Hoping that the use of Microsoft LAPS will mitigate the lateral movement of the WMIC calls (fingers crossed, waiting for shoe to drop).
-
-
-
...don't forget to block remote use of local accounts via GPO
-
Thanks
@ForensicFarmer. Learned something new today
End of conversation
New conversation -
-
-
How does it get username/password? (mimikatz?!)
-
Reuse of auth token on system ?
-
probably
End of conversation
New conversation -
-
-
A rapidly written new blog post on how to easily block the psexec attack vectorhttps://guyrleech.wordpress.com/2017/06/28/petya-easily-disabling-access-to-psexec/ …
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
This Tweet is unavailable.Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
WMI is poison created by Microsoft.
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
How does it get creds?
-
Likely people have local admin on remote machine and runs under their context. Bad arch - no firewall, too much priv, etc
End of conversation
New conversation -
-
-
CVE2017-0199 might be involved too.
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
Do you have a sample that is confirmed to use WMIC to propagate?
-
The one that you can share, that is. Sample or hash.
End of conversation
New conversation -
-
-
That is correct. There is a decision tree for each of those 3.
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
patching Office doesn't prevent lateral spreading?
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
100
s!
Your tweet has been liked by 100 people. https://favstar.fm/t/879742221326721028 …https://twitter.com/mikko/status/879742221326721028 …Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
Thanks. Twitter will use this to make your timeline better. Undo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.