Phishing, spear phishing, and whaling
Not every fraudulent message looks suspicious. The most effective attacks use genuine context, pressure, and compromised communication channels.
Read the analysis →No fearmongering and no shortcuts. We explain how a threat works, which signals it leaves, and what individuals, administrators, and organizations can do.
Not every fraudulent message looks suspicious. The most effective attacks use genuine context, pressure, and compromised communication channels.
Read the analysis →Chaos is often the greatest threat during the first few minutes. Learn how to contain the impact without destroying evidence.
Read the procedure →An update, library, or service provider account can bypass defenses because the organization already trusts it.
Read the analysis →Searchable definitions provide a plain explanation, technical context, an example, and a basic protective measure. Terms are linked by category, making the full mechanism easier to understand.
Targeted phishing directed at people in key roles or those with broad privileges.
A vulnerability for which no effective patch or defense is available when it is exploited.
A distributed attempt to exhaust a service's resources using traffic from many sources.
Malicious software disguised as a legitimate or useful program.
A penetration test verifies whether defensive assumptions hold up within an agreed scenario and boundaries.
A brief description of the situation, scope, and expected outcome is enough to begin — no passwords or access credentials.