Behind the Scenes: Crushing Cybercriminals with MAV | Huntress
ID: 24eda10c-7779-5355-ab2e-d8cfa5f08afd
STIX ID: report--24eda10c-7779-5355-ab2e-d8cfa5f08afd
Feed Name: Huntress Blog
Threat Score
Huntress describes an intrusion in which an attacker brute-forced a public SQL Server (port 1433), deployed a malicious batch script that disabled Defender protections and deployed Meterpreter; Microsoft Defender alerted analysts who pivoted to EDR, external recon and logs to investigate, isolate the host, and provide remediation and detection guidance (including a Sigma rule) to partners and the community.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
