logo

Intelligence-Led Threat Hunting: The Key to Fighting Cross-Domain Attacks

ID: 0441b9c9-5b1f-5c7b-bd18-03a56dbc4e45

STIX ID: report--0441b9c9-5b1f-5c7b-bd18-03a56dbc4e45

Feed Name: Crowdstrike Blog

Threat Score
78/100

Date Published: 2025-03-03

Date Updated: 2026-04-27

Author: Thuy Nguyen - Dana Larson

...
...

This case study details a sophisticated, multi-stage intrusion: initial exploitation of a vulnerable Linux Tomcat server to obtain root, credential harvesting and lateral movement to Windows hosts, establishment of covert access (SSH keys/tunnels), and abuse of cloud control-plane mechanisms (SSM) to run commands against cloud instances, create persistent fallback resources, and exfiltrate sensitive data—activity detected and remediated through CrowdStrike OverWatch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.