A Pentester’s Voyage – The First Few Hours
ID: a8e00d74-03a3-5474-881e-02fc3f05e7ca
STIX ID: report--a8e00d74-03a3-5474-881e-02fc3f05e7ca
Feed Name: Black Hills Infosec Blog
Threat Score
This blog post walks through an internal penetration test demonstrating rapid credential theft and lateral-movement techniques (LLMNR/NBNS poisoning, NTLM relaying, exposed Cisco Smart Install with Type 7 passwords) and documents findings, detection methods (event ID 4624 and a SIGMA rule), and defensive recommendations such as enforcing SMB signing, disabling vulnerable services, patching, and improved logging/segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
