➡️Initial Access: CVE-2021-44077 exploited
➡️Execution: Web shell
➡️Credential Access: WDigest + MiniDump
➡️Lat Movement: RDP using Plink
➡️Exfiltration: Sensitive data exfilled
thedfirreport.com/2022/06/06/w...
➡️Initial Access: CVE-2021-44077 exploited
➡️Execution: Web shell
➡️Credential Access: WDigest + MiniDump
➡️Lat Movement: RDP using Plink
➡️Exfiltration: Sensitive data exfilled
thedfirreport.com/2022/06/06/w...
A free mini eBook for #DFIR professionals with practical steps to deploy, fine-tune, and start logging with Sysmon.
dfirinsights.com/2024/11/27/m...
#infosec #blueteam
A free mini eBook for #DFIR professionals with practical steps to deploy, fine-tune, and start logging with Sysmon.
dfirinsights.com/2024/11/27/m...
#infosec #blueteam