Oct. 25, 2022, 9:50 a.m. | /u/sadboy2k03

cybersecurity www.reddit.com

I was having a talk with a couple guys from the last security ops centre I worked and one of them is convinced that exploits and attacker methodologies exist within the Intune application/GP to drop Ransomware or Cobalt Strike. He asked me if i've seen this activity before from threat actors which, honestly I haven't

​

My original thoughts on this is that this would not be possible unless an account with permissions to modify GP/Intune was compromised already, but …

cobalt cybersecurity intune ransomware

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Engineer, Incident Response

@ Databricks | Remote - Netherlands

Associate Vulnerability Engineer - Mid-Atlantic region (Part-Time)

@ GuidePoint Security LLC | Remote in VA, MD, PA, NC, DE, NJ, or DC

Data Security Architect

@ Accenture Federal Services | Washington, DC

Identity Security Administrator

@ SailPoint | Pune, India