During a routine security audit, an incident handler observes that several software developers in a research division were redirected to a compromised third-party technical discussion forum they frequently visit. The compromised forum silently downloaded a malicious browser extension to harvest API tokens used in the company's continuous integration pipeline. Which of the following social engineering techniques best describes this initial access vector?
- Watering hole attackCevap
- BSpear phishing
- CTyposquatting
- DInfluence principle of social proof
Cevap
Watering hole attack
A watering hole attack occurs when an adversary anticipates the web resources a specific target group frequents, compromises one or more of those websites, and uses them to infect visitors from the target organization.
Adım Adım Çözüm
Anahtar Kavram
Watering Hole Attack Identification
Tahmini Süre:1m 15s