Share This:

From our sponsor

XDR ThreatsIn 2023, Barracuda XDR, including its team of SOC analysts on 24-hour watch, cut through nearly two trillion (1,640 billion) IT events to isolate tens of thousands of potentially high-risk security threats.

Security researchers have analyzed the most prevalent XDR detections for 2023. Their findings, summarized in this blog, show the most common ways attackers tried — and failed — to gain persistent access to networks through intruder activity. This includes business email compromise and using malicious code and exploits.

It’s important to note that defensive security technologies, including XDR, are designed to detect, notify, and block the enemy at the gate or in the early stages of an intrusion. The attacks are prevented from being carried out fully — and this means that we don’t always know what the final intended payload might have been, such as ransomware.

Overview of 2023: High-severity attack attempts increasing

High-severity detections during 2023 included 66,000 threats serious enough to be escalated to a SOC analyst for investigation, and a further 15,000 that required urgent and immediate defensive action. There was a steady rise in both threat categories throughout the year — peaking from October into November and December.

These months are the prime season for online shopping and festive holidays. Both factors are potentially highly attractive to attackers. The first because it offers a large pool of potential targets and opportunities. The second because it generally means IT teams are away from the workplace or less attentive.

There was a second, smaller, peak in June — which for many countries represents a key holiday month.

Together, these results reinforce the findings we first reported in 2022 — that attackers seize the opportunity of people being away, busy, or distracted to launch more damaging and high-risk attacks.

XDR Threats


Share This:
Merium Khalid

Posted by Merium Khalid

Merium Khalid is Director of SOC Offensive Security at Barracuda. Merium has extensive experience in analyzing data, identifying threats, incident response, research and development, and a lot more. Her team is responsible for leading Incident Response triage calls, building best-in-class use case detections through machine learning, static queries, researching, and implementing new platforms, and automation of workflow in efforts to protect their customers, providing best-in-class experience along with ensuring the SOC analyst experience is top notch. Merium received her bachelor’s degree in computer science from SUNY Old Westbury and has many years of experience leading and handling security operations.

14 Comments

  1. Mucho interesting and informative, thanks. 🙂

    Reply

  2. very good info, sharing to everyone in our company as a good reminder. thanks for the info

    Reply

  3. Interesting statistics. Very informative.

    Reply

  4. Matthew Hickman March 6, 2024 at 4:12 pm

    Barracuda XDR helped us catch a lot of potential attacks during the holidays. Not just with networks, but with email accounts too. Luckily though, we were able to track most items down to VPN users traveling for the holidays, but still, we were alerted and we love that ability.

    Reply

  5. Thanks for the insights! Always necessary to have real world statistics on cybersecurity to upsell and prioritize

    Reply

  6. Matthew Thompson March 7, 2024 at 3:28 am

    Very interesting, great information

    Reply

  7. We are going to incorporate some of this info into our MSP presentations. Referencing Barracuda of course.

    Reply

  8. Great insight! Everyone needs to be aware of the changes and developments in cybersecurity! Barracuda’s SOC is a game changer.

    Reply

  9. Great Inisght! We must be aware of these malicious attacks both on our customers as well as our own data! Barracuda SOC is a must!

    Reply

  10. Great recap of 2023! Thank you for sharing these insights!

    Reply

  11. very good article, covers a lot. The importance of XDR for small MSPs….

    Reply

  12. Very good info

    Reply

  13. Esteban Cubero May 3, 2024 at 6:20 pm

    Very interesting information and quite important.

    Reply

  14. Moss Jacobson May 16, 2024 at 8:47 am

    The sheer number of attacks is stunning – especially considering this is growing constantly at an alarming rate. And, I am convinced there is no other way to handle this without more effective use of technology like this.

    Reply

Leave a reply

Your email address will not be published. Required fields are marked *