In order to protect one's own company against phishing, awareness must first and foremost be created among employees. This can be done through workshops, phishing simulation or company policies.
In Active Directory, groups are used to group user accounts and computer accounts into units that are then easier to manage. First, it is important to understand why groups and group memberships are relevant.
How to find a specific "Object of Interest" or even several objects that have certain properties? The answer to this is as logical as it is simple: you need to know and specify the right search filters.
That a compromised mailbox is an extremely unpleasant situation is something everyone should be able to imagine. In a recent case we have investigated, attackers have been particularly clever.
In this article, we will look at artifacts that should always be collected during an incident on a Windows-based system to get the best possible picture of what happened.
In Active Directory, domains are used to emulate organizational structures; a domain is always an organizational unit with a unique name that contains, among other things, specific security policies and settings.
Having previously made a name for itself on the criminal scene by attacking major companies such as Quanta Computer and Invernergy, REvil's latest attack on software company Kaseya and its update service is believed to have affected several hundred companies worldwide.
In the event of an attack, companies should take appropriate countermeasures with professional help. The tool of choice here is Digital Forensics & Incident Response (DFIR).