Pentest-Tools.com @pentest-tools.com · May 23

Your detection logic is asking the wrong question. Most orgs have invested heavily in signature-based detection. The monitoring of legitimate admin tooling, cloud consoles, and scripting environments? Still thin. That's exactly where LotL attacks live.

0 likes 1 replies

?

Replies

Pentest-Tools.com · May 23

Razvan Ionescu, head of professional services at Pentest-Tools.com, in ITPro: "Before asking what you'd detect, ask what an attacker with compromised admin credentials to your endpoint management platform, your identity provider or your cloud management console could do.