Mapping MITRE ATT&CK to the Equifax Indictment
ID: 09cec05a-a7ed-5b27-acd3-1acf504af12c
STIX ID: report--09cec05a-a7ed-5b27-acd3-1acf504af12c
Feed Name: ReliaQuest Blog
Threat Score
This report revisits the 2017 Equifax breach and maps the intrusion to MITRE ATT&CK: alleged PLA operators exploited Apache Struts (CVE-2017-5638) to upload web shells, performed extensive SQL reconnaissance (thousands of queries) to find PII (names, addresses, SSNs, DOBs), compressed and exfiltrated data over HTTP, and removed logs and artifacts; the analysis enumerates the TTPs used and provides mitigation and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
