THREAT OPS › Threat News › Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
<aside class="table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents" id="accordion-f2d9dbb7-ffe1-455a-a658-1b62a7e603bb"> <button class="btn btn-collapse" type="button"> <span class="table-of-contents-block__label">In this article</span> <span class="table-of-contents-block__current"></span>
<svg class="table-of-contents-block__arrow" fill="none" height="11" viewBox
MITRE ATT&CK techniques
- Screen CaptureT1113
- Rundll32T1218.011
- JavaScriptT1059.007
- Domain AccountT1087.002
- System ChecksT1497.001
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- MsiexecT1218.007
- Social EngineeringT1684
- MasqueradingT1036
- System Binary Proxy ExecutionT1218
- Windows Remote ManagementT1021.006
- System Network Configuration DiscoveryT1016
- Account DiscoveryT1087
- Command and Scripting InterpreterT1059
- Domain AccountT1136.002
- Virtualization/Sandbox EvasionT1497
- PowerShellT1059.001
- Social MediaT1593.001
- CredentialsT1589.001
- Domain AccountsT1078.002
- Security Software DiscoveryT1518.001
- ImpersonationT1684.001
- Web ProtocolsT1071.001
- Remote System DiscoveryT1018
- Software DiscoveryT1518
- Ingress Tool TransferT1105
- Spearphishing via ServiceT1566.003
- Command and Scripting InterpreterAML.T0050
- ImpersonationAML.T0073
- MasqueradingAML.T0074
- Virtualization/Sandbox EvasionAML.T0097
Indicators of compromise
- 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389dsha256
- a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676sha256
- cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5sha256
- 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3sha256
- 69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23sha256
- a135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87sha256
- https://microsoft.github.io/zerotrustassessment/url
- dssdfvsdfvsdfvsdgbfbdvdzv.orgdomain