Initial Access Tactics, techniques and procedures

From Enlace Hacktivista
Revision as of 22:29, 2 April 2023 by Booda (talk | contribs)
Jump to navigation Jump to search

Phishing

Password Attacks

In our engagements we will try many things to gain an initial foothold, however it's best to try all the low hanging fruits before diving deep into a full social engineering and penetration testing engagement.

Groups like Lapsus$ show's the world that you don't need to be a great technical hacker to pwn massive corporations and if common password and multi-factor authentication (MFA) attacks work on the likes of Uber, Rockstar games, Okta and so on then they will work on our hacktivist targets!

If your target uses multi-factor authentication you can try either social engineering or MFA fatigue.

username creation based on recon/osint

Passwords

password cracking tools

Searching leaks

Services

Please note: DO NOT use intelx[.]io as they have been seen doxing hackers in the past and block the use of VPNs, proxies and Tor. AVOID!

Buying Access

You can use the genesis market to purchase credentials stolen from targets through the use of info stealer malware. Search your target here to see if you can make a quick win gaining access to an admin account. Any account that allows internal access is always a great start. Invites can be found on forums and markets.

Password spraying

CVE POCs