Black Hills InfoSec - How to Phish for User Passwords with PowerShell

tokyoneon // Spoofing credential prompts is an effective privilege escalation and lateral movement technique. It’s not uncommon to experience seemingly random password prompts for Outlook, VPNs, and various other authentication protocols in Windows environments. Adversaries will abuse functionalities built into Windows and PowerShell to invoke credential popups to acquire user passwords.  As defined by the MITRE […]

The post How to Phish for User Passwords with PowerShell appeared first on Black Hills Information Security.



from Black Hills Information Security https://www.blackhillsinfosec.com/how-to-phish-for-user-passwords-with-powershell/

Comments

Popular posts from this blog

KnowBe4 - Scam Of The Week: "When Users Add Their Names to a Wall of Shame"

Krebs - NY Charges First American Financial for Massive Data Leak

SBS CyberSecurity - In The Wild 166