OTRF / detection-hackathon-apt29

Place for resources used during the Mordor Detection hackathon event featuring APT29 ATT&CK evals datasets
GNU General Public License v3.0
132 stars 41 forks source link

16.C) Next, the attacker uses the previously dumped credentials (T1078) to create a remote PowerShell session to the domain controller (T1028). #39

Open Cyb3rWard0g opened 4 years ago

Cyb3rWard0g commented 4 years ago

Next, the attacker uses the previously dumped credentials (T1078) to create a remote PowerShell session to the domain controller (T1028).