Monthly Adversary Tradecraft Spotlight – August

Monthly Adversary Tradecraft Spotlight – August

Exports Critical Registry Keys To a File The Windows Registry stores a significant amount of operating system and security information. The SAM (Security Account Manager) hive contains local account password hashes, the SYSTEM hive contains the boot key required to...

read more
Think Like an Attacker: Spot the Security Risks

Think Like an Attacker: Spot the Security Risks

Wi-Fi password posted on the wall ("Office-WiFi / Password: Office123!") Unattended laptop left unlocked Mobile phone left unattended on the desk Password written on a sticky note ("New password Summer2024") Sensitive handwritten notes left in the open Printed...

read more
Monthly Adversary Tradecraft Spotlight – June

Monthly Adversary Tradecraft Spotlight – June

OpenWith.exe Executes Specified Binary This technique leverages OpenWith.exe as a proxy execution mechanism to run arbitrary code while blending in with legitimate system activity. It is a trusted Windows binary that is typically used when a user selects “Open with…”...

read more