Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Boards are from Mars, CISOs are from Venus

Ebook

Boards are from Mars, CISOs are from Venus
Learn more in this resource.
A Deep Dive Into A Posh C2 Implant

Research

A Deep Dive Into A Posh C2 Implant
PoshC2 is an open-source C2 framework used by penetration testers and threat actors. It can generate a Powershell-based implant, a C#.NET implant that we analyze in this paper, and a Python3 implant.
SecurityScorecard Announces Significant Momentum in 2022, Growing by 49%

Press

SecurityScorecard Announces Significant Momentum in 2022, Growing by 49%
SecurityScorecard now delivers Security Ratings, Response, and Resilience Solutions and Services to 73% of Fortune 100 organizations.
ESXiArgs Ransomware Campaign Targets VMWare ESXi Vulnerability

Research

ESXiArgs Ransomware Campaign Targets VMWare ESXi Vulnerability
Executive Summary On February 3, European hosting providers and computer emergency response teams (CERTs) began warning of a widespread ransomware campaign exploiting CVE-2021-21974, a VMWare ESXi vulnerability for which a patch has been available since February 2021. Shortly after the warnings’ publication, SecurityScorecard developed an emergency informational… Read More
Cyber Threat Intelligence
Ransomware Attack Against U.S. Public Housing Authority Linked to Previous Attacks

Research

Ransomware Attack Against U.S. Public Housing Authority Linked to Previous Attacks
Executive Summary On January 3, local media reported that a major U.S. city’s housing authority had suffered a ransomware attack. The LockBit ransomware group, which has made false claims in the past, took responsibility for the incident. As of this publication, the housing authority has announced a disruption, but… Read More
Cyber Threat Intelligence
Public Sector
How brokers and MSSPs partner to reduce cyber risk and enhance cyber hygiene

Webinars

How brokers and MSSPs partner to reduce cyber risk and enhance cyber hygiene
Learn more in this resource.
Cyber Insurance
How brokers and MSSPs partner to reduce cyber risk and enhance cyber hygiene

Webinars

How brokers and MSSPs partner to reduce cyber risk and enhance cyber hygiene
Learn more in this resource.
Cyber Insurance
SecurityScorecard releases list of Killnet open proxy IP addresses

Blog

SecurityScorecard releases list of Killnet open proxy IP addresses
In the wake of Killnet’s latest DDoS attack on U.S. hospitals on January 30, SecurityScorecard has made its KillNet open proxy IP blocklist available to the public. This list is the product of the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team’s ongoing research into KillNet. We released this list to help organizations better defend themselves against KillNet and other groups like it by preventing traffic from exploitable assets. In this blog, we’ll explain how we developed this proxy list and our recommendations for preventing DDos attacks.
Cyber Threat Intelligence
A Detailed Analysis Of A New Stealer Called Stealerium

Research

A Detailed Analysis Of A New Stealer Called Stealerium
Learn more in this resource.
Cyentia Institute and SecurityScorecard Research Report: Close Encounters of the Third (and Fourth) Party Kind

Research

Cyentia Institute and SecurityScorecard Research Report: Close Encounters of the Third (and Fourth) Party Kind
Learn more in this resource.
Close Encounters of the Third- (and Fourth-) Party Kind: The Blog

Blog

Close Encounters of the Third- (and Fourth-) Party Kind: The Blog
Let’s dive deeper into some other insights that help us understand the true extent of exposure from third- and fourth-party relationships.
Supply Chain Cyber Risk
SecurityScorecard Research Shows 98% of Organizations Globally Have Relationships With At Least One Breached Third-Party

Press

SecurityScorecard Research Shows 98% of Organizations Globally Have Relationships With At Least One Breached Third-Party
In collaboration with The Cyentia Institute, SecurityScorecard research finds 98% of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years.
Close Encounters Of The Third And Fourth Party Kind

Research

Close Encounters Of The Third And Fourth Party Kind
Learn more in this resource.
大学共同利用機関法人 自然科学研究機構 岡崎3機関

事例

大学共同利用機関法人 自然科学研究機構 岡崎3機関
株式会社ネットワークバリューコンポネンツによる導入事例
Japanese
Enterprise Cybersecurity: What it is & Why it’s Important

Blog

Enterprise Cybersecurity: What it is & Why it’s Important
Having effective enterprise cybersecurity is more than having your employees create a password that isn’t their pet’s name—unless perhaps their cat’s name is at least 12 characters long, and a combination of upper- and lower-case letters and symbols. Whether it’s well-researched spearphishing attempts or bypassing MFA, threat actors have only… Read More
Tech Center
Live Attack Simulation: Uncover Ransomware in Real-Time [#1]

Webinars

Live Attack Simulation: Uncover Ransomware in Real-Time [#1]
Learn more in this resource.
Being Proactive with Security: Deep Dive into Tabletop Exercises

Webinars

Being Proactive with Security: Deep Dive into Tabletop Exercises
Learn more in this resource.
Addressing the Trust Deficit in Critical Infrastructure

Research

Addressing the Trust Deficit in Critical Infrastructure
Global Cybersecurity Risk Measurement and Transparency are Key Despite a decade or more of increased focus on cybersecurity in boardrooms, legislatures, and the media, cyber resilience is getting worse, not better. Increasing cyberattacks and highly publicized breaches have undermined the public’s trust in the resilience of our societies, prompting business… Read More
SecurityScorecard Research Finds 48% of Global Critical Manufacturing At Significant Risk of Breach

Press

SecurityScorecard Research Finds 48% of Global Critical Manufacturing At Significant Risk of Breach
SecurityScorecard research finds 48% of global critical manufacturing is at a significant risk of breach; addressing trust deficit is key.
Cyber Threat Intelligence
Cyber Risk Intelligence: LockBit 3.0 Ransomware Group Claims Defense Contractor Breach

Research

Cyber Risk Intelligence: LockBit 3.0 Ransomware Group Claims Defense Contractor Breach
Executive Summary On December 2, the LockBit 3.0 ransomware group claimed to have exfiltrated data from a major defense contractor, and threatened to leak stolen files; however, as of December 13, the supposed victim no longer appears on LockBit 3.0’s data leak site. Following the claim, the SecurityScorecard… Read More
Attack Surface Management
Cyber Insurance
Cyber Threat Intelligence
Cyber Risk Intelligence: LockBit 3.0 Ransomware Group Claims Defense Contractor Breach

Research

Cyber Risk Intelligence: LockBit 3.0 Ransomware Group Claims Defense Contractor Breach
Executive Summary On December 2, the LockBit 3.0 ransomware group claimed to have exfiltrated data from a major defense contractor, and threatened to leak stolen files; however, as of December 13, the supposed victim no longer appears on LockBit 3.0’s data leak site. Following the claim, the SecurityScorecard… Read More
Attack Surface Management
Cyber Insurance
Cyber Threat Intelligence