Augmenting Security Testing and Analysis Activities with Microsoft 365 Products
ID: 2189ce6c-f180-5ce2-9e36-e386dee7186a
STIX ID: report--2189ce6c-f180-5ce2-9e36-e386dee7186a
Feed Name: Black Hills Infosec Blog
This blog post explains how Microsoft 365/Office (notably Excel) macros can be used for both security testing and abuse, covering document poisoning, covert reconnaissance, establishing initial access via SSH (dropping keys and LNK persistence), and post‑compromise data collection from Active Directory and other resources; it is presented as guidance for testers and defenders rather than a report of a specific incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
