Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Detection and response: what modern attackers changed for defenders


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: As malware volume scaled from tens of thousands of samples to millions, signature-based antivirus was swamped and attackers shifted to fileless techniques, lateral movement, ransomware, and supply chain compromise, according to SentinelOne. The lesson is that detection latency, asset visibility, and rapid containment now matter more than point-in-time prevention.

NHIMG editorial — based on content published by SentinelOne: a history of cyber security from worms to ransomware and the rise of detection

By the numbers:

Questions worth separating out

Q: What breaks when security teams rely on signatures to stop modern malware?

A: Signature-only defense breaks when attackers reuse trusted tools, mutate code, or switch to fileless execution.

Q: Why do lateral movement attacks matter more once an attacker gets inside?

A: Lateral movement turns a single foothold into a platform for broad compromise.

Q: How do security teams know whether detection and response are actually working?

A: They should measure how quickly suspicious activity is identified, contained, and investigated across endpoints, identity systems, and network paths.

Practitioner guidance

  • Harden internal movement paths Map the internal services and protocols that allow command execution or remote file access, then reduce exposure with segmentation, allow-listing, and protocol monitoring.
  • Instrument detection around runtime behaviour Collect endpoint and identity telemetry that shows execution chains, privilege changes, and abnormal parent-child process behaviour.
  • Treat supply chain trust as revocable Assume that signed updates, vendor tooling, and build-system dependencies can become attacker-controlled.

What's in the full article

SentinelOne's full analysis covers the operational detail this post intentionally leaves for the source:

  • Historical attack timelines for Morris, EternalBlue, WannaCry, and SolarWinds that show how tactics evolved over time
  • Product and solution context around endpoint protection and detection tooling that this post did not evaluate
  • Examples of how adversaries used fileless malware, macros, and PowerShell to bypass legacy controls
  • The vendor's own demonstrations and product tour content on visibility, forensics, and rapid recovery

👉 Read SentinelOne's history of cyber security from worms to ransomware →

Detection and response: what modern attackers changed for defenders?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Static prevention is no longer a sufficient governance model: this article shows that the defender's centre of gravity moved from blocking known files to observing behaviour across the runtime. Malware volume, fileless execution, and internal lateral movement all erode the value of point-in-time controls. For identity programmes, the same lesson applies to service accounts and tokens: if access is only reviewed periodically, it will be abused between reviews.

A question worth separating out:

Q: Who is accountable when ransomware reaches sensitive systems despite existing controls?

A: Accountability sits with the organisation's control owners, not with any single tool category. Security leaders should map responsibility across identity, endpoint, network, backup, and incident response functions, because ransomware succeeds when those controls are not orchestrated together. Frameworks such as NIST CSF and NIST SP 800-53 are useful for assigning that ownership.

👉 Read our full editorial: How cyber defense shifted from signatures to detection and response



   
ReplyQuote
Share: