{"id":1295,"date":"2019-07-24T12:31:31","date_gmt":"2019-07-24T04:31:31","guid":{"rendered":"https:\/\/greycortex.hk\/?page_id=1295"},"modified":"2019-08-20T17:03:49","modified_gmt":"2019-08-20T09:03:49","slug":"use-case-malicious-insider-attack","status":"publish","type":"page","link":"https:\/\/greycortex.hk\/zh\/use-case-malicious-insider-attack\/","title":{"rendered":"Use Case &#8211; Malicious Insider Attack"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1295\" class=\"elementor elementor-1295\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7b0d884 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7b0d884\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fff738f\" data-id=\"fff738f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-53c01ba elementor-widget elementor-widget-heading\" data-id=\"53c01ba\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Malicious Insider Attack<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7a8f804 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7a8f804\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0dc140f\" data-id=\"0dc140f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-d38b3e5 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d38b3e5\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-2219b44\" data-id=\"2219b44\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3a8feb9 elementor-widget elementor-widget-text-editor\" data-id=\"3a8feb9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Industry:<\/strong><\/p><p>IT<\/p><p><strong>Entry Point:<\/strong><\/p><p>Insider Attack<\/p><p><strong>Objective:<\/strong><\/p><p>Company data theft\/revenge<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-870b873\" data-id=\"870b873\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-408b5df elementor-widget elementor-widget-text-editor\" data-id=\"408b5df\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Primary Detection:<\/strong><\/p><p>Advanced behavioral analytics<br \/>\u2022 Brute-force attack<br \/>\u2022 Network scanning<\/p><p>Network visibility<br \/>\u2022 New device in network<\/p><p><strong>Stolen Credentials Identified by:<\/strong><\/p><p>Active Directory Integration<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<div class=\"elementor-element elementor-element-2c8b8e4 elementor-widget elementor-widget-text-editor\" data-id=\"2c8b8e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>In an IT company, a disgruntled employee decided retaliate against his employer. As a developer, he had access into internal company systems, but was unable to access certain sensitive company information which he wanted. He took several suspicious actions within the network in order to hack into the data. He launched a scan for unsecured devices which could access the data he sought, then attempted a brute force attack to access those devices.<\/h5><h5>MENDEL identified these behaviors, both the network scan, and the brute force attack, as they happened and automatically alerted the security team. This attack was done using a private device and the credentials of another user. MENDEL identified the device as a standard feature, but through MENDEL\u2019s integration with Active Directory \u2013 available out of the box \u2013 the security team could identify the employee whose credentials were misused. After comparing the network behavior of the attacking device with the behavior of other users during the attack, the list of suspects was narrowed down. After short investigation, the employee was identified and immediately terminated.<\/h5><h5>Employee attacks can have devastating eff ects on company data, reputation, and revenue. But like advanced threats, employee attacks involve anomalous behavior within the network. This behavior was easily detected by MENDEL, allowing the security team to stop the attack before it could do damage.<\/h5>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6a47f24 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6a47f24\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-14e14f7\" data-id=\"14e14f7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ff2f7d0 elementor-widget elementor-widget-image\" data-id=\"ff2f7d0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"254\" height=\"300\" src=\"https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?fit=254%2C300&amp;ssl=1\" class=\"attachment-medium size-medium wp-image-948\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?w=1594&amp;ssl=1 1594w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=254%2C300&amp;ssl=1 254w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=768%2C906&amp;ssl=1 768w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=868%2C1024&amp;ssl=1 868w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=600%2C708&amp;ssl=1 600w\" sizes=\"(max-width: 254px) 100vw, 254px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-f388703\" data-id=\"f388703\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-47259a9 elementor-hidden-desktop elementor-hidden-tablet elementor-widget elementor-widget-spacer\" data-id=\"47259a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-57cb5dc elementor-widget elementor-widget-heading\" data-id=\"57cb5dc\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">\u4f60\u6709\u4ec0\u9ebc\u554f\u984c\u55ce\uff1f<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-484e54b elementor-widget elementor-widget-text-editor\" data-id=\"484e54b\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;,&quot;_animation_delay&quot;:200}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\u8acb\u7559\u4e0b\u60a8\u7684\u806f\u7d61\u65b9\u5f0f\uff0c\u4ee5\u4fbf\u6211\u5011\u6839\u64da\u60a8\u516c\u53f8\u7684\u9700\u6c42\u63d0\u4f9b\u500b\u6027\u5316\u7684\u670d\u52d9\u3002<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-b6bed35 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b6bed35\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-77b0c11\" data-id=\"77b0c11\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-fe814cb\" data-id=\"fe814cb\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Malicious Insider Attack Industry: IT Entry Point: Insider Attack Objective: Company data theft\/revenge Primary Detection: Advanced behavioral analytics\u2022 Brute-force attack\u2022 Network scanning Network visibility\u2022 New device in network Stolen Credentials Identified by: Active Directory Integration In an IT company, a disgruntled employee decided retaliate against his employer. As a developer, he had access into internal [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-templates\/fullwidth-content.php","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"footnotes":""},"class_list":["post-1295","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/PaZ0Rf-kT","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1295","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/comments?post=1295"}],"version-history":[{"count":22,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1295\/revisions"}],"predecessor-version":[{"id":2018,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1295\/revisions\/2018"}],"wp:attachment":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/media?parent=1295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}