logo

Evicting the Adversary | Huntress

ID: fb54054f-133a-5015-94b9-de8276dd264c

STIX ID: report--fb54054f-133a-5015-94b9-de8276dd264c

Feed Name: Huntress Blog

Threat Score
45/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

This blog post explains how defenders can detect, investigate, and eject attackers from Windows Active Directory environments by identifying misuse of WinRM/PowerShell remoting, Impacket WMIexec, and RDP; it showcases monitoring artifacts and provides remediation actions (disabling accounts, rotating passwords, removing admin rights, and terminating sessions) while warning about the tradeoffs of alerting adversaries during response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.