Explore tweets tagged as #Initialaccess
@Gi7w0rm
Gi7w0rm
3 years
Just found a #Telegram #cybercrime market channel where you are only allowed to write if you use the words WTB (want to buy) and WTS (want to sell). #GoogleAds , #FacebookAds , #TwitterAds and #YouTube Accounts among the most searched for accounts. #infosec #initialaccess
0
10
45
@pfiatde
pfiatde
2 years
Did you know, that you can use search-ms to bind a WebDAV drive and filter there? This offers some possibilities for attack chains, e.g. with Java, Python, Ruby or Visual Studio. Here is a PoC for Visual Studio: More 🧵👇 #initialAccess
1
13
31
@M0jtaba_Sed
Mojtaba Sedaghat
1 year
Explorer hides extensions of 16 file types, even if you want to see them all. If such files contain real PE (exe) content, they behave differently when you double click them. 😈 #InitialAccess #RedTeam
1
0
2
@M0jtaba_Sed
Mojtaba Sedaghat
1 year
SVG smuggling and HTML smuggling methods are supported by both MacroPack and ShellcodePack 💡 Use --container=<name>.zip.svg to generate an evasive SVG smuggling container dropping a zip archive containing your payload ! #InitialAccess #RedTeam
1
0
2
@sekoia_io
Sekoia.io
2 years
The threat actor is either looking for partners to exploit known #vulnerabilities such as CVE-2023-34124, CVE-2023-33308 and CVE-2023-27997 for initial access ($20,000 per CVE) or directly buying #InitialAccess for further compromise.
0
3
7
@M0jtaba_Sed
Mojtaba Sedaghat
1 year
Browser Cache #Smuggling Attack + Creativity When we visit any website ,there’s lot of content that our browser fetches from the websites ,like CSS,HTML ,JavaScript, Images ,Video ,etc. Now our browser actually cache (save’s a local copy) of certain data . #InitialAccess #RedTeam
1
0
1
@InfosecPandey
InfoSec Pandey🥷🏻 🇮🇳 🕉️
3 years
Many of the current #RaaS org. can capitalize on the tools they already have. We expect that in future, the groups will also adopt other criminal business models14 to monetize #initialaccess, such as stock fraud, business email compromise (BEC), money laundering, and others.
1
0
0
@Ransom_DB
Ransom-DB
1 year
🚨 Threat Actor "Miyako" Offering Root Access to USA State University Server 🇺🇸 Privilege: Root Access Revenue: $5.6B+ Price: $1,500 #Breach #InitialAccess #UnitedStates #Education
0
0
0
@socradar
SOCRadar®
2 years
💡As part of #RansomwareAwarenessMonth, we continue to share #ransomware groups notorious for their malicious activities. 🔻Read our blog to learn all the details about the attacks, #InitialAccess methods, tactics, and related #malware of #BianLian. 🔗 https://t.co/WT5EKcoGDJ
0
2
3
@MarioRojasChin
Mario Rojas
5 months
🇨🇷 Un actor malicioso afirma vender acceso no autorizado al panel de control de Wordpress de una organización en #CostaRica el actor afirma tener la capacidad de implementar un shell en el servidor para permitir acceso de manera remota al comprador #InitialAccess @micittcr
0
0
0
@francescofaenzi
francescofaenzi
2 years
#Ransomware in #OneDrive: the #attack (1/3 - #initialaccess) #TrustEverybodyButCutTheCards The first step that an #attacker would take would be to attempt to gain access to the #Microsoft365 environment.
1
0
1
@francescofaenzi
francescofaenzi
2 years
#M365 #InitialAccess Vectors #LogSources #TrustEverybodyButCutTheCards *** Unified Audit Log The #UnifiedAuditLog (UAL) in #Microsof365 aggregates logs from various services, such as #ExchangeOnline, #SharePointOnline, #OneDrive, #MicrosoftTeams and #AzureAD.
1
0
0
@EmanuelePicari5
Emanuele Picariello
1 year
0
0
0
@kondah_ha
Kondah Hamza 🦑
3 years
💡Rejoignez moi dans mon prochain webinar afin de découvrir l'exploitation des COM Scriptlets à travers différentes implémentations. 🚀 Lien d'inscription : https://t.co/NbHLvrhTys 👉 Date et heure : Jeudi 27 Avril 2023 à 18h. #RedTeaming #initialaccess #phishing
0
1
6
@francescofaenzi
francescofaenzi
1 year
Relative #frequency and #losses for observed #initialaccess techniques #TrustEverybodyButCutTheCards Always the same "music": #Exploit Public-Facing Application + #Phishing + External #RemoteServices Source: #Risk Insights on #ransomware by #Cyentia Institute
0
0
0
@francescofaenzi
francescofaenzi
2 years
Is still #human the weakest link? #TrustEverybodyButCutTheCards Top 4 #initialaccess vectors from Unit 42 incident response cases in 2023 Source: #PAN #Unit42 #IncidentResponse report 2024
0
0
0
@francescofaenzi
francescofaenzi
2 years
Seems confirmed: is only #enduser the problem? #TrustEverybodyButCutTheCards Top #initialaccess vectors #XForce observed in 2022 and 2023. Sources: X-Force and #MITREATTaCK Matrix for Enterprise framework
0
0
0