Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Protect and detect to prevent the lateral attacker

by The Gurus
April 9, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

Tracking attackers and preventing their lateral movement across your network will help you better protect against persistent attacks.
 
Speaking with Donato Capitella, security consultant at MWR Infosecurity, he said that if an attack is successful it doesn’t mean game over, but if they compromise you they should not have access to everything in order to get to a target.
 
“We can try and make life harder or make it more painful by importing controls together,” he said. “You can have the best detection and intrusion prevention, but the two things need to go together.”
 
He said that with attacks enabled by spear-phishing, once an attacker gets into a workstation they exploit the privilege of the user and will not do anything that is too suspicious, but will try to do “lateral movement” as the victim does not know where they are in the network, and explore file shares and other users.
 
He explained that once an attacker gets in, they should not have the opportunity to do more and if we can stop them, then they don’t make the news. “Most of the time they can move around laterally, making it very difficult to stop or detect them, which is what needs to be happening,” he said.
 
A common problem is that the activities between the compromise and malicious activity are difficult to detect if you don’t have the right infrastructure on your network to detect that. So if an attacker compromises the endpoint and needs to talk out, if there is outbound filtering implemented, then it is very difficult for the attacker to connect back to the machine.
 
“With a proxy there, the attacker needs to go through that and it makes it more difficult as they might have proxy logs that show the connection. So you slow them down and make them more detectable, and all security controls can be part of deploying secure builds,” he said.
 
Capitella said that there are technologies that will slow down an attacker providing more ways to detect them and the harder it is, the slower it will be for them. “By implementing security controls, you force the attacker down the path of least resistance and it becomes to easier to spot them,” he said.
 
“You are forcing them down that way; application whitelisting it is important for security and controls and an attacker needs to develop a zero-day and that is more expensive. It is not 100 per cent bulletproof, but it will stop some attackers and this makes it more difficult for skilled attackers and you have a better chance of detecting and monitoring what they are doing or stopping them immediately.”
 
I asked Capitella if he sees a lot of use of the outbound proxy, and he said that often clients deploy application whitelisting across the infrastructure, while removing privilege from regular users works well. “A control is taking away administrator privilege from the attacker as now they have to work without privilege escalation; if they are skilled they can do it, but you slow them down,” he said.
 
He also said that data loss prevention tools can be used too as part of the “mix”, and if you have to prioritise, implementing a good strategy for hardening and forcing attackers down the “difficult” path and detecting anomalies in configuration is the main thing.
 
I asked him for his recommendations on what companies can do to enable such hardened measures to prevent lateral movement of an attacker. He recommended having a holistic strategy for detection and prevention as much as you can, and consider adding: application whitelisting; taking away administrator privileges; segregate users and networks so it is more difficult for an attacker to strike; and patch everything, particularly on client side software.
 
“To accommodate for this, you need to work as best as you with detection and intrusion prevention systems and work to focus monitoring on the area of least resistance and that will help you in the process of using things to detect attackers,” he said.
 
 
 
Donato Capitella, security consultant at MWR Infosecurity, was talking to Dan Raywood Learn more about MWR Infosecurity’s training options here

Tags: attackDetectionPhishingPrevention
ShareTweet
Previous Post

Buhtrap campaign spied on and stole from Russian businesses

Next Post

French TV network taken offline by hackers

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol