AttackIQ Blog

    IDC’s Top Insights Around Purple Teaming

    May 25, 2022
    Why adopt purple teaming? This IDC analyst brief explains how blending red and blue mindsets helps you holistically prepare for cyberattacks.
    Read More

    Computing Context is Everything

    May 23, 2022
    It’s January 14, 2020. Patch Tuesday.  Your CIO wants to know: “ How does that RDP vulnerability I saw in the news affect us? ” Well, which RDP vulnerability are you talking about, boss?”  Never mind; it’s still a good question. You dig deeper.
    Read More

    Quantifying Risks of Remote Workers

    May 23, 2022
    With everyone working from home and IT teams struggling to scale up their infrastructure, how are you accounting for risk?
    Read More

    Attack Graph Response to US-CERT AA22-108A: North Korean Targeting of Blockchain Companies

    May 10, 2022
    Read More

    Attack Graph Response to UNC1151 Continued Targeting of Ukraine

    April 29, 2022
    Uncover new attacks from a threat actor likely operating out of Belarus known as UNC1151 or Ghostwriter.
    Read More

    Integrations – Vectra

    April 18, 2022
    AttackIQ has released a new integration for use with network based scenarios. This blog describes use cases, scenarios one can utilize and what indicators we look for when determining a match.
    Read More

    5 Reasons You Don’t Want to Miss Purple Hats Conference 2022

    April 11, 2022
    The award-winning Purple Hats Conference is the industry destination for cybersecurity practitioners around the globe to collaborate, share ideas, and learn how to evolve cybersecurity strategies from a reactive to proactive threat-informed defense. We’re just days away from the best “cyberforum of the year” and you won’t want to miss it—and there’s still time to join. Here we’re breaking down for you five reasons you don’t want to miss Purple Hats.
    Read More

    Attack Graph Response to US-CERT AA22-083A: Historical Russia-based Actors Targeting the Energy Sector 

    April 1, 2022
    AttackIQ has released a new attack graph for organizations to test and validate their cyberdefense effectiveness against the HAVEX strain of malware. This attack graph follows a pair of Department of Justice indictments of Russia-based threat actors and a new joint FBI-CISA Cybersecurity Advisory about HAVEX released last week. An enduring and dangerous threat, HAVEX targeted the energy and power sectors in 135 countries from 2012-2018, and the tactics and techniques within it continue to threaten organizations today.
    Read More

    Testing Network Security Controls against Russian Malware 

    March 29, 2022
    Following an up-tick in the activity of Russia-based cyberthreat actors, this blog discusses the practical steps you can take to validate your network security controls against known Russian tactics, techniques, and procedures to improve your security readiness. It walks readers through Russia-specific emulations included in the AttackIQ Network Control Validation module.
    Read More

    Attack Graph Response to US CERT AA22-074A: Russia-based actors disabling multi-factor authentication (MFA)  

    March 18, 2022
    AttackIQ has released a new attack graph to emulate Russia-based threat actors as they exploit multi-factor authentication protocols to disable MFA. This blog describes the scenarios we have included in the new attack graph to emulate the adversary and then, to inform a purple team construct for cyberdefense operations, it provides detection and mitigation recommendations that you can use to improve your security program effectiveness. Read on for more.
    Read More

    Testing with Realism: Attack Flows and AttackIQ Attack Graphs  

    March 11, 2022
    AttackIQ and the Center for Threat-Informed Defense are furthering the art of adversary emulation with the Center’s new Attack Flow project. Building on our deep research partnership with the Center, AttackIQ’s Attack Graphs emulate the adversary with specificity and realism to test advanced cyberdefense technologies against multi-stage attacks. Read on for more.
    Read More

    Preparing for Known Russia-based Cyberthreats Using MITRE ATT&CK and AttackIQ

    March 8, 2022
    To prepare for a potential cyberattack from Russia-based actors, you can begin by testing your security controls against known adversary tactics. The vast majority of cyberattacks use tactics and techniques that have been employed in the past. This blog walks you through key known tactics and techniques, and highlights scenarios in the AttackIQ Security Optimization Platform that you can use today to test your defenses and improve your cybersecurity readiness.
    Read More

