Intelligence-Led Threat Hunting: The Key to Fighting Cross-Domain Attacks
ID: 0441b9c9-5b1f-5c7b-bd18-03a56dbc4e45
STIX ID: report--0441b9c9-5b1f-5c7b-bd18-03a56dbc4e45
Feed Name: Crowdstrike Blog
Threat Score
This case study details a sophisticated, multi-stage intrusion: initial exploitation of a vulnerable Linux Tomcat server to obtain root, credential harvesting and lateral movement to Windows hosts, establishment of covert access (SSH keys/tunnels), and abuse of cloud control-plane mechanisms (SSM) to run commands against cloud instances, create persistent fallback resources, and exfiltrate sensitive data—activity detected and remediated through CrowdStrike OverWatch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
