Threat Intel Accelerates Detection and Response
ID: e75ff67b-83fb-5c23-9e44-0a07f1e9d448
STIX ID: report--e75ff67b-83fb-5c23-9e44-0a07f1e9d448
Feed Name: Huntress Blog
Threat Score
This Huntress report details discovery of reconnaissance activity against a legacy MSExchange installation: the attacker used OWA/powershell endpoints to execute commands (finger.exe, encoded PowerShell, whoami) that contacted IP 185.56.83.82. Huntress correlated Windows Defender detections, MSExchange CmdletLogs, and IIS logs to validate the indicators of compromise, mapped the behavior to OWASSRF exploitation, and advised immediate Exchange patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
