nitter
Jake Williams
@MalwareJake
16 Sep 2022
I can't tell you the number of times I've gone from initial entry to having privileged access (often domain admin) from credentials stored in world readable scripts, usually in SYSVOL.
7
25
2
219
Hal Pomeranz
@hal_pomeranz
16 Sep 2022
Replying to
@MalwareJake
Strikes me as an interesting honeypotting technique for defenders
Sep 16, 2022 · 11:52 AM UTC
1
4
Rossle
@RossleRed
16 Sep 2022
Replying to
@hal_pomeranz
@MalwareJake
There is a lovely
@ThinkstCanary
CanaryToken in the form of an AWS API key.
docs.canarytokens.org/guide/…
2