Stories from the SOC: When threats come from inside the house
ID: 32854410-8135-58cd-a31b-cc552c65d4e8
STIX ID: report--32854410-8135-58cd-a31b-cc552c65d4e8
Feed Name: Expel Blog
Threat Score
Expel MDR detected and stopped an internal phishing incident in which an attacker used a compromised employee email to distribute a malicious link that downloaded an attacker-controlled remote management tool to five users; the SOC contained the affected accounts and hosts, blocked related domains/IPs, and recommended conditional access and application control to prevent recurrence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
