Rapid7 Quarterly Threat Report: 2018 Q3

The Raw Threat Landscape, Incidents and Responses

Published November 2018

c

Recent months have seen attackers make good use of the exploits they’ve sown and infrastructure they’ve co-opted. The credential compromises and remote access attempts of Q2 ripened into suspicious service logins and lateral movement actions involving credentials, along with increases in the presence of malware on systems.

The quarterly threat reports cover three core areas:

1. What the raw threat event landscape looked like for our Managed Detection and Response customers (so you can get a feel for event types, volume, and velocity to compare against your own threat event logs).

2. How those raw threat events manifested into distilled/qualified incidents that required a response by security operations teams.

3. A review of the most critical internet-facing threats.