Cyber risk and advisory programs that identify security gaps and build strategies to address them.
MDR that provides improved detection, 24/7 threat hunting, end-to-end coverage and most of all, complete Response.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Be protected by the best from Day 1.
24/7 Threat Investigation and Response.
Expert hunting, research and content.
Defend brute force attacks, active intrusions and unauthorized scans.
Protect assets from ransomware, trojans, rootkits and more.
Intelligence and visibility across AWS, O365, DevOps and more.
Configuration escalations, policy and posture management.
Detects malicious insider behavior leveraging Machine Learning models.
Join Tiff Cook, eSentire's Sr. Director of Incident Response and Bill…
eSentire will be participating in ILTA LegalSEC Summit.
Join eSentire as they explore how to build a comprehensive training and…
On December 1, 2014, a blog regarding activity by a threat actor classified as “FIN4” was published by the Wall Street Journal. This article describes an active targeted phishing campaign with a focus specifically targeted at the emails of C-level executives, legal counsels, regulatory, risk, and compliance personnel, and other individuals who discuss confidentially and potentially market affecting matters.
The technique uses spear phishing emails to gather credentials from users and return them back to the Command and Control servers (CnC) where the login credentials are then used to log into the users' webmail remotely through TOR to escalate the attack. This threat activity was previously alerted on by eSentire in a communication sent to our clients and posted to our website on November 11, 2013. At that time eSentire began blocking these attacks for our clients proactively within the Asset Manager Protect Service (AMP) and have continued to watch for these indicators since.
The following recommended actions are effective security controls that you can implement locally to help protect your networks from this threat: