PRC's State-Sponsored Cyber Actr Living Off the Land to Evade Detection [pdf]

  • Given the nature of the news from the FBI today this feels relevant to re-post.

    ``` Some of the built-in tools this actor uses are: wmic, ntdsutil, netsh, and PowerShell. The advisory provides examples of the actor’s commands along with detection signatures to aid network defenders in hunting for this activity. ```