Credential Theft: Expanding Your Reach, Pt. II
ID: e87cca35-2c00-5697-b7c9-2cd116a779ae
STIX ID: report--e87cca35-2c00-5697-b7c9-2cd116a779ae
Feed Name: Huntress Blog
Threat Score
Huntress observed and documented a credential-theft technique in which adversaries abused the Windows LOLBin print.exe to copy AD credential stores (NTDS.DIT, SAM, SYSTEM) from Volume Shadow Copies; the report provides example command lines, notes use of NetTime.exe and vssuirun.exe, shows telemetry context across customer EDR data, and offers detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
