tag: Endpoint · 3 items
- Engineer — Learn: No CVE or patch involved — attackers are abusing a legitimate admin tool’s functionality. Review whether Faronics Deploy is in your environment and whether its deployment permissions are appropriately scoped.
- SOC/IR — Act: Hunt for unexpected ScreenConnect installations originating from Faronics Deploy processes; build detections for remote-management tool deployments not initiated by IT change management workflows.
- Leader — Skip
- Engineer — Plan: If Windows Defender crashes were affecting endpoint coverage in your environment, apply the follow-on fix via Windows Update to restore stable antivirus operation.
- SOC/IR — Plan: Verify that EDR/Defender telemetry gaps didn’t occur during the crash window; confirm detection coverage was restored after the fix is applied.
- Leader — Skip
- Engineer — Learn: ACR Stealer targets browser-stored credentials and tokens — review whether your CI/CD pipelines or developer workstations enforce short-lived tokens and MFA to limit blast radius if credentials are harvested.
- SOC/IR — Act: Microsoft is actively observing this campaign; hunt for ACR Stealer IOCs across EDR telemetry and SIEM, and tune detections for credential-access behaviors (browser credential dumping, token theft) across enterprise endpoints.
- Leader — Plan: A confirmed surge targeting enterprise customers elevates infostealer risk on your risk register; consider briefing on phishing-resistant MFA adoption and reviewing credential hygiene posture this quarter.