OPSEC failures when threat hunting
ID: 4ee5740f-1cc0-5fbd-80cf-4abe89a2ac59
STIX ID: report--4ee5740f-1cc0-5fbd-80cf-4abe89a2ac59
Feed Name: Pen Test Partners Blog
A practitioner describes a phishing assessment using a spoofed Microsoft Forms/M365 email with a hidden Azure CDN link and a UNC path to an SMB server (Impacket) to silently capture NetNTLM hashes; while users reported the phish, IT staff working remotely with split-tunnel VPN forwarded and opened the email in native Outlook, leaking hashes and metadata, then used Browserling and uploaded the URL to VirusTotal, risking sensitive data exposure when a researcher entered apparent valid credentials. The post underscores OPSEC pitfalls in incident response and recommends opening suspicious emails only in sandboxed environments via webmail, avoiding uploads of potentially genuine content to public analysis services, and enforcing controls such as blocking outbound port 445 for remote users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
