Untold Tales from Tactical Response | Huntress
ID: 69eae712-5695-5569-8c34-983b51ec2957
STIX ID: report--69eae712-5695-5569-8c34-983b51ec2957
Feed Name: Huntress Blog
Huntress recounts an investigation where attackers gained foothold (likely via VPN brute-force), exploited a known Veeam Backup & Replication vulnerability (CVE-2023-27532) to extract credentials and execute code via Veeam.Backup.MountService.exe, then moved laterally using WinRM (wsmprovhost), created persistent local administrator/RDP accounts, and modified registry settings to enable further RDP access and bypass UAC; the report includes event/log evidence, process lineage, MITRE ATT&CK mapping, and applicable IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
