The increasing complexity of development of new attack methods or variants of already known ones pose challenges for signature-based detection methods. Additional approaches are needed that are capable of supporting such a system where signatures and rules can no longer be used effectively.
In order to protect one's own company against phishing, awareness must first and foremost be created among employees. This can be done through workshops, phishing simulation or company policies.
In Active Directory, groups are used to group user accounts and computer accounts into units that are then easier to manage. First, it is important to understand why groups and group memberships are relevant.
How to find a specific "Object of Interest" or even several objects that have certain properties? The answer to this is as logical as it is simple: you need to know and specify the right search filters.
That a compromised mailbox is an extremely unpleasant situation is something everyone should be able to imagine. In a recent case we have investigated, attackers have been particularly clever.
In this article, we will look at artifacts that should always be collected during an incident on a Windows-based system to get the best possible picture of what happened.
In Active Directory, domains are used to emulate organizational structures; a domain is always an organizational unit with a unique name that contains, among other things, specific security policies and settings.