3. APT attack detection methods
Detecting this type of attack is difficult, and requires multiple methods on several levels.
Quite often, detection comes from a source outside the company. For example, government agencies, private companies or CERT/CSIRT (Computer Emergency Response Team / Computer Security Incident Response Team) structures notify "victim" companies. In the course of their incident response, these structures may come across elements that point to other victims. This could be malware containing strings linked to other companies, or domain names close to company names, etc.
In the end, detecting APT incidents always comes down to two things:
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
APT attack detection methods