Easy Wins

If a method is used more than once then it begins to become a technique for the actor and worthy of a signature and signatures are cheap. Here are a couple that might trip up some internal red teams or testing.

  • payload.txt
  • dest_port = 1337
  • mimikatz
  • powersploit
  • powerview
  • nc.exe
  • metasploit
  • exploit
  • kerberoast
You get the idea, don't make it easy on them.

Comments

Popular posts from this blog

Misleading extensions Xls.exe Doc.exe Pdf.exe

Netconn from suspicious directories

Powershell DNS C2 Notes