Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

How to Analyze JavaScript Malware – A Case Study of Vjw0rm

Research

How to Analyze JavaScript Malware – A Case Study of Vjw0rm
Vjw0rm is a worm that spreads via USB drives and has RAT capabilities because it implements different commands transmitted by the C2 server. It establishes persistence on a machine by copying to the Startup folder and creating a Run registry entry. The malware drops a Java-based RAT called STRRAT, executed using the Java executable that can be found on the local computer or downloaded from a remote URL.
Iran-Attributed Exploitation of Log4Shell Vulnerability

Research

Iran-Attributed Exploitation of Log4Shell Vulnerability
Executive Summary CISA and the FBI issued a joint advisory warning of ongoing exploitation of the Log4Shell vulnerability (CVE-2021-44228) on November 16. The advisory noted that an unspecified Iran-linked threat actor group had exploited the vulnerability during an intrusion into a Federal Civilian Executive Branch (FCEB) organization’s network earlier… Read More
Cyber Threat Intelligence
STRIKE Team
Showcase your Strong Security Posture to be the Vendor of Choice

Webinars

Showcase your Strong Security Posture to be the Vendor of Choice
Learn more in this resource.
SecurityScorecard Joins World Economic Forum Global Innovators Community

Press

SecurityScorecard Joins World Economic Forum Global Innovators Community
Recognized innovator will contribute to WEF’s Centre for Cybersecurity’s initiative to address systemic challenges, improve digital trust, and build cyber resilience.
Show the Value of Your Security Program

Webinars

Show the Value of Your Security Program
Learn more in this resource.
@IT Media: 一筋縄ではいかない「サプライチェーン攻撃」、専門家が語る4つの分類と対策

メディア掲載

@IT Media: 一筋縄ではいかない「サプライチェーン攻撃」、専門家が語る4つの分類と対策
関連企業が攻撃されたり、ソフトウェアサプライチェーンの弱い部分が突かれたりする「サプライチェーン攻撃」が問題となっている昨今、企業はどんな対策を講じるべきなのか。サプライチェーン攻撃をはじめ、サイバーセキュリティ全般のコンサルティングを手掛けるニュートン・コンサルティングの内海良氏に話を聞いた。
Japanese
Carve Through the Noise by Prioritizing the Most Critical Threats

Webinars

Carve Through the Noise by Prioritizing the Most Critical Threats
Learn more in this resource.
Taking Control of Your Security in Turbulent Times

Webinars

Taking Control of Your Security in Turbulent Times
Learn more in this resource.
Liquidnet Case Study

Case Studies

Liquidnet Case Study
Liquidnet uses SecurityScorecard as a third-party management solution to quantify the security performance of their vendors, provide continuous monitoring and do both of those things without requiring an immense amount of manual time from Liquidnet’s team.
CISO on the Shelf

Infographic

CISO on the Shelf
It’s that time of year again! Be on the lookout for your organization’s CISO. This helpful security professional will be watching over every security move you make… so be on your best behavior because they’ll be reporting back to the CEO!
A Deep Dive into Cyber Risk Quantification for Board Reporting

Webinars

A Deep Dive into Cyber Risk Quantification for Board Reporting
Learn more in this resource.
Hackers Are Using These 3 Techniques to Bypass MFA

Blog

Hackers Are Using These 3 Techniques to Bypass MFA
Multi-factor authentication (MFA) is an essential security measure, but here are some frequently-used methods cyber-attackers leverage to bypass MFA.
Tech Center
SecurityScorecard Empowers Customers to Maximize their Security Investments by Providing a One-Stop Shop with Dramatically Expanded Partner Marketplace

Press

SecurityScorecard Empowers Customers to Maximize their Security Investments by Providing a One-Stop Shop with Dramatically Expanded Partner Marketplace
Discover how SecurityScorecard’s Marketplace has expanded by 80%, enhancing cybersecurity visibility and integration for trusted partner solutions.
A Deep Dive Into Cloud Security Assessments

Webinars

A Deep Dive Into Cloud Security Assessments
Learn more in this resource.
9 Steps to Mitigate Ransomware Attacks for Your Business

Blog

9 Steps to Mitigate Ransomware Attacks for Your Business
Ransomware attacks are a top concern for many businesses as the threat landscape expands. Follow these 9 steps to help mitigate the risk for your business.
Tech Center
Mobile Device Forensics: Challenges, Threats, & Solutions

Blog

Mobile Device Forensics: Challenges, Threats, & Solutions
Mobile device forensics can help you recover lost or deleted data, as well as investigate a potential mobile security breach. Learn more.
Tech Center
Confident Data gives you Actionable Insights in our Q4 ’22 Release

Webinars

Confident Data gives you Actionable Insights in our Q4 ’22 Release
Learn more in this resource.
A Technical Analysis Of The Royal Ransomware

Research

A Technical Analysis Of The Royal Ransomware
This malware encrypts files with the AES algorithm, either fully or partially. The extension of the affected files changes to “.royal”. Find out more in this technical analysis of the Royal Ransomware from SecurityScorecard’s Senior Malware Analyst, Vlad Pasca.
Workshop: A Live Hunt for Malicious Activity Using Attack Surface Intelligence

Webinars

Workshop: A Live Hunt for Malicious Activity Using Attack Surface Intelligence
Learn more in this resource.
A Look Under The Hood: Data Powering Attack Surface Intelligence

White Papers

A Look Under The Hood: Data Powering Attack Surface Intelligence
In this white paper, understand how we collect the data that powers Attack Surface Intelligence and the tools we use.
Attack Surface Management
KillNet Operations Against U.S. Targets Persist With Attempted Airport Website Attacks

Research

KillNet Operations Against U.S. Targets Persist With Attempted Airport Website Attacks
Executive Summary In October, BleepingComputer reported that the websites of several airports were experiencing service disruptions after KillNet announced that it would target airports throughout the U.S. Researchers leveraged NetFlow data to identify traffic that may reflect a DDoS attack by KillNet. By consulting SecurityScorecard’s internal threat intelligence… Read More
Public Sector