyber defenses.

Initial Access Brokers

Initial access brokers are individuals or groups specializing in gaining unauthorized access to systems and then selling that access to the highest bidder. Here, intelligence can provide clues about specific corporate environments that may be under threat.

For example, if a cybersecurity team finds that cybercriminals are selling their organization’s access credentials, they can take immediate action, like initiating password resets and investigating potential breaches.

Operational Intelligence

The dark web is also a hub for trading stolen data and compromised devices. This can range from leaked credentials to infected devices for sale. By keeping an eye on these marketplaces, companies can identify if their data or devices have been compromised and take swift action.

For example, cybersecurity professionals can monitor sales of botnets – networks of compromised devices threat actors use for large-scale attacks like Distributed Denial of Service (DDoS). If they identify their systems within these botnets, they can immediately isolate and clean the infected systems, thereby disrupting the botnet’s operations and protecting their infrastructure. They can also share this intelligence with other organizations and law enforcement, assisting in the broader disruption of the threat actor’s operations.

Top OSINT Tools

There are plenty of OSINT tools out there, and the number is growing all the time. With this in mind, here we will focus on the top OSINT tools organizations can use to improve their cybersecurity.

Shodan

Shodan is a specialized search engine that allows users to discover Internet-connected devices worldwide. It indexes data from various devices, including webcams, servers, and routers. Unlike typical search engines that crawl websites, Shodan explores the internet’s infrastructure, revealing vulnerabilities and exposing potential security risks.

Maltego

A powerful data mining tool that aids in visualizing complex networks, Maltego allows users to easily map relationships and find patterns among various internet-based data points. These could be networks of individuals, organizations, websites, social media profiles, or other interconnected entities. The ability to map relationships in a graph format helps unveil hidden connections and patterns that might not be discernable from raw data.

Mitaka

An extension for browsers, Mitaka enhances OSINT capabilities by allowing users to scan and analyze highlighted texts for potential security threats or investigate cybercrime. Users can use Mitaka to scan selected text on a webpage for any signs of cyber threats, such as IP addresses associated with known malicious activities, hash values of potential malware, or even suspicious URLs.

SpiderFoot

An open-source intelligence automation tool, SpiderFoot collects and analyzes data about an IP address, domain name, or other related entities to aid in cybersecurity investigations. This can include details about an IP address, domain name, or network subnet.

BuiltWith

A web technology lookup tool, BuiltWith profiles and tracks what technology, including server software and analytics tools, websites across the internet are using. Users can discover what server software a website uses, the ad networks it participates in, the tracking widgets installed, or even the WordPress plugins used.

Metasploit

A widely-used penetration testing framework, Metasploit helps cybersecurity professionals perform vulnerability assessments, improve security awareness, and conduct rigorous penetration tests on their networks. Metasploit contains a vast collection of exploits and payloads that users can deploy against target systems to evaluate their security posture.

DarkSearch.io

DarkSearch.io serves as a gateway to the dark web, allowing users to perform safe searches across numerous .onion sites. It makes the dark web more accessible, revealing content typically hidden from standard search engines.

Spyse

A cybersecurity search engine, Spyse allows for thorough internet data reconnaissance by accumulating and indexing information about internet entities like IP addresses, domains, Autonomous System Numbers (ASNs), and even cryptographic certificates.

Google Dorks

Advanced search techniques using Google, Google Dorks help users to find specific information or expose potential vulnerabilities on websites that the regular Google search may not reveal.

Babel X

A comprehensive threat intelligence platform, Babel X sifts through multilingual data from the web, the dark web, and other sources to deliver actionable intelligence for security teams. By leveraging AI and machine learning, it can identify, categorize, and alert potential security threats in more than 200 languages.

Recon-n

An open-source reconnaissance framework with an interface similar to Metasploit. It provides a modular platform where different independent modules perform tasks like harvesting data from social media, querying network registries, or even detecting vulnerabilities.

Aircrack-ng

A comprehensive suite of tools for network security, Aircrack-ng enables users to monitor, attack, test, and crack Wi-Fi networks, assessing their vulnerabilities. It’s particularly renowned for its ability to break WEP and WPA-PSK keys, which allows it to identify weak points in a Wi-Fi network’s security.

Final Thoughts

Understanding OSINT tools and their potential for misuse is critical for maintaining organizational security. Attackers can leverage the same tools designed for securing systems to expose vulnerabilities and execute breaches. By familiarizing ourselves with the OSINT framework, we can anticipate potential threats and fortify our defenses, thereby keeping a step ahead of the perpetrators. Awareness and proactivity are our best defenses in an ever-evolving cyber threat landscape.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。