Wednesday, May 30, 2018

Free tool - GeoLogonalyzer - From FireEye - Helps to weed out hackers exploiting stolen credentials to log into their targets.

Remember, this is NOT a replacement for best practices or existing protection.


Stolen enterprise user credentials are all the rage among hackers these days, but spotting the bad guys among legitimate users logging in remotely can be difficult

FireEye recommends several best practices for thwarting remote access hacks in addition to deploying GeoLogonalyzer,

  • Including limiting remote access from the Internet to sensitive data 
  • Instituting multi factor authentication using one-time tokens
  • Whitelisting legit IP address ranges for remote access users, 

among other steps.

Pointers  that can help you in your decision making

  1. Three things to know at any given point of time:
  2. What are you trying to protect
  3. What is the cost of  failure (to protect)
  4. Who is is your enymy
  5. What is the simplest and transparent way to protect
  6. What is the cost (money / time / resources)
  7. How do I monitor and generate valuable metrics





https://www.darkreading.com/analytics/fireeye-offers-free-tool-to-detect-malicious-remote-logins/d/d-id/1331923

No comments:

Post a Comment