voldimmoral ๐ช
@voldimmoral
#Veteran | Progressive Thinker | Diversity Ally โฅ๏ธ Committed to the truth, integrity, fairness, and moral justice. #Equality is a human right, not a debate.
ID: 1537863192591802368
17-06-2022 18:22:28
2,2K Tweet
1,1K Followers
924 Following
Tanner Curity John Hammond These invocations followed after typical enumeration commands: โ whoami /priv โ cmdkey /list โ net group and others that indicate hands-on-keyboard threat actor activity. Huntress has isolated the affected organization to prevent further post-exploitation.
๐๐๐ฆ๐ง ๐ข๐ฆ๐๐ก๐ง ๐ง๐ข๐ข๐๐ฆ ๐ (๐ช๐ถ๐๐ต ๐จ๐ฅ๐๐ ๐ + ๐ฃ๐๐ฟ๐ฝ๐ผ๐๐ฒ ๐ฏ) 1๏ธโฃ Shodan ๐ shodan.io ๐ฏ Finds internet-connected devices (cameras, servers, IoT) 2๏ธโฃ Censys ๐ search.censys.io ๐ฏ Scans internet assets & SSL certificates 3๏ธโฃ Criminal IP ๐
๐ก๏ธ ๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ ๐ฆ๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐๐ป๐ด๐ถ๐ป๐ฒ๐ (๐ข๐ฆ๐๐ก๐ง) ๐ Infra โข Shodan โ Find exposed devices shodan.io โข Censys โ Internet-wide asset view censys.io โข FOFA โ Asset discovery fofa.info โข ZoomEye โ Attack surface mapping