Skip to content

Opening book details…

About this document

T1003 008 Lab Writeup by 郭文康 is a document available to read on EtoBox.

The document details a lab writeup analyzing a credential dumping attack on a Linux host, specifically focusing on the copying of /etc/passwd and /etc/shadow files and their exfiltration to a remote server. The investigation identified the attacker used sudo to escalate privileges and executed commands to copy, archive, and exfiltrate sensitive files via HTTP POST. Key findings emphasize the need for monitoring access to sensitive files, restricting sudo access, and implementing egress filtering to prevent

Author
郭文康
Language
EN