Happy Friday all!
Today, lets talk tools, the right tool in the wrong hands can be catastrophic.
What tool have you seen so the most damage to an environment? Whether it’s a built in tool/feature or 3rd party, I wanna hear!
For me, it’s Remote PowerShell. I witnessed this being used by a malicious script to deploy ransomware to every device in the domain and the rest of the network. The script was harvesting credentials from users working on the infected endpoint and the moment a domain admin signed in, BANG, remote PowerShell to all!