"Storm-0501 is the latest threat actor observed to exploit weak credentials and over-privileged accounts to move from organizations' on-premises environments to cloud environments."
"After gaining initial access and code execution capabilities on the affected device in the network, the threat actor performed extensive discovery to find potential desirable targets such as high-value assets and general domain information like Domain Administrator users and domain forest trust."
Collection
[
|
...
]