logo

Top 10 post-exploitation tools threat actors use in real intrusions

ID: a13c96ac-a1f8-532f-8210-b6339d5125e8

STIX ID: report--a13c96ac-a1f8-532f-8210-b6339d5125e8

Feed Name: ThreatLocker Blog

Threat Score
88/100

Date Published: 2025-12-16

Date Updated: 2026-05-01

...
...

This report catalogs commonly abused post-exploitation tools (Cobalt Strike, Impacket, Metasploit/Meterpreter, Sliver, Rubeus, PowerSploit/PowerView, Rclone, CrackMapExec/NetExec, PowerShell Empire, Brute Ratel), ties them to real-world intrusions and campaigns (SolarWinds SUNBURST, DIB intrusion, Conti, BlackSuit, Black Basta, BumbleBee), explains typical attack chains (initial access, in-memory loaders, credential theft, lateral movement, staging and exfiltration), and recommends defensive measures such as deny-by-default application control, ringfencing, and elevation control to limit attackers’ ability to run post-exploitation tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.