Discussion about this post

User's avatar
Neural Foundry's avatar

Solid aggregation on Ink Dragon repurposing government servers as relay infrastructure. The detail about IIS-based modules to blend with enterprise traffic is exactly the kind of low-signal tactic that burns through traditional perimeter telemetry. I ran into similar schemes in a past engagement where comproised SharePoint instances were used as data exfil staging points because outbound traffic from MS endpoints looked completely benign. Defenders need to treat internal web apps as potential threat infastructure, not just assets to protect.

Expand full comment
1 more comment...

No posts

Ready for more?