Active Directory Infiltration Methods Employed by Cybercriminals – ASEC Report
ID: 9ef73f5b-36d3-5bd6-8ca7-2d403b5c6392
STIX ID: report--9ef73f5b-36d3-5bd6-8ca7-2d403b5c6392
Feed Name: GBHackers
Threat Score
This report summarizes Active Directory infiltration techniques used by threat actors, detailing reconnaissance (port scanning, net commands), AD enumeration and stealthy tooling (PowerView, AdFind), and attack-path mapping (BloodHound/SharpHound), and notes ASEC-observed exploitation and Ryuk’s use of AdFind; it emphasizes that compromising Domain Controllers or Domain Admins enables full domain compromise and that these tools can evade traditional defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
