logo

Threat Mitigation Strategies: Observations and Recommendations

ID: c1bdc0dd-9716-5609-912b-ce3a4f7c6c17

STIX ID: report--c1bdc0dd-9716-5609-912b-ce3a4f7c6c17

Feed Name: SpecterOps Blog

Date Published: 2018-01-25

Date Updated: 2026-04-30

Author: James Tubberville

...
...

This post provides practical, high-impact defensive strategies to hinder common adversary behaviors—such as lateral movement, C2, and credential theft—by enforcing network communication controls (blocking client-to-client and server-to-client traffic, restricting outbound server access), reducing credential exposure (clearing caches, resetting KRBTGT, LAPS), tightening privileges and group nesting, monitoring critical authentication patterns, and adopting application whitelisting. Emphasizing that compliance is not security, it advocates for assumed breach, precise PPS whitelisting, and operationally feasible configurations that both constrain attacker options and improve detection through deviations from a well-defined baseline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.