Thread by @malmoeb on attacks: Visibility is key for eradication
Posted by jpluimers on 2024/06/28
[Wayback/Archive] Thread by @malmoeb on Thread Reader App: Visibility is key for eradication.
The thread is about attacks on networks with Windows machines, but the concept works on all networks.
Start of thread: [Wayback/Archive] Stephan Berger on Twitter: “1/ Visibility is key for eradication 🥷 In a recent IR case, the TA created persistences with #QakBot on almost every system in the network. If only individual systems in the network were forensically examined, one or more infected systems would undoubtedly be missed. 🧵”
The gist is to setup your network monitoring in such a way that you can quickly identify compromised systems based on network traffic patterns.
–jeroen






Leave a comment