The Wiert Corner – irregular stream of stuff

Jeroen W. Pluimers on .NET, C#, Delphi, databases, and personal interests

  • My badges

  • Twitter Updates

  • My Flickr Stream

  • Pages

  • All categories

  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 1,862 other subscribers

Thread by @malmoeb on attacks: Visibility is key for eradication

Posted by jpluimers on 2024/06/28

[Wayback/Archive] Thread by @malmoeb on Thread Reader App: Visibility is key for eradication.

The thread is about attacks on networks with Windows machines, but the concept works on all networks.

Start of thread: [Wayback/Archive] Stephan Berger on Twitter: “1/ Visibility is key for eradication 🥷 In a recent IR case, the TA created persistences with #QakBot on almost every system in the network. If only individual systems in the network were forensically examined, one or more infected systems would undoubtedly be missed. 🧵”

The gist is to setup your network monitoring in such a way that you can quickly identify compromised systems based on network traffic patterns.

–jeroen

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.