Explore >> Select a destination


You are here

www.deepinstinct.com
| | www.cybereason.com
2.0 parsecs away

Travel
| | Cybereason GSOC observed distribution of the Bumblebee Loader and post-exploitation activities including privilege escalation, reconnaissance and credential theft. Bumblebee operators use the Cobalt Strike framework throughout the attack and abuse credentials for privilege escalation to access Active Directory, as well as abusing a domain administrator account to move laterally, create local user accounts and exfiltrate data...
| | marcusedmondson.com
2.8 parsecs away

Travel
| | Today I wanted to talk about using the deception technology called New-HoneyHash.ps1. This is a tool that was inspired by Mark Baggett and authored by Matt Graeber, that will inject fake credentials into the lsass.exe process. This can be effective at finding attackers who are dumping the lsass process in your environment in order to...
| | adsecurity.org
1.4 parsecs away

Travel
| | [AI summary] The article discusses techniques for extracting credentials from Windows systems, focusing on dumping LSASS memory and Active Directory databases to compromise security.
| | www.dragos.com
30.3 parsecs away

Travel
| Discover the critical role of specialized cyber threat intelligence in safeguarding OT in the fourth blog of a new fundamentals series from Dragos and SANS ICS.