Attack Tool(s): CredMaster, Burp Suite, Hashcat, Hydra
- CredMaster: https://github.com/knavesec/CredMaster
- Burp Suite: https://portswigger.net/burp
- Hashcat: https://hashcat.net/hashcat/
- Hydra: https://github.com/vanhauser-thc/thc-hydra
Detection Link(s):
- Server Analysis
- User and Entity Behavior Analytics (UEBA)
- Cloud Event Log Analysis
- Security Information and Event Management (SIEM) Log Analysis
Helpful Blogs (BHIS):
- “Running Hashcat on Ubuntu” – https://www.blackhillsinfosec.com/running-hashcat-on-ubuntu-18-04-server-with-1080ti – Hashcat setup.
- “Using Simple Burp Macros” – https://www.blackhillsinfosec.com/using-simple-burp-macros-to-automate-testing – Burp Suite tips.
