216.73.217.22

Investigating a SharePoint Compromise: IR Tales from the Field

· Published 05/11/2024 16:01 · Modified 05/11/2024 16:32

Export JSON

Essential information

Published
05/11/2024 16:01
Modified
05/11/2024 16:32
Tags
2024-11-05 CVE-2024-38094 credential harvesting domain compromise fast reverse proxy (frp) impacket lateral movement mimikatz sharepoint
Related entities
8 observables, 8 techniques (mitre), 4 malware

Description

An incident response investigation uncovered an attacker who exploited a vulnerability () to gain initial access. The attacker remained undetected for two weeks, moving laterally across the network and compromising the entire domain. Key tactics included installing Horoung Antivirus to impair defenses, using tools like and for and , and establishing persistence through scheduled tasks. The attacker attempted to destroy backups and used various binaries for network reconnaissance and privilege escalation. The investigation revealed the importance of efficient response procedures and comprehensive security tooling to mitigate the impact of such breaches.

External references