惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
L
LINUX DO - 最新话题
T
Troy Hunt's Blog
博客园_首页
量子位
Jina AI
Jina AI
S
SegmentFault 最新的问题
IT之家
IT之家
Hacker News - Newest:
Hacker News - Newest: "LLM"
大猫的无限游戏
大猫的无限游戏
N
News | PayPal Newsroom
P
Proofpoint News Feed
Cyberwarzone
Cyberwarzone
S
Securelist
Google Online Security Blog
Google Online Security Blog
P
Privacy International News Feed
博客园 - Franky
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
NISL@THU
NISL@THU
C
Cisco Blogs
V
Vulnerabilities – Threatpost
腾讯CDC
The Hacker News
The Hacker News
K
Kaspersky official blog
C
Cyber Attacks, Cyber Crime and Cyber Security
雷峰网
雷峰网
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Security Archives - TechRepublic
Security Archives - TechRepublic
A
About on SuperTechFans
Webroot Blog
Webroot Blog
The Register - Security
The Register - Security
Scott Helme
Scott Helme
B
Blog
Security Latest
Security Latest
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
W
WeLiveSecurity
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tenable Blog
Blog — PlanetScale
Blog — PlanetScale
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
Schneier on Security

Vectra AI Blog

Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Why You Need an NDR to Protect Your Modern Network Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI named in Gartner hype cycle for security operations 2025 Vectra AI Vectra AI Vectra AI How Sanofi Detected and Stopped a Cyberattack How MITRE ATLAS Helps Detect LLM Attacks in Cloud AI Detecting Iranian APT identity attacks across hybrid environments Vectra AI Vectra AI Vectra AI Breaking down the axios supply chain incident Vectra AI Vectra AI Who’s Doing What on Your Network? FortiClient EMS Zero-Day: When the Control Plane Becomes Initial Access Detecting Compromise After the Axios Supply Chain Attack. Vectra AI Vectra AI Vectra AI AI Is Now the Attack Surface: Why Your Security Stack Must Adapt Fast Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How attackers use Brute Ratel (BRC4) Vectra AI Vectra AI Vectra AI The Cutting Edge: AI’s Inevitable Rise in Offensive Security Vectra AI Vectra AI Is AI the Right Tool to Defend Against Modern Cyberattacks? Vectra AI Vectra AI Vectra AI Turns Out Network Security Is Cool Again – and It’s Called NDR Vectra AI Vectra AI Vectra AI Choosing the Right NDR: Gartner’s 5 Questions Every Security Buyer Should Be Asking Vectra AI Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Identity Threat Detection and Response (ITDR) Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI You Have the Right Tools. So Why Are Attackers Still Getting In? Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Challenges in Microsoft Log Monitoring: Insights for Your SOC Vectra AI Platform Visualizes Multi-domain Modern Attacks with Attack Graphs Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Gartner Security and Risk Conference – Chaos meets Opportunity Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Network Detection and Response (NDR) Presenting the 2025 Vectra AI Scholars Simplify Threat Investigation and Hunting with Pre-built Queries in Vectra Investigate The 2025 Gartner® Magic Quadrant™ for Network Detection and Response (NDR) - Why Vectra AI Stands Tall Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How Black Basta Turned Public Data into a Breach Playbook Play’s New Tactics Bypass Traditional Defenses. Are You Ready? Charting a New Era of Network Security: Vectra AI at the Forefront Unlocking Operational Efficiency: How Vectra AI Drives 40% Gains in SOC Performance and 391% ROI Identity-Centric Attacks: The New Reality for UK Retail CISA Flags Fast Flux as a National Threat: Are You Covered? AI Agents: What Do They Mean in Cybersecurity?
Vectra AI
Zoey Chu · 2025-12-02 · via Vectra AI Blog

For years, some tools have claimed that sending a TCP Reset (RST) is enough to stop an attacker. It sounds simple: if something suspicious happens, break the connection. But modern attackers don’t behave in ways a reset can control. TCP RST is unreliable, easily bypassed, and can even disrupt critical business services.  

Why TCP resets fall short

A TCP reset is like slamming a door in an attacker’s face. But modern attackers? They just open another door—instantly.

How? They can:

  • Ignore RST packets completely using a one-line firewall rule.
  • Use encrypted tunnels, VPNs, and proxies where resets can’t be injected.
  • Reconnect immediately from a new port or IP.
  • Leverage tools, like Cobalt Strike, Sliver, Metasploit, and Havoc, that are built to resist or bypass resets.

Even when resets do work, they risk collateral damage like corrupting applications or disrupting environments using critical protocols such as BGP. The bottom line: TCP resets don’t stop attackers. They just momentarily inconvenience them.  

By the time a reset is sent, the attacker may have already used the stolen credentials, moved laterally through your environment, established persistence, and accessed sensitive, business-critical data.  

Resetting a single connection is like shutting one door while the intruder is already inside the building, opening new ones as they go. You’re not stopping the attack; you’re playing whack-a-mole. Modern defenders need a way to lock every door at once and keep them locked.

Learn more about the limitations of TCP reset here: https://support.vectra.ai/vectra/article/KB-VS-2644

The modern solution: Vectra AI’s 360 Response

Vectra AI’s 360 Response replaces fragile packet resets with real, enforced containment across the layers attackers actually abuse, which are identity, device, and traffic. This gives defenders the ability to shut down attacker actions everywhere they try to move.

360 Response locks every possible door through:

  • Host Lockdown: Isolates compromised devices via EDR to stop lateral spread.
  • Account Lockdown: Disables or restricts compromised user accounts in AD or Entra ID.
  • Traffic Lockdown: Applies true firewall blocks that attackers cannot ignore, bypass, or reconnect around.

Instead of hoping a reset works, Vectra AI uses the customer’s authoritative enforcement tools to stop attackers decisively. Vectra’s AI detects the threat. 360 Response locks every door. The attacker loses control—and the defender regains it.

360 Response: from disruption to true control

TCP resets were never meant to stop cyberattacks, and today’s adversaries walk right through them. They can be ignored, bypassed, or nullified, and sometimes cause more harm than good. Vectra AI’s 360 Response delivers what resets never could: real, persistent containment that shuts down every path an attacker tries to take.