Gone Phishing: How an Intern’s Credentials can be a Gateway to Your Crown Jewels
2024-2-5 22:0:57 Author: www.horizon3.ai(查看原文) 阅读量:8 收藏

Six fishing poles mounted to the back of a motorized boat

“Who cares that the intern was phished during our phishing campaign? It’s an intern, they don’t have access to anything important.”

As a security practitioner, that mindset among business leaders drove me nuts. There are many ways a credential as innocuous as an intern’s could be used by an attacker to compromise a domain or gain access to sensitive data, but it was very difficult to articulate the “blast radius” of a phished credential.

That’s why I’m really excited to launch the new Phishing test type within NodeZero…

  1. A user sets up a phishing campaign using KnowBe4, Proofpoint, Mimecast or other phishing test tools.
  2. That user adds a few lines of javascript generated by NodeZero to their phishing page.
  3. Credentials caught by KnowBe4 are automatically injected into a running NodeZero pentest via the javascript copied into the phishing page.
  4. NodeZero then uses those phished credentials as part of its attack, finding ways to chain together credentials, misconfigurations, CVEs, and dangerous product defaults to achieve a technical objective (e.g. Domain Compromise, Sensitive Data Exposure, etc).
  5. The user gets a detailed report of the blast radius for every credential phished by the KnowBe4 campaign.

The NodeZero Phishing Impact test is first-to-market and gives you the ammunition required to drive meaningful improvements to the credential attack surface of your organization.

“Actually boss, the intern’s credentials enabled the attacker—NodeZero—to gain access to our sensitive financial data. Take a look for yourself…”

How can NodeZero help you?

Let our experts walk you through a demonstration of NodeZero, so you can see how to put it to work for your company.


文章来源: https://www.horizon3.ai/gone-phishing-how-an-interns-credentials-can-be-a-gateway-to-your-crown-jewels/
如有侵权请联系:admin#unsafe.sh