Don’t Be The DNC: An Introduction to Enterprise Threat Hunting
ID: 273555e5-a460-56c1-8766-b038e5fe323d
STIX ID: report--273555e5-a460-56c1-8766-b038e5fe323d
Feed Name: Security Ledger
Executive summary: The article reviews The New York Times' post-mortem of the DNC hack, describing months-long espionage by hackers believed linked to the Russian government that used phishing (fake Google password reset e-mails) to gain persistent access and exfiltrate tens or hundreds of thousands of emails. It emphasizes failures in detection, training, communication, and the absence of an incident response/threat-hunting capability at the DNC, and uses the case to illustrate the importance of low-cost IR practices, pre-established relationships with partners and law enforcement, and proactive threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
