Your trust, our signature
ID: f2012f13-27a0-5072-8faa-dec313288e21
STIX ID: report--f2012f13-27a0-5072-8faa-dec313288e21
Feed Name: Fox-IT blog
Threat Score
This blogpost demonstrates how attackers (or red teams) can obtain and use legitimate S/MIME email certificates and lookalike domains to send signed phishing emails that appear trustworthy in common mail clients, includes a Python signing example and operational notes, and recommends mitigations such as registering similar domains, restricting the Secure Email EKU, and user awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
