The DFIR Report on Twitter: "Quantum Ransomware ➡️TTR: 3h 48 minutes ➡️Initial Access: IcedID ISO ➡️Persistence: Scheduled Tasks ➡️Discovery: WMIC, net, nltest, AdFind, etc. ➡️C2: Cobalt Strike ➡️Lateral Movement: PsExec, WMI, RDP ➡️Impact: Domain wide ransomware https://t.co/Py3FqlElJx" / Twitter
https://twitter.com/TheDFIRReport/status/1518557060639735810