The DFIR Report on Twitter: "From Zero to Domain Admin ➡️Initial Access: Maldoc deploys Hancitor ➡️C2: #CobaltStrike & #Hancitor ➡️Discovery: net, nltest, check.exe, AD module, scan for backup systems ➡️Privilege Escalation: Zerologon CVE-2020-1472 https://t.co/gtiUAi9EQN" / Twitter

https://twitter.com/TheDFIRReport/status/1455138052708474885