logo

Augmenting Security Testing and Analysis Activities with Microsoft 365 Products

ID: 2189ce6c-f180-5ce2-9e36-e386dee7186a

STIX ID: report--2189ce6c-f180-5ce2-9e36-e386dee7186a

Feed Name: Black Hills Infosec Blog

Date Published: 2024-06-13

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post explains how Microsoft 365/Office (notably Excel) macros can be used for both security testing and abuse, covering document poisoning, covert reconnaissance, establishing initial access via SSH (dropping keys and LNK persistence), and post‑compromise data collection from Active Directory and other resources; it is presented as guidance for testers and defenders rather than a report of a specific incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.