Invictus Incident Response
@invictusir
Helping organizations respond to cyber incidents in the cloud |
๐ 24/7 support invictus-ir.com/24-7 |
๐ Academy academy.invictus-ir.com
ID: 1397641493138087943
http://invictus-ir.com 26-05-2021 19:54:27
349 Tweet
1,1K Followers
30 Following
๐Time to update your favorite cloud IR tool, the Microsoft Extractor Suite! ๐๐ฉ๐๐๐ญ๐-๐๐จ๐๐ฎ๐ฅ๐ -๐๐๐ฆ๐ ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ-๐๐ฑ๐ญ๐ซ๐๐๐ญ๐จ๐ซ-๐๐ฎ๐ข๐ญ๐ Release notes for version 3.0.4 ๐ - Added -UserIds parameter to Get-Users for filtering by specific user IDs. -
๐จ New blog from Datadog, Inc. on fresh AWS TTPs! Me and Team Invictus Incident Response pivoted & enriched their infra data to uncover the actor #JavaGhost is likely abusing callback proxy networks and leveraging Mass SMTP Tester. ๐ securitylabs.datadoghq.com/articles/talesโฆ #CloudSecurity #ThreatIntel #CTI