Advertisement

Privileged Attack Vectors

Building Effective Cyber-Defense Strategies to Protect Organizations

  • Morey J. Haber
Book

Table of contents

  1. Front Matter
    Pages i-xxxv
  2. Morey J. Haber
    Pages 1-10
  3. Morey J. Haber
    Pages 11-37
  4. Morey J. Haber
    Pages 39-64
  5. Morey J. Haber
    Pages 65-85
  6. Morey J. Haber
    Pages 87-98
  7. Morey J. Haber
    Pages 99-116
  8. Morey J. Haber
    Pages 117-125
  9. Morey J. Haber
    Pages 127-131
  10. Morey J. Haber
    Pages 133-137
  11. Morey J. Haber
    Pages 139-149
  12. Morey J. Haber
    Pages 151-171
  13. Morey J. Haber
    Pages 173-188
  14. Morey J. Haber
    Pages 189-202
  15. Morey J. Haber
    Pages 215-226
  16. Morey J. Haber
    Pages 227-232
  17. Morey J. Haber
    Pages 233-238
  18. Morey J. Haber
    Pages 239-250
  19. Morey J. Haber
    Pages 251-255
  20. Morey J. Haber
    Pages 257-284
  21. Morey J. Haber
    Pages 285-294
  22. Morey J. Haber
    Pages 295-304
  23. Morey J. Haber
    Pages 305-323
  24. Morey J. Haber
    Pages 325-334
  25. Morey J. Haber
    Pages 335-359
  26. Morey J. Haber
    Pages 361-365
  27. Morey J. Haber
    Pages 367-373
  28. Back Matter
    Pages 375-384

About this book

Introduction

See how privileges, insecure passwords, administrative rights, and remote access can be combined as an attack vector to breach any organization. Cyber attacks continue to increase in volume and sophistication. It is not a matter of if, but when, your organization will be breached. Threat actors target the path of least resistance: users and their privileges.

In decades past, an entire enterprise might be sufficiently managed through just a handful of credentials. Today’s environmental complexity has seen an explosion of privileged credentials for many different account types such as domain and local administrators, operating systems (Windows, Unix, Linux, macOS, etc.), directory services, databases, applications, cloud instances, networking hardware, Internet of Things (IoT), social media, and so many more. When unmanaged, these privileged credentials pose a significant threat from external hackers and insider threats. We are experiencing an expanding universe of privileged accounts almost everywhere.

There is no one solution or strategy to provide the protection you need against all vectors and stages of an attack. And while some new and innovative products will help protect against or detect against a privilege attack, they are not guaranteed to stop 100% of malicious activity. The volume and frequency of privilege-based attacks continues to increase and test the limits of existing security controls and solution implementations.

Privileged Attack Vectors details the risks associated with poor privilege management, the techniques that threat actors leverage, and the defensive measures that organizations should adopt to protect against an incident, protect against lateral movement, and improve the ability to detect malicious activity due to the inappropriate usage of privileged credentials. 

This revised and expanded second edition covers new attack vectors, has updated definitions for privileged access management (PAM), new strategies for defense, tested empirical steps for a successful implementation, and includes new disciplines for least privilege endpoint management and privileged remote access.

You will:

  • Know how identities, accounts, credentials, passwords, and exploits can be leveraged to escalate privileges during an attack
  • Implement defensive and monitoring strategies to mitigate privilege threats and risk
  • Understand a 10-step universal privilege management implementation plan to guide you through a successful privilege access management journey
  • Develop a comprehensive model for documenting risk, compliance, and reporting based on privilege session activity


Keywords

Privileged Access Management PAM Password Management Session Management Least Privileged Lateral Movement Privileged Escalation Vulnerabilities Cyber Threat Cybersecurity Information Security Infosec Exploits Administrator Root

Authors and affiliations

  • Morey J. Haber
    • 1
  1. 1.HeathrowUSA

Bibliographic information

Industry Sectors
Pharma
Finance, Business & Banking
Electronics
IT & Software
Telecommunications
Aerospace
Engineering