Bringing the hashes home with reGeorg & Empire
ID: 679b7687-7b26-5e86-9dad-351c35e0287a
STIX ID: report--679b7687-7b26-5e86-9dad-351c35e0287a
Feed Name: SensePost Blog
Threat Score
A penetration-test blog recounts chaining an SQL injection to upload a PHP web shell, using reGeorg to tunnel into the internal network, leveraging impacket psexec to gain a session on the domain controller, and deploying PowerShell Empire with mimikatz to extract and crack large numbers of domain credentials—demonstrating full domain compromise resulting from common misconfigurations and weak passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
