Shifting detection left for more effective ITDR
This is the second blog in our series looking at the ‘why’ behind the ‘what’ at Push. In this entry, we’re exploring the idea of shifting detection and response left in the face of modern identity attacks. As an industry, we’ve been conditioned to think about threat detection and response as something that happens post-compromise. Best practice has formed around resources like the Cyber Kill Chain and the MITRE ATT&CK Framework which focus on detecting indicators of an attacker presence on your network, and their behaviors and actions as they move through it. But with the shift to identity attacks, where attackers look to take over accounts on internet-facing apps and services, relying on an assumed compromise approach to detection is becoming less reliable. The most significant breaches of the last 12-18 months have been the result of identity attacks where an attacker has taken over an account, exfiltrated data… and that’s it. This change means that the typical methods of post-compro
This is the second blog in our series looking at the ‘why’ behind the ‘what’ at Push. In this entry, we’re exploring the idea of shifting detection and response left in the face of modern attacks. As an industry, we’ve been conditioned to think about threat detection and response as something that happens post-compromise. Best practice has formed around resources like the Cyber Kill Chain and the MITRE ATT&CK Framework which focus on detecting indicators of an attacker presence on your network, and their behaviors and actions as they move through it. But with the shift to identity attacks, whe
saved by
related reading
- Responding to Adversary in the Middle attacksinvictus-ir.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- Threat actors misuse OAuth applications to automate financially driven attacksmicrosoft.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- What Is Identity Threat Detection & Response (ITDR)? | Proofpoint USproofpoint.com
- Report: Identity Crisis: The Biggest Prize in Security | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Mediumblog.palantir.com
- The Newest Instagram "Exploit" is the Goofiest I've Seen0xsid.com