Where SensePost meets the real world
ID: 09e49a87-5744-5fd9-8164-192aa6b7bd90
STIX ID: report--09e49a87-5744-5fd9-8164-192aa6b7bd90
Feed Name: SensePost Blog
This document outlines SensePost’s Black Hat USA infrastructure training, emphasizing methodology over tools to emulate real-world attackers. It highlights techniques such as passive and active network enumeration, identifying “low-hanging fruit” (e.g., unauthenticated NoSQL/X11/VNC services and weak credentials on MSSQL/Tomcat/JBOSS), credential discovery from hosts (registry, configs, memory), and lateral movement using tools like Responder, PsExec/WMI, Impacket, and Metasploit. Referencing the Hacking Team breach for context, it presents the course as an 18-hour, hands-on program to help students discover, target, exploit, and exfiltrate like determined adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
