Identifying an Existing APT Intrusion
ID: d880d215-f47a-5588-8409-3c02344fb76e
STIX ID: report--d880d215-f47a-5588-8409-3c02344fb76e
Feed Name: WatchGuard Secplicity Blog
Threat Score
WatchGuard Threat Lab discovered and investigated an APT intrusion on a customer network in which attackers acquired valid local and domain accounts, attempted VBS/PowerShell-based payload delivery, executed PowerSploit and Cobalt Strike components for lateral movement and command-and-control, used PsExec and Mimikatz, and exfiltrated data to Dropbox via RClone; the report provides TTP mapping, IOCs (including an MD5), and recommendations such as MFA and robust EDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
