More mitigations
So like I said we are going over mitigations and I grabbed a couple slides and while this is not everything, I grabbed ones that helped to spark a thought process and understand how mitigation can be performed.
Now we started with SMB Relay because we were told its one of the most exploited vulnerabilities. Really until this slide I was thinking "if it's such a known vulnerability why is it still being used?" And seeing this slide with the pros and cons made me realize certain things need to be used and our job as security professionals can't be just to shut down everything that can be exploited but rather make things as safe as possible so that our companies can still be as productive as possible while being as safe as possible.Now I always thought I knew strong passwords but in taking this course I found out just how easy password cracking is. So, 14 or more characters and make it complex. Capital, Lowercase, Numbers, Special Characters, stay away from common words. I mean really is laziness a good excuse to allow an attacker into your systems.
Again here is another one where a strong password can make a difference as well as rotating.
This is one of the more difficult mitigation slides I feel like.
Account tiering and local admin, two important mitigation techniques that will save a lot.
Now I think the most important thing to realize is the reason learning these particular ones is so important is because these aren't some obscure attacks someone had to spend hours researching and building a script for. These are all built into a company's OS and come standard. And the tools to manipulate them are a few keystrokes away for absolutely anyone to use.
Comments
Post a Comment