Jan. 19, 2023, 1:02 a.m. | /u/Flaky_Card2907

cybersecurity www.reddit.com

*I can’t give too much details as this is work related*

I reviewed a lateral movement alert where the source address was an APIPA address. The said activity was terminated while in the process of encrypting files.

My question is what technique would be used to spoof this information?

The alert was generated by one of the top vendors EDR. Is this some sort of spoofing / redirection going on?

EDIT: A word

address alert apipa cybersecurity edr files generated information lateral movement process question sort spoof spoofing vendors word work

PMO Cybersécurité H/F

@ Hifield | Sèvres, France

Third Party Risk Management - Consultant

@ KPMG India | Bengaluru, Karnataka, India

Consultant Cyber Sécurité H/F - Strasbourg

@ Hifield | Strasbourg, France

Information Security Compliance Analyst

@ KPMG Australia | Melbourne, Australia

GDS Consulting - Cyber Security | Data Protection Senior Consultant

@ EY | Taguig, PH, 1634

Senior QA Engineer - Cloud Security

@ Tenable | Israel