Skip to main content

Research Examines Use of Credential Theft Foresight in Detecting and Preventing Predictable Cyber Security Risk

CyberArk released new research from CyberArk Labs introducing credential theft foresight as an effective approach to identifying network weak spots likely to expose privileged credentials to compromise

The report, “Predicting Risk: Credential Theft Foresight,” examines how privilege escalation can be detected and neutralized, and how future risk can be prevented. This approach enables organizations to minimize the attack surface and improve their overall security posture.

The research identifies “HotSpots” and “ColdSpots” as indicators of weak areas on a network that are likely to be attacked. Organizations have an average 5.5 HotSpots, which are areas predictably vulnerable to attack that act as bottlenecks for dozens of potential attack vectors, on their networks at any given time. They also have an average 37 ColdSpots, which are machines hosting privileged accounts that could be targeted by attackers in an attempt to escalate privileges.

The research details:

Credential theft foresight as a significant defensive advantage over traditional security tools like vulnerability scanners and intrusion detection systems
The multi-step process for identifying and mitigating HotSpots and ColdSpots
Two use cases in applying credential theft risk mitigation

To easily identify HotSpots in real time as they are created, CyberArk Labs also released a new tool – PreCog – that’s available now on GitHub: https://github.com/cyberark/PreCog.

CyberArk Labs researchers will be available at RSA Conference to discuss the research. They’ll also unveil new research in the RSA Conference session, “Sneak Your Way to Cloud Persistence – Shadow Admins Are Here to Stay,” on Thursday, April 19, at 9:15 a.m. PDT. To learn more, members of the CyberArk Labs team will be available at booth #4201. 

Additional Resources

Blog: Predicting Risk: Credential Theft Foresight
Research paper: Predicting Risk: Credential Theft Foresight
Research paper: CyberArk Labs: Kerberos Decryption
Research paper: CyberArk Labs: Pass-the-Hash Detection Using Windows Events

Comments

Popular posts from this blog

Cloud Computing powering India’s priority of ‘Digital-first country’

By: Sunil Mahale, India MD and VP, Nutanix
Digital transformation has been recognized as being vital to the growth of our nation. This transformation has enjoyed the unanimous approval and contribution from all stake holders including enterprises, MSMEs, government bodies and citizens. But this level of adoption in a country with a population of over a billion people would need a robust technology base that is capable to collecting and distributing vital data seamlessly.
Digital India envisions creating high speed digital highways, that will impact commerce and create a digital footprint for every individual. Technologies based on mobility, analytics, Internet of things and most importantly, cloud technologies are the building blocks for the digital India missionThere is a growing need to manage huge volumes of data, and making them readily available to public through digital cloud services. Cloud has a pivotal role in enabling this change.
While Data centers have become crucial to th…

RevStart launches its RevItUp Incubation Programme

Underlining its vision of creating a nurturing ecosystem for start-ups to grow in, RevStart, a co-working and incubation centre, has announced the launch of its RevItUp Incubation Programme. The 12-week long programme will be held at RevStart Incubation Centre in Noida from July 1, 2018 onwards. As part of the programme, RevStart will select five high potential start-ups from the ed-tech sector, AI, Consumer Internet, Sustainability, as well as for-profit social impact companies to assist them with developing their business, along with connecting them to global mentors across industries and sectors. In addition, start-ups selected for the programme will receive INR 5 lakh to Rs. 25 lakhs worth of cash and benefits, while RevStart will get an equity stake in the ventures.
The RevItUp Incubation Programme has been created to enhance the founding team’s industry, product, and company building knowledge and capabilities through a world-class curriculum. The programme will focus on tailor…

The Workplace of the Future

By: Arnab Ghosh – Director, Synergy Property Development Services)
Workplaces are undergoing a major transformation today to stay relevant. Conventional space planning and design approach for office space are slowly but steadily changing across the globe. What was a trickle a decade back is snowballing into a movement as we speak? The nature of the work we do and the time we spend in our workplace is driving this change. 
The Social Workplace The original office in the west was originally based on the factory floor design. The Workers occupied the maximum space followed by Managers and the Senior Executives in their glass cabins. The term “productivity” also has industrial roots. There were well-defined tasks and targets for the employees to achieve in their working time. All these have changed drastically over the last few decades and going to change further in the future. The culture of organizations has to adapt to this change to stay ahead and retain talent. Productivity is no long…