Easy

Trend Micro Collaboration -

College of Saint Benilde & Trend Micro Collaboration Event

Published October 30, 2025

So, you may be asking: What was this event about?

In this event, various topics were discussed:

  1. Cybersecurity Fundamentals
  2. Targets of Cyber Criminals
  3. Threat Tactics and Threats

What Did I Learn?

As a first year student, this event allowed me to refine my knowledge and understanding of concepts related to the field of Cybersecurity. With their hands on material and proper articulation, I was able to understand the concepts easily (despite my struggle to getting the hands-on material to work on my computer due to never actually using RDP on my Arch Linux laptop). (Yes, I’m an arch user btw.)

Lets start with the Cybersecurity fundamentals. One of the key takeaways for this topic that was that to them, the definition of Cybersecurity is but the practice of the CIA triad (Confidentiality, Integrity and Availability) towards information. While this was true, seeing their perspective on the definition allowed me to add onto my understanding of what the field was all about. It wasn’t just about hacking or defending a business’ assets, it’s about upholding the confidentiality, integrity, and availability of information.

Then we moved onto the topics of cybercriminals and their usual targets. They discussed 3 main targets: infrastructure, information and identity. The thing that Trend Micro loved focusing on was identity, which was the top target of cybercriminals. Think of the heavy amounts of data breaches that occur annually, containing plenty of PII (or personally identifiable information). They also expounded on the idea that identity can also be identified as the control plane, everything that YOU do at home, and is all of the info that is reliant on your information. In other words, it’s integral to not only our daily lives, but also that which controls it. Hence the reiteration of authentication as a part of you identity. Many companies nowadays include authentication, to ultimately uphold the validity that you are who you say you are with you providing something you know, have or ultimately, own.

The next and last topic that was discussed was Threat Tactics and Threats. This was the part that included the hands-on activity. This was my favorite part, as it allowed me to learn with actual immersion and simulation of an event, detailing every phase of the cyberkill chain: reconnaissance, weaponization, delivery, exploitation, installation, C2, and actions on objectives. While I did learn about this in my pursuit for NSE and CompTIA certifications, this did deepen my understanding of how threat actors function, and how they operate.

For the hands-on activity, we did a few things: assuming the attacker and host endpoints are within the same network and that a phishing link was sent and clicked on, we ultimately received an IP and some credentials. One of the first first things that we did was log into our simulated C2 server online. Here, it allowed us to send and receive Windows Powershell commands. The first goal we did was attempting to disable security tools to ensure and prevent them from detection malicious activities. Next was persistence, aimed at establishing a foothold through scheduled tasks or creating additional accounts. To further delive into the system’s network, we were also able to do network service scanning, further helping in network reconnaissance. Afterwards, we collected as much information and files as we could for the first vulnerable machine, and did lateral movement through accessing insecure credentials, viewing remote shares, reading file contents, and exfiltrating over C2 channels. The last thing we did was simulate a ransomware attack and encrypt all of the items within the vulnerable lab!

After the activity, we were then asked on how to defend against these type of attacks in the future. In my opinion, while I did have answers in my head on how to protect systems, I was too shy to stand up and recite.

Overall, this was truly fun, and I learned so much from just this collaboration! I just hope that next time, I’ll be able to actually contribute a thought towards a discussion, and I hope that I may continue to learn with pursuit for the purpose of securing the world.