Bad Habits: An ANTISOC Operation
ID: 4244ee8c-8b44-5f53-9927-88562c9f68e7
STIX ID: report--4244ee8c-8b44-5f53-9927-88562c9f68e7
Feed Name: Black Hills Infosec Blog
**Executive summary:** A BHIS ANTISOC case study describes how a helpdesk technician's reuse of a single reset password enabled attackers to password-spray that credential across an Entra ID export, compromise more than 100 accounts (some without MFA), establish SSH-based C2 and persistence inside the internal network, and access a backup web portal that could allow destructive actions; the report outlines detection gaps, attacker techniques, and post-incident remediation steps taken by the victim.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
