Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
Research
How to Analyze JavaScript Malware – A Case Study of Vjw0rm
Vjw0rm is a worm that spreads via USB drives and has RAT capabilities because it implements different commands transmitted by the C2 server. It establishes persistence on a machine by copying to the Startup folder and creating a Run registry entry. The malware drops a Java-based RAT called STRRAT, executed using the Java executable that can be found on the local computer or downloaded from a remote URL.
Research
Iran-Attributed Exploitation of Log4Shell Vulnerability
Executive Summary CISA and the FBI issued a joint advisory warning of ongoing exploitation of the Log4Shell vulnerability (CVE-2021-44228) on November 16. The advisory noted that an unspecified Iran-linked threat actor group had exploited the vulnerability during an intrusion into a Federal Civilian Executive Branch (FCEB) organization’s network earlier… Read More
Cyber Threat Intelligence
STRIKE Team
Webinars
Showcase your Strong Security Posture to be the Vendor of Choice
Learn more in this resource.
Press
SecurityScorecard Joins World Economic Forum Global Innovators Community
Recognized innovator will contribute to WEF’s Centre for Cybersecurity’s initiative to address systemic challenges, improve digital trust, and build cyber resilience.
Webinars
Show the Value of Your Security Program
Learn more in this resource.
メディア掲載
@IT Media: 一筋縄ではいかない「サプライチェーン攻撃」、専門家が語る4つの分類と対策
関連企業が攻撃されたり、ソフトウェアサプライチェーンの弱い部分が突かれたりする「サプライチェーン攻撃」が問題となっている昨今、企業はどんな対策を講じるべきなのか。サプライチェーン攻撃をはじめ、サイバーセキュリティ全般のコンサルティングを手掛けるニュートン・コンサルティングの内海良氏に話を聞いた。
Japanese
Webinars
Carve Through the Noise by Prioritizing the Most Critical Threats
Learn more in this resource.
Webinars
Taking Control of Your Security in Turbulent Times
Learn more in this resource.
Case Studies
Liquidnet Case Study
Liquidnet uses SecurityScorecard as a third-party management solution to quantify the security performance of their vendors, provide continuous monitoring and do both of those things without requiring an immense amount of manual time from Liquidnet’s team.
Infographic
CISO on the Shelf
It’s that time of year again! Be on the lookout for your organization’s CISO. This helpful security professional will be watching over every security move you make… so be on your best behavior because they’ll be reporting back to the CEO!
Webinars
A Deep Dive into Cyber Risk Quantification for Board Reporting
Learn more in this resource.
Blog
Hackers Are Using These 3 Techniques to Bypass MFA
Multi-factor authentication (MFA) is an essential security measure, but here are some frequently-used methods cyber-attackers leverage to bypass MFA.
Tech Center
Press
SecurityScorecard Empowers Customers to Maximize their Security Investments by Providing a One-Stop Shop with Dramatically Expanded Partner Marketplace
Discover how SecurityScorecard’s Marketplace has expanded by 80%, enhancing cybersecurity visibility and integration for trusted partner solutions.
Webinars
A Deep Dive Into Cloud Security Assessments
Learn more in this resource.
Blog
9 Steps to Mitigate Ransomware Attacks for Your Business
Ransomware attacks are a top concern for many businesses as the threat landscape expands. Follow these 9 steps to help mitigate the risk for your business.
Tech Center
Blog
Mobile Device Forensics: Challenges, Threats, & Solutions
Mobile device forensics can help you recover lost or deleted data, as well as investigate a potential mobile security breach. Learn more.
Tech Center
Webinars
Confident Data gives you Actionable Insights in our Q4 ’22 Release
Learn more in this resource.
Research
A Technical Analysis Of The Royal Ransomware
This malware encrypts files with the AES algorithm, either fully or partially. The extension of the affected files changes to “.royal”. Find out more in this technical analysis of the Royal Ransomware from SecurityScorecard’s Senior Malware Analyst, Vlad Pasca.
Webinars
Workshop: A Live Hunt for Malicious Activity Using Attack Surface Intelligence
Learn more in this resource.
White Papers
A Look Under The Hood: Data Powering Attack Surface Intelligence
In this white paper, understand how we collect the data that powers Attack Surface Intelligence and the tools we use.
Attack Surface Management
Research
KillNet Operations Against U.S. Targets Persist With Attempted Airport Website Attacks
Executive Summary In October, BleepingComputer reported that the websites of several airports were experiencing service disruptions after KillNet announced that it would target airports throughout the U.S. Researchers leveraged NetFlow data to identify traffic that may reflect a DDoS attack by KillNet. By consulting SecurityScorecard’s internal threat intelligence… Read More
Public Sector