Post #4069663
2026-07-24 17:26 UTC
@Xavier@infosec.exchange How does it matter at all? Once you know you have your creds stolen, is there any reason to assume they won't be sold/abused? Why would your defensive posture/response differ?
Replies (1)
-
@Xavier@infosec.exchange 2026-07-24 18:30
@mttaggart@infosec.exchange Yes, if its a cred reseller, we can expect our normal controls to remain effective. For example, we find creds on the dark web. Just reset creds and run reports, but likelihood is that they never successfully connected due to other controls. If the actor is like Scattered Spider, then they already have automated process that is learning your controls and are actively adding capabilities to their attack. This is a all hands on deck, including security engineering, and will probably be a extended engagement. Not knowing anything your actor means responding like SS every time, which is not fun.