Update: CrowdStrike's 2020 Global Threat Report is now available. Download the report to stay ahead of today's adversaries.
This year’s Global Threat Report: “Adversary Tradecraft and the Importance of Speed,” addresses the quickening pace and increasing sophistication in adversary tactics, techniques and procedures (TTPs) over the past year — and in particular, highlights the critical importance of speed in staying ahead of rapidly evolving threats.
Last year, we introduced the concept of “breakout time” — the window of time from when an adversary first compromises an endpoint machine, to when they begin moving laterally across your network. In this year’s report, we were able to provide a more granular examination of breakout time by clocking the average speed of major nation-state actors. The report compares the breakout speeds of Russia, China, North Korea, Iran, and the combined category of global eCrime actors. This and other unique insights in the report can help organizations advance their response objectives, depending on which adversary types they are most likely to encounter in the year ahead.
The report also makes clear — in spite of some impressive indictments against several named nation-state actors — their activities show no signs of diminishing. Throughout 2018, eCrime and nation-state adversaries collectively upped their game. A few examples:
- In diplomatic channels and the media, several nation-states gave lip-service to curbing their clandestine cyber activities, but behind the scenes, they doubled down on their cyber espionage operations — combining those efforts with further forays into destructive attacks and financially motivated fraud.
- eCrime actors demonstrated new-found flexibility, forming and breaking alliances and quickly changing tactics mid-campaign to achieve their objectives. The shifting currents of the underground economy — including the availability of new TTPs-for-hire and the fluctuating value of Bitcoin —
- We also witnessed an increased focus on “Big Game Hunting,” where eCrime actors combine targeted intrusions with ransomware to extract big payoffs from large enterprise organizations.
and explains the unique structure of the CrowdStrike® organization. With our dedicated teams, we focus on these complementary disciplines:
- Tracking and analyzing adversary activity though global intelligence-gathering and proactive hunting
- Developing and deploying groundbreaking new technologies to combat bad actors
- Delivering best-in-class incident response services directly to the victims of cyberattacks
Additional Resources
- Download the 2019 Global Threat Report.
- Read the press release.
- Join a webcast on the 2019 Global Threat Report.
- Learn more about the CrowdStrike Falcon® platform.
- Test CrowdStrike next-gen AV for yourself. Start your free trial of Falcon Prevent™ today.