I can't tell you the number of times I've gone from initial entry to having privileged access (often domain admin) from credentials stored in world readable scripts, usually in SYSVOL.
7
25
2
219
Replying to @MalwareJake
Strikes me as an interesting honeypotting technique for defenders

Sep 16, 2022 · 11:52 AM UTC

1
4
There is a lovely @ThinkstCanary CanaryToken in the form of an AWS API key. docs.canarytokens.org/guide/…
2