![]() ![]() The beginning of this engagement was particularly frustrating as the client used CrowdStrike Falcon for the primary EDR solution in their environment. CrowdStrike Falcon gave us a difficult time by preventing several tools, techniques, and procedures (TTPs) from working that we had previous success with on prior engagements in terms of evading CrowdStrike Falcon. Our progress was affected enough that it forced us to focus on how to bypass CrowdStrike, rather than focusing on arguably more important aspects of the engagement such as identifying security misconfigurations and/or gaps in alerting and response. Luckily, CrowdStrike Falcon provided enough wiggle room that we were able to use tools to perform password guessing attacks against domain user accounts. The password guessing attacks led to the compromise of credentials for an account that had Local Administrator privileges over a limited number of systems in the environment. ![]() ![]() Specifically, the compromised account credentials provided remote administrative access to hosts running legacy operating systems that used Symantec Endpoint Protection, which is un/fortunately easy to disable with Local Administrator access.Īccess to legacy systems running Symantec Endpoint Protection allowed us to continue the Red Team engagement without having to further interact with CrowdStrike Falcon. ![]()
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |