TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Huntress

Proactive Account Review Uncovers Unauthorized | Huntress

2025-06-17 · Read original ↗

ATT&CK techniques detected

2 predictions
T1525Implant Internal Image
73%
"gcp - au. activtrak. net https : / / ws - gcp - au. activtrak. net https : / / api - au. activtrak. com"
T1685Disable or Modify Tools
45%
"operations center ( soc ) gets visibility into the native defender alerts and can correlate them with other findings in managed edr and managed security information and event management ( siem ). why are mav exclusions interesting? a mav exclusion is when defender is configured t…"

Summary

A routine account review revealed the use of productivity monitoring tools in a medical clinic, highlighting the hidden risks associated with employee monitoring software. Learn the importance of proactive audits in protecting critical systems and sensitive data from potential threats.