    Attack Graph Response to US-CERT AA22-011A & AA22-047A: Preparing for Russian State-Sponsored Cyberthreats

    February 24, 2022
    In anticipation of escalating cyberattacks by the Russian government against U.S. and allied interests, AttackIQ has developed a new attack graph to help organizations test and validate their cyberdefenses against known Russian adversarial tactics, techniques, and procedures (TTPs).
    Read More
    2021 Impact Report

    The Center for Threat-Informed Defense: Impacting the Public Good

    February 9, 2022
    The Center for Threat-Informed Defense is transforming the practice of cybersecurity and elevating security teams’ performance all over the world. This blog post looks at research highlights from Center’s retrospective 2021 Impact Report, explains why the Center is so important to us at AttackIQ, and shows security teams how to elevate their program performance using a range of free educational resources derived from the Center’s research.
    Read More

    Compliance and Cyber Security Risk Reduction Don’t have to be Enemies

    February 8, 2022
    How to design a Cyber Vulnerability Management program that maximizes the ROI of your team’s work to be compliant and maximize the reduction of business risk at the same time.
    Read More

    The trick to handling ransomware: prepare  

    January 19, 2022
    Ransomware is a vexing challenge and attacks have doubled since 2020, but there is a path out of the problem. In this new guide, Countering Ransomware with MITRE ATT&CK, AttackIQ outlines clear, practical steps to test and validate that your security program performs against ransomware. The trick is to prepare, and the path to follow is a threat-informed defense. Check it out and come join us for a technical demonstration of our ransomware capabilities on January 27.
    Read More
    Boards need to form a dedicated cybersecurity committee that can stay deeply engaged

    The Boardroom Isn’t Ready for the Next SolarWinds

    January 13, 2022
    Attacks like Log4j, SolarWinds and Colonial Pipeline have board rooms across the nation questioning their preparedness in combating cybersecurity risks. What can boards do now to be more effective for the next big attack?
    Read More
    Getting ahead of Log4Shell

    Getting Ahead of Log4Shell-enabled Cyberattacks: New Attack Scenarios and Technical Recommendations

    December 20, 2021
    Read More

    DeepSurface 2.7

    December 15, 2021
    We’re excited to announce the general availability of DeepSurface Risk Analyzer v2.7!  There are a ton of changes under the hood, but we wanted to let you know about a few key improvements.
    Read More
    Log4Shell

    Validate Your Cyberdefenses against Log4Shell with MITRE ATT&CK®

    December 13, 2021
    This article focuses on helping organizations to assess the effectiveness of their compensating controls, enable a threat-informed defense with breach and attack simulation plus the MITRE ATT&CK framework, and interdict the adversary post-breach to drive down risk.
    Read More

    A View of PrintNightmare Through the Lens of Prioritization

    November 29, 2021
    Now that the dust has settled around CVE-2021-34527, also known as PrintNightmare, we thought we’d use it as an example of how DeepSurface can reprioritize even the highest priority vulnerabilities, saving you and your patch team hours of effort.  For this blog post, you don’t need to know anything about PrintNightmare other than it was nearly ubiquitous, there are dozens of exploits in the wild, and that it’s fairly easy to remediate.
    Read More

    Announcing DeepSurface 2.6

    November 16, 2021
    We’re excited to announce the general availability of DeepSurface Risk Analyzer v2.6!  There are a ton of changes under the hood, but we wanted to let you know about a few key improvements.
    Read More
    CVE + Att&ck

    Prioritize and streamline vulnerability management through a threat-informed defense, with new research from the Center for Threat-Informed Defense and the MITRE ATT&CK framework as a foundation.

    October 29, 2021
    Read More

    10 Things You May Not Know About Purple Teaming 

    October 27, 2021
    We’re familiar with red teaming and blue teaming, but have you heard about purple teaming? This blog dives into facts you may not be aware of around this new team construct meant to foster collaboration between red and blue teams for a stronger cybersecurity practice.
    Read More