THREAT OPS › Threat News › Anatomy of a Silent Domain Takeover
Anatomy of a Silent Domain Takeover
<hr />
<section style="background-color: #f7f8fb; padding: 16px 18px;"> <h4 style="color: #ed2e26;">Key Takeaways</h4>
<ul> <li>Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint.</li> <li>The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single att
MITRE ATT&CK techniques
Indicators of compromise
- https://www.verizon.com/business/resources/reports/dbir/url
- https://www.qualys.com/apps/etm-identityurl
- https://www.qualys.com/apps/etm-identity/url
- s.w.orgdomain
Original source: https://blog.qualys.com/category/product-tech