\f0\fs24 \cf0 Ticket: 473822\ |
Incident: Tangerine Yellow\ |
Date: 2/15/2019 14:54:03\ |
Description: cmd.exe commands via Pineapple RAT\ |
Status: Assigned\ |
\ |
The following commands were collected via Sysmon following Pineapple RAT \ |
execution on the beachhead box.\ |
\ |
\ |
ipconfig /all\ |
arp -a\ |
tasklist /v\ |
sc query\ |
systeminfo\ |
net group "Domain Admins" /domain\ |
net user /domain\ |
net group "Domain Controllers" /domain\ |
netsh advfirewall show allprofiles\ |
netstat -ano\ |
\ |
\ |
\'a92019 The MITRE Corporation. ALL RIGHTS RESERVED\'a0 Approved for public release. Distribution unlