Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 12 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Beating the cyber criminals at their own game

by The Gurus
December 3, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

Beating the cyber criminals at their own game

By James Chappell, Chief Technology Officer and Co-Founder at Digital Shadows
The age of digital business has, for the most part, been positive. It has increased the ease and speed of communication while at the same time as reducing the cost. But with more than 3 billion individuals interacting across social media, mobile and cloud services every day it means that digital footprints are increasing. With this comes the increased risk that some of this information can be inadvertently exposed and may be used maliciously.
The information at risk, we refer to as a ‘digital shadow’. This is a subset of a digital footprint but consists of exposed personal, technical or organisational information that is often highly confidential, sensitive or proprietary. Adversaries can exploit these digital shadows to reveal weak points in an organisation and launch targeted attacks.
Adversaries cast a digital shadow too
A digital shadow is not necessarily a bad thing. Adversaries also cast a shadow similar to that of private and public corporations. These ‘shadows’ can be used to better understand the threat businesses face. This includes attacker patterns, motives, attempted threat vectors, and activities. Armed with this enhanced understanding, organisations are better able to assess and align their security postures.
The chief aim of cyber criminals is to make money. Tracking a digital shadow begins with this understanding. The anonymity offered by the ‘dark web’ is often (but my no means exclusively) used as a safe-haven by these criminals. By observing activity on the dark web it is possible to gain a better understanding of how cyber criminals behave. For instance, it’s possible to monitor what is being sold on online marketplaces and gain a view of the latest tools, such as attack kits which are being used and which vulnerabilities criminals are looking to exploit. This provides an attacker’s eye view of how these criminals might look at our own organisation and means we can be better positioned when it comes to our own security defences.
Learning from hacktivist groups
As stated, the so-called ‘dark web’ is not the only place where it’s possible to exploit the shadows of adversaries. With ‘hacktivist’ activity, for example, more typically uses social media such as Twitter and Facebook, and sharing sites such as Pastebin are used. Hacktivists tend to be more visible and easy to track because a primary motivation is to be heard and cause disruption and embarrassment. Their activity can be broken down into three main parts:

  1. Indication and warning – social media is a useful tool for monitoring hacktivist operational announcements. The use of operational hashtags, which are prevalent, aids this process. Groups will invariably provide operation names and specify target lists. If a hacking group name you on a target list, you are going to want to know.
  2. Evidence of attack – organisations should monitor for claims of defacements, DDoS attacks and breaches. This may occur on social media, often Twitter, but also on code-sharing sites such as Pastebin. Getting there first can help to reduce the reputational impact on your organisation. But it also helps from a historical view; understanding what tactics, techniques and procedures (TTPs) have used in the past help you to gauge how to best prioritise defence spending.
  3. Significant activity – Organisations can monitor social media and news sources for significant activity. While more mature organisations may use Activity Based Intelligence (ABI) to draw this information out, this approach need not be that complex. This approach may simply include observing arrests, reference to new techniques, declaration of links to other groups or actors.

Defence through understanding
The dark web can be a useful place to find out about the latest TTPs of cyber criminals, but firms should not underestimate the power of social media and sharing sites. These can provide a valuable insight into the activities, motivations and TTPs of attackers. Simply put, those who possess an understanding of these will be in a stronger position to defend themselves.

ShareTweet
Previous Post

Hackers Using Social Media to Execute Attacks

Next Post

UK’s top teenage code breakers battle it out in Cyber City games

Recent News

Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026
artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol