The DFIR Report on Twitter: "Exchange Exploit Leads to Domain Wide Ransomware TTR: 42 Hours Initial Access: Exchange Exploited (ProxyShell) Discovery: ipconfig, nslookup, ping, KPortScan, etc. Execution: Fast Reverse Proxy & Plink Lateral Movement: RDP Impact: Data Encryption https://t.co/adxHmp4P7K" / Twitter
https://twitter.com/TheDFIRReport/status/1460221329953669123