We’re all human: we make mistakes. Unfortunately, there will always be people trying to take advantage of our mistakes for their own benefit, which can cost our business tremendous financial loss. No matter how sophisticated our cyberdefenses are, how advanced our technologies are, how good our security practices are, we will always be constrained by this human factor.
Excellium services newsletter : Integrate the security in an Agile project using the Pushing Left approach
In this newsletter, we’ll cope with the Pushing Left approach. What is this approach? Why do we need it?
Excellium services newsletter : Deception technology, part II
In the first episode, we have seen what is deception technology. Let’s discover how to get started.
Excellium services newsletter : Deception technology, part I
The term Deception technology might be unknown or obscure to you, and that is perfectly normal considering it refers to one of the latest trend in the cybersecurity field. Its concepts are however quite intuitive and easy to understand, and based on other well-known technologies such as Honeypots.
Excellium services newsletter : Improper Machine Hardening Leading to Privilege Escalation
From an external or an internal perimeter, an attacker will look for weaknesses on the workstation or the server she just gained access. After web server breach in a DMZ or a workstation in the user LAN, her goal is to get access to other machines, to sensitive information that needs more authorization and accesses, taking advantage of machines weaknesses.
Most of the time, the local privilege escalation is a technique that pays off.
Excellium services newsletter : Threat Intelligence Demystified
Threat Intelligence (TI) is one of these new trendy words in the cybersecurity world. Many vendors offer their own solution of threat intelligence. In the present era of information, the challenge is finding the right solution on time. Sometimes it is like finding a needle in a haystack, but, luckily not always. And this is what TI is about, about going through huge amount of data to find relevant information and use it.
This newsletter will dive deep into the underlying issues of TI, and describes typical pitfalls usually encountered when learning to use it.
Excellium services newsletter : NIS Directive Review
The NIS (Network and Information System Security) Directive was adopted by the European institutions on 6 July 2016. Its objective is to guarantee a high and common level of security for networks and information systems within the European Union. In the context of this NIS Directive, several elements are highlighted. In addition to the emphasis on cooperation between national authorities and between Member States, the Directive also promotes the implementation of a national security strategy in each Member State of the European Union. The Directive also encourages the establishment of a European CSIRT network, again with the aim of improving cooperation between States. Security and notification requirements, in particular for essential service operators and digital service providers, are reinforced.
The main objective of the Directive is to ensure effective cooperation and protection of Member States’ critical economic and societal activities, in particular in order to protect themselves against the risk of cyber-attacks.
Excellium services newsletter : OSINT: Open Source Intelligence
The world of intelligence assessment is divided into multiple parts. For example, the SIGINT, or signal intelligence is the fact of collecting information or data via signals (Mobile network, Wi-Fi, radar, radio…). Another part is the HUMINT, for human intelligence. This part is related to information that can be extracted from human, with discussion for example.
This newsletter will deep dive into another part: the open source intelligence.
Excellium services newsletter : Office 365, Azure Active Directory and the Incident Response
Microsoft is the de facto leader when it comes to the enterprise infrastructure. Recently, we have seen an increasing number of companies shifting from on premises to cloud based solutions, entrusting Microsoft’s with their data but also the burden to manage their infrastructure. With Azure and Office 365, less assets are needed on premises, so the time and cost needed to administrate them is also reduced. Active Directory, Exchange, day-to-day applications (OneDrive, Skype for Business, Office …) are all manageable in the cloud with just a few clicks and the integration with Microsoft’s single-sign-on solution make them work seamlessly.
The promises are attractive, but how do you protect access to your business data? And what happens if an account is compromised, can you really assess the extent of a breach?