

Dimitrios Bougioukas
61 posts

@DBougioukas
➡ VP, IT Security Training Services @hackthebox_eu ➡ (Informal) Expert, Incident Response Technical Training @enisa_eu














Recent pre-ransomware incident identified by our #SOC: - Initial access: Remote access using compromised credentials - Enumeration: AdvancedIPScanner, net commands - Lateral movement: PsExec, RDP, SMB - Defense Evasion: AmsiScanBuffer bypass, cleared Windows event logs - PrivEsc: Memdump with Comsvcs.dll, ZeroLogon (CVE-2020-1472) - unsuccessful We were able to detect and remove attacker access prior to ransomware deployment. The attack happened very quickly highlighting why there is so much latency sensitivity in today's security operations environment. Reminder: stress test your incident response plans and practice remediation. "It's 2am on a Saturday and we just detected activity consistent with potential pre-ransomware techniques. Who do we escalate to and are we prepared to take all remediation actions, quickly and accurately?"




























