Skip to main content
  • Book
  • © 2018

Privileged Attack Vectors

Building Effective Cyber-Defense Strategies to Protect Organizations

Apress
  • Explains all vectors used in privileged attacks from passwords to exploits

  • Describes the attack chain and how privileged access management protects against and detects privileged attacks

  • Outlines use cases and methodology for deploying a success privileged access management program within an organization

Buy it now

Buying options

eBook USD 19.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Other ways to access

This is a preview of subscription content, log in via an institution to check for access.

Table of contents (24 chapters)

  1. Front Matter

    Pages i-xxvii
  2. Privileges

    • Morey J. Haber, Brad Hibbert
    Pages 1-23
  3. Shared User Credentials

    • Morey J. Haber, Brad Hibbert
    Pages 25-38
  4. Password Hacking

    • Morey J. Haber, Brad Hibbert
    Pages 39-48
  5. Password Less Authentication

    • Morey J. Haber, Brad Hibbert
    Pages 49-52
  6. Privilege Escalation

    • Morey J. Haber, Brad Hibbert
    Pages 53-68
  7. Insider Threats

    • Morey J. Haber, Brad Hibbert
    Pages 69-73
  8. Threat Hunting

    • Morey J. Haber, Brad Hibbert
    Pages 75-78
  9. Data-Centric Audit and Protection

    • Morey J. Haber, Brad Hibbert
    Pages 79-82
  10. Privileged Monitoring

    • Morey J. Haber, Brad Hibbert
    Pages 83-89
  11. Privileged Access Management

    • Morey J. Haber, Brad Hibbert
    Pages 91-106
  12. PAM Architecture

    • Morey J. Haber, Brad Hibbert
    Pages 107-118
  13. Break Glass

    • Morey J. Haber, Brad Hibbert
    Pages 119-130
  14. Industrial Control Systems (ICS)

    • Morey J. Haber, Brad Hibbert
    Pages 131-137
  15. Internet of Things (IoT)

    • Morey J. Haber, Brad Hibbert
    Pages 139-142
  16. The Cloud

    • Morey J. Haber, Brad Hibbert
    Pages 143-155
  17. Mobile Devices

    • Morey J. Haber, Brad Hibbert
    Pages 157-161
  18. Ransomware

    • Morey J. Haber, Brad Hibbert
    Pages 163-165
  19. Secured DevOps (SDevOps)

    • Morey J. Haber, Brad Hibbert
    Pages 167-169
  20. Regulatory Compliance

    • Morey J. Haber, Brad Hibbert
    Pages 171-188

About this book

See how privileges, passwords, vulnerabilities, and exploits can be combined as an attack vector and breach any organization. Cyber attacks continue to increase in volume and sophistication. It is not a matter of if, but when, your organization will be breached. Attackers target the perimeter network, but, in recent years, have refocused their efforts on the path of least resistance: users and their privileges.

In decades past, an entire enterprise might be sufficiently managed through just a handful of credentials. Today’s environmental complexity means privileged credentials are needed for a multitude of different account types (from domain admin and sysadmin to workstations with admin rights), operating systems (Windows, Unix, Linux, etc.), directory services, databases, applications, cloud instances, networking hardware, Internet of Things (IoT), social media, and more. When unmanaged, these privileged credentials pose a significant threat from external hackers and insider threats.

There is no one silver bullet to provide the protection you need against all vectors and stages of an attack. And while some new and innovative solutions will help protect against or detect the initial infection, they are not guaranteed to stop 100% of malicious activity. The volume and frequency of privilege-based attacks continues to increase and test the limits of existing security controls and solution implementations.

Privileged Attack Vectors details the risks associated with poor privilege management, the techniques that hackers and insiders leverage, and the defensive measures that organizations must adopt to protect against a breach, protect against lateral movement, and improve the ability to detect hacker activity or insider threats in order to mitigate the impact. 

What You’ll Learn

  • Know how identities, credentials, passwords, and exploits can be leveraged to escalate privileges during an attack
  • Implement defensive and auditing strategies to mitigate the threats and risk
  • Understand a 12-step privileged access management Implementation plan
  • Consider deployment and scope, including risk, auditing, regulations, and oversight solutions
Who This Book Is For

Security management professionals, new security professionals, and auditors looking to understand and solve privileged escalation threats


Authors and Affiliations

  • Heathrow, USA

    Morey J. Haber

  • Carp, Canada

    Brad Hibbert

About the authors

Morey Haber has 20+ years of IT industry experience. He joined BeyondTrust in 2012 as a part of the eEye Digital Security acquisition and overseas strategy for both vulnerability and privileged access management. In 2004, Morey joined eEye as the Director of Security Engineering and was responsible for strategic business discussions and vulnerability management architectures in Fortune 500 clients. Prior to eEye, he was a Development Manager for Computer Associates, Inc. (CA), responsible for new product beta cycles and key customer accounts. Morey began his career as a Reliability and Maintainability Engineer for a government contractor building flight and training simulators.

Brad Hibbert has 20+ years of experience in product strategy and management. He leads BeyondTrust’s solution strategy and development. He joined BeyondTrust via the company’s acquisition of eEye Digital Security, where Brad led strategy and products. Under Brad’s leadership, eEye launched several market firsts, including vulnerability management solutions for cloud, mobile, and virtualization technologies. Prior to eEye, Brad served as Vice President of Strategy and Products at NetPro before its acquisition in 2008 by Quest Software. Over the years Brad has attained many industry certifications to support his management, consulting, and development activities. Brad has his Bachelor of Commerce, specialization in Management Information Systems, and MBA from the University of Ottawa.



Bibliographic Information

  • Book Title: Privileged Attack Vectors

  • Book Subtitle: Building Effective Cyber-Defense Strategies to Protect Organizations

  • Authors: Morey J. Haber, Brad Hibbert

  • DOI: https://doi.org/10.1007/978-1-4842-3048-0

  • Publisher: Apress Berkeley, CA

  • eBook Packages: Professional and Applied Computing, Professional and Applied Computing (R0), Apress Access Books

  • Copyright Information: Morey J. Haber and Brad Hibbert 2018

  • eBook ISBN: 978-1-4842-3048-0Published: 08 December 2017

  • Edition Number: 1

  • Number of Pages: XXVII, 247

  • Number of Illustrations: 1 b/w illustrations, 29 illustrations in colour

  • Topics: Security

Buy it now

Buying options

eBook USD 19.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Other ways to access