pwshub.com

Mandiant combats new threats posed by remote access tools

As technology advances, so too do cybersecurity threats, and a new point of vulnerability for companies could be remote access tools.

Nader Zaveri (pictured), senior manager of Mandiant incident response and remediation at Google Cloud, estimates that 10% of the company’s investigations involved remote management tool abuse last year and anticipates further growth.

Nader Zaveri, senior manager of Mandiant incident response at Google Cloud, discusses the danger of remote access tools at mWISE 2024.

Mandiant’s Nader Zaveri talks about the dangers of remote access tools.

“We are starting to see threat actors utilize what we call remote access tools, RATs, or the industry properly terms them remote monitoring and management tools,” Zaveri said. “Threat actors are basically utilizing those tools to maintain persistence in organizations during their attacks and are able to laterally move throughout the environment. So, they’re just piggybacking off of already existing tool sets in the environment or just going inside and downloading their own thing. So, we want to call that out and highlight it because we’re starting to see it all over.”

Zaveri spoke with theCUBE Research’s John Furrier and Savannah Peterson at mWISE 2024, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed the complexities of remote access tools and how companies can protect themselves. (* Disclosure below.)

Ratting out remote access tools with AI

Mandiant combats what Zaveri calls “weaponized convenience,” a term for when threat actors use existing tools to infiltrate a company’s network. Cybercriminals may also use tools that are not approved but are not actually blocked by the company’s detection and response system. However, there are still ways to identify an attack.

“The way we identify a lot of threat actors, we try to cluster them based off of the different ways, what we call TTPs, different tools, techniques and procedures, how they maneuver, what different tooling they use as part of their mission,” Zaveri said. “After 10 years of seeing a constant pattern of the way, when they’re in an environment, they have these specific tools that they want to utilize. Maybe the tooling may change, but the overarching mission stays the same.”

Companies can protect themselves by blocking remote access tools that are not necessary for day-to-day operations. Mandiant is also using “red AI,” an artificial intelligence simulation of a cyberattack, to pinpoint weaknesses.

“What you can do is protect what you can control,” Zaveri said. “So, things like hardening the environment, ensuring you’re blocking the remote access capabilities of those tools … we actually put together a hunting script that can use in your environment, that you can scour your entire environment, and it’ll go through 50 or 60 different remote tools that we’ve seen threat actors utilize. With those tools, you can then start to block those that are not in your normal day-to-day administration.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE Research’s coverage of mWISE 2024:

(* Disclosure: Google Cloud Security sponsored this segment of theCUBE. Neither Google nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

Source: siliconangle.com

Related stories
1 day ago - Ransomware has quickly grown into a multi-billion-dollar industry, forcing a shift in how cybersecurity is approached, including the development of solutions such as Mandiant Threat Intelligence. In the last five years, as profits for...
1 month ago - Google LLC’s Mandiant has published details of a critical privilege escalation vulnerability found in Microsoft Corp.’s Azure Kubernetes service that, while having since been patched by Microsoft, could have allowed attackers to gain...
3 weeks ago - Industrial cybersecurity firm Nozomi Networks Inc. today announced the general availability of the Nozomi TI Expansion Pack, a new federated solution powered by Mandiant Threat Intelligence that helps strengthen the way industrial and...
2 days ago - Google Cloud today announced several new security features and an updated framework aimed at enhancing threat detection, identification and response, along with assisting companies in sharing threat intelligence and defending their...
3 hours ago - As cyberattacks become more sophisticated, advanced threat detection continues to play a critical role in safeguarding enterprise environments, particularly against long-standing threats with extended dwell times. Despite technological...
Other stories
57 minutes ago - Boeing said on Friday the head of its troubled space and defense unit is leaving the company immediately, in the first management change under new CEO Kelly Ortberg. Ortberg who took over in August said Ted Colbert would be leaving and...
57 minutes ago - Palantir Technologies, Inc. (NYSE:PLTR) co-founder, Joe Lonsdale, has expressed his support for Tesla and SpaceX CEO Elon Musk’s acquisition of Twitter, now rebranded as X. What Happened: On Thursday, while appearing on CNBC’s Squawk Box,...
1 hour ago - The European Commission is expected to bring formal charges against Google LLC over its business practices in the search market. Bloomberg revealed the upcoming regulatory action today, citing people familiar with the matter. Google...
2 hours ago - Nvidia has built a solid position for itself in this fast-growing data center niche that could help generate sizable revenue for the company in the long run.
3 hours ago - Qualcomm Inc. has approached Intel Corp. about a potential acquisition, the Wall Street Journal reported today. It’s believed that the mobile chip designer floated the idea in recent days. The Journal’s sources cautioned that a deal is...