Black Hills InfoSec - How to Phish for User Passwords with PowerShell

tokyoneon // Spoofing credential prompts is an effective privilege escalation and lateral movement technique. It’s not uncommon to experience seemingly random password prompts for Outlook, VPNs, and various other authentication protocols in Windows environments. Adversaries will abuse functionalities built into Windows and PowerShell to invoke credential popups to acquire user passwords.  As defined by the MITRE […]

The post How to Phish for User Passwords with PowerShell appeared first on Black Hills Information Security.



from Black Hills Information Security https://www.blackhillsinfosec.com/how-to-phish-for-user-passwords-with-powershell/

Comments

Popular posts from this blog

KnowBe4 - Scam Of The Week: "When Users Add Their Names to a Wall of Shame"

KnowBe4 - Phishing Campaigns Abuse AI Workflow Automation Platforms

The Hacker News - Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools