BH ASIA 2023内鬼数据安全解决方案
作者从三个方面定义一个数据外发的异常信号。
数据量。哪个员工比平常更多的上传和下载
文件性质。哪些文件包含敏感数据
方向。哪些员工把数据存到了他们的个人云盘
VMware’s Carbon Black Managed Detection and Response (MDR) team began seeing a surge of TrueBot activity in May 2023. TrueBot, otherwise known as Silence.Downloader has been seen since at least 2017. TrueBot is under active development by Silence, with recent versions using a Netwrix vulnerability for delivery. In this article, we will break down what … Continued
The post Carbon Black’s TrueBot Detection appeared first on VMware Security Blog.