Qilin Ransomware Expands Post-Compromise Reconnaissance
ID: 261ba159-0dc4-5180-9f72-9180d3890635
STIX ID: report--261ba159-0dc4-5180-9f72-9180d3890635
Feed Name: Cyber Press
Researchers observed the Qilin RaaS group deploying a stealthy post-compromise reconnaissance technique: a PowerShell query of Event ID 1149 in the Windows Terminal Services operational log to enumerate RDP authentication history (usernames, domains, source IPs) and quickly map privileged accounts for lateral movement. The report warns this living-off-the-land approach evades noisy scans and advises defenders to enable PowerShell ScriptBlock Logging and monitor for the specific log-extraction queries and other advanced PowerShell activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
