Elektrine lite

← Feed

@Xavier@infosec.exchange

Post #4069661

2026-07-24 18:30 UTC

@mttaggart@infosec.exchange Yes, if its a cred reseller, we can expect our normal controls to remain effective. For example, we find creds on the dark web. Just reset creds and run reports, but likelihood is that they never successfully connected due to other controls. If the actor is like Scattered Spider, then they already have automated process that is learning your controls and are actively adding capabilities to their attack. This is a all hands on deck, including security engineering, and will probably be a extended engagement. Not knowing anything your actor means responding like SS every time, which is not fun.

Replies (1)

  • @mttaggart@infosec.exchange 2026-07-24 18:42

    @Xavier@infosec.exchange To be frank, that sounds like missing telemetry in both cases. You shouldn't be guessing about follow-on behavior. And again, with that telemetry, you're focused on behavior and not who might have done it.

    Open ##4069849