Call us today on: +44 (0)203 88 020 88
SecureTeamSecureTeamSecureTeamSecureTeam
  • Home
  • Our Services
    • Infrastructure Testing
      • Internal Network Penetration Test
      • External Network Penetration Test
      • Wireless Network Penetration Test
      • Vulnerability Assessment
      • Network Segregation Test
      • Voice over IP (VoIP) Penetration Test
    • Application Testing
      • Web Application Penetration Test
      • Mobile Application Penetration Test
      • Desktop Application Security Assessment
      • Citrix Breakout Test
    • Configuration Review
      • Windows Server Build Review
      • Linux Server Build Review
      • Citrix Configuration Review
    • Information Assurance
      • ISO 27001 Gap Analysis
    • Cyber Essentials
  • News
  • Articles
  • About
    • About SecureTeam
    • STORM Appliances
      • Installing a STORM Device
      • Returning a STORM Device
    • White-Label Consultancy
    • Jobs
    • Cookie Policy
    • Privacy Notice
    • Website Terms & Conditions
  • Contact Us

Blog

Home Search results for "cyber security"

What are Web shell attacks?

By Mark Faithfull | Articles, Web Applications | 18 February, 2021 | 3

Web shell attacks have doubled over the last 6 months according to Microsoft’s Detection And Response Team.  But, what are Web Shell Attacks and how can you defend against them? In a recent blog post, Microsoft’s DART detailed the rise in Web Shell Attacks that have been uncovered in Windows Defender telemetry- growing from anRead more

What is HTML smuggling?

By Mark Faithfull | Articles, Information Assurance | 25 August, 2020 | 0

HTML smuggling is a technique for bypassing perimeter security devices by generating malicious HTML behind the firewall – within the browser on the target endpoint. HTML Smuggling techniques sidestep traditional network security solutions such as email scanners, proxies and sandboxes by using the features of HTML5 and Javascript.  This is done by generating the malicious HTMLRead more

What is network segmentation

By Mark Faithfull | Articles, Infrastructure | 7 August, 2020 | 1

Network segmentation is a powerful and essential tool in the security manager’s arsenal that improves the security of computer networks and makes them easier to manage.  Network segmentation provides protection against attackers who manage to breach the perimeter defences by limiting their ability to move laterally within the network. It can also protect key systemsRead more

What is a Next Generation Firewall?

By Mark Faithfull | Articles, Infrastructure | 24 July, 2020 | 0

What is a Next Generation Firewall and how can it help keep your network secure? The phrase ‘next generation firewall’ is increasingly being used by security vendors to describe their network security products. However, the definition of precise capabilities required to call a firewall next generation (or not) are far from universally agreed. This articleRead more

What is Security Awareness Training

By Mark Faithfull | Articles, Information Assurance | 17 June, 2020 | 0

Security Awareness Training is an essential component of any organisation’s information security. Even though it is mandated by frameworks such as PCI-DSS or ISO 27001, Security Awareness Training should be more than just a compliance exercise.  A good security awareness training programme will drive changes in behaviour amongst staff, suppliers and customers that will improveRead more

What is Mitre ATT&CK?

By Mark Faithfull | Articles, Information Assurance | 25 February, 2020 | 0

Mitre ATT&CK helps security managers defend their networks by providing a framework for categorising the techniques and tactics used in real world cyberattacks. Founded in 2013 in order to document the common threats, tactics and procedures used to attack Windows networks, Mitre ATT&CK has gathered data and telemetry on real world attacks which can beRead more

What is SIEM?

By Mark Faithfull | Articles, Information Assurance, Infrastructure | 20 January, 2020 | 2

Security Information and Event Management – SIEM – is the ability to collate and analyse events from across the network in real time in order to detect security incidents and attacks. Many organisations first encounter SIEM when it becomes a compliance exercise in order meet the requirements of a security framework such as PCI-DSS orRead more

What is fileless malware?

By Mark Faithfull | Articles, Information Assurance | 19 December, 2019 | 0

Fileless malware attacks have increased over 300% in 2019. What is fileless malware and how does it work? According to their mid-year Cybersecurity report, Trend Micro asserts that fileless malware attacks have increased 365% over the same period the previous year.  In order to understand why this is increasing and how fileless malware works, weRead more

The risks of nation state actors to your business

By Mark Faithfull | Articles, Information Assurance | 5 November, 2019 | 0

Reading about the latest hacks by alleged nation state sponsored groups from China or Russia may make for interesting lunchtime reading.  But do these groups pose a real threat to the typical business?  Many security managers ask themselves: Do I really need to worry about nation state actors? In this article, we will answer thatRead more

What is the cyber kill chain?

By Mark Faithfull | Articles, Information Assurance | 28 October, 2019 | 0

What is the cyber kill chain and how can it help shape your security policy? The idea of the cyber kill chain was first proposed by computer scientists at the defence contractor Lockheed Martin in 2011.  Given the background of the business, it is not surprising that their approach to defining a cyber-attack was heavilyRead more

123

Recent Posts

  • What is a pass the hash attack?
  • VMware patches critical RCE in vCenter Server
  • What is a dependency confusion attack?
  • What are Web shell attacks?
  • Critical Windows Fax Server Vulnerability Patched – and Why You Should Care

Tags

Android Apple Bluetooth Chrome Cisco credential stuffing cyber crime cyber essentials cyber security cyber security news Data Protection DDoS DNS Exchange Server exim fileless formjacking GDPR Intel IoT Linux MacOS Meltdown microsoft ncsc patching penetration testing phishing ransomware RDP security breach Security operations security testing SIEM software development Spectre supply chain attacks Sysinternals Tomcat TPM Unix vulnerability management web applications web browsers wireless

Archives

  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • July 2018
  • June 2018
  • April 2018
  • January 2018
  • October 2017
BCS Cyber Essentials Cyber Essentials Cyber Essentials PLUS ISO 9001 ISO 27001
information. secured.
  • Home
  • Our Services
    • Infrastructure Testing
      • Internal Network Penetration Test
      • External Network Penetration Test
      • Wireless Network Penetration Test
      • Vulnerability Assessment
      • Network Segregation Test
      • Voice over IP (VoIP) Penetration Test
    • Application Testing
      • Web Application Penetration Test
      • Mobile Application Penetration Test
      • Desktop Application Security Assessment
      • Citrix Breakout Test
    • Configuration Review
      • Windows Server Build Review
      • Linux Server Build Review
      • Citrix Configuration Review
    • Information Assurance
      • ISO 27001 Gap Analysis
    • Cyber Essentials
  • News
  • Articles
  • About
    • About SecureTeam
    • STORM Appliances
      • Installing a STORM Device
      • Returning a STORM Device
    • White-Label Consultancy
    • Jobs
    • Cookie Policy
    • Privacy Notice
    • Website Terms & Conditions
  • Contact Us
SecureTeam