5/5 Lateral Movement Assessment
Using valid administrator credentials, the attacker leveraged remote execution utilities to access additional internal hosts.
Observed Attack Chain:
PHPStudy Exploitation
โ Discovery
โ Payload Deployment
โ C2 Establishment
โ Persistence
โ Credential Access
โ Network Discovery
โ Lateral Movement
This intrusion demonstrates how a single vulnerable web application can rapidly evolve into broader internal compromise.
1/5 Threat Activity Analysis
Source: Attack simulation telemetry analysis.
Initial access was achieved through exploitation of a vulnerable PHPStudy deployment. The attacker executed reconnaissance commands to identify the current user context, network configuration, ARP cache, and external connectivity.
Assessment: The activity indicates validation of code execution capabilities prior to payload deployment.
ATT&CK: T1190, T1082, T1016
โก Fresh Talk Alert for BSides Luxembourg 2026!
๐ฌ๐ข๐จ๐ฅ ๐๐ง๐ ๐ฅ๐๐ฃ๐ข๐ฅ๐ง๐ฆ ๐๐ฅ๐ ๐จ๐ฆ๐๐๐๐ฆ๐ฆ ๐ช๐๐ง๐๐ข๐จ๐ง ๐ฆ๐ง๐ฅ๐จ๐๐ง๐จ๐ฅ๐: ๐๐ฅ๐ข๐ ๐จ๐ก๐ฆ๐ง๐ฅ๐จ๐๐ง๐จ๐ฅ๐๐ ๐ง๐๐ฅ๐๐๐ง ๐๐ก๐ง๐๐ ๐ง๐ข ๐ฆ๐ง๐๐ซ ๐๐ก๐ข๐ช๐๐๐๐๐ ๐๐ฅ๐๐ฃ๐๐ฆ ๐ช๐๐ง๐ ๐๐๐ ๐ฆ ๐๐ก๐ ๐ ๐๐ฃ ๐ฆ๐๐ฅ๐ฉ๐๐ฅ โ Antonio Formato
Turn unstructured threat intelligence into actionable, machine-readable defense logic in this deep dive from the Actionable CTI & Detection Engineering Village. Every week, critical threat reports are published in PDFs and blog posts โ rich in insight but unusable for SIEMs, SOARs, or AI agents. This talk shows how to bridge that gap using a hybrid architecture that combines deterministic extraction and LLM-based semantic inference to generate STIX 2.1 knowledge graphs.
Youโll explore how threat reports can be transformed into structured intelligence objects, mapped to MITRE ATT&CK, and visualized as interactive knowledge graphs. The session also introduces TI Mindmap HUB, an independent research platform that converts real-world reports into multi-layered CTI views including ATT&CK heatmaps, Diamond Model structures, and CVE prioritization.
A key focus is the Model Context Protocol (MCP), which exposes structured CTI as tool calls for AI agentsโmaking intelligence directly usable in automated workflows, SOC tooling, and AI copilots. The talk concludes with emerging research into LLM-inferred threat intelligence knowledge graphs and cross-report correlation at scale.
Antonio Formato is a Senior Cybersecurity Solution Engineer at Microsoft and an independent researcher focused on Generative AI for Cyber Threat Intelligence. He is the creator of TI Mindmap HUB and co-author of academic research on automated STIX 2.1 generation currently under peer review.
๐
Conference Dates: 6โ8 May 2026 | 09:00โ18:00
๐ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #CTI #ThreatIntelligence #STIX #MITREATTACK #AISecurity #DetectionEngineering
๐ฎ The Return of Malware & Monsters: Collaborative IR Gaming (2h Workshop) on May 6th!
๐๐ข๐ง๐ง๐ ๐๐ข๐ก๐ง๐๐๐ก '๐๐ ๐๐๐: ๐๐ข๐๐๐๐๐ข๐ฅ๐๐ง๐๐ฉ๐ ๐๐ก๐๐๐๐๐ก๐ง ๐ฅ๐๐ฆ๐ฃ๐ข๐ก๐ฆ๐ ๐ง๐ฅ๐๐๐ก๐๐ก๐ ๐ง๐๐ฅ๐ข๐จ๐๐ ๐๐๐ ๐๐ก๐ with Klaus Agnoletti (@klausagnoletti) & ๐๐๐๐ก ๐ฆ๐ข๐ฅ๐๐ก๐ฆ๐๐ก - 6 May, 9AM - 11AM
Back by popular demand after last year's hit! Ditch dull tabletops for Malware & Monsters โ tabletop RPG meets creature-collecting where teams hunt/contain digital threats in story-driven scenarios with MITRE ATT&CK-mapped malware "malmons." Experience real IR chaos: coordination under pressure, incomplete intel, stakeholder drama. Take roles like Hunter, Analyst, Forensicator, Communicator to see how teams actually collaborate. Learn mechanics, build custom scenarios from real malware history, run live sims with "type effectiveness" for defenses and evolution for escalating attacks. Walk away with free, ready-to-use materials for fun, effective IR training.
Led by Klaus Agnoletti https://pretalx.com/orga/event/bsidesluxembourg-2026/speakers/SQVVHK/ (infosec pro since 2004, BSides Kรธbenhavn co-founder, storytelling cyber advisor, neurodiversity advocate) & Glen Sorensen https://pretalx.com/orga/event/bsidesluxembourg-2026/speakers/J3PRCC/ (Recovering CISO, DeleteMe Solutions Engineer, OSINT/AI expert, HackBack Gaming Incident Master).
๐
Conference dates and time: 6โ8 May 2026 | 9AM - 6PM
๐ Venue: 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
Game your way to better IR skills โ popular return engagement! ๐ฒ
#BSidesLuxembourg2026 #IncidentResponse #CyberSecurityTraining #BlueTeam #GameBasedLearning #MITREATTACK #BSides #DnD #DFIR
If the Kardashians launched their own framework it would be Kommand and Kontrol (K2).
The Momager (Kris.exe or Kris.sh): The primary C2 listener.
The Glow Up: Privesc
Keeping Up: Lateral movement
#C2Framework #RedTeaming #PostExploitation #MalwareDevelopment #Infosec #CyberSecurity #EDRBypass #ActiveDirectory #PenTesting #ThreatHunting #MITREATTACK #APTHunting #Shellcode #ZeroDay #Persistence #Exfiltration #BlueTeam #PurpleTeaming #kardashians
Why the MITRE ATT&CK Framework Actually Works: https://levelup.gitconnected.com/why-the-mitre-att-ck-framework-actually-works-29ac26d2d20c
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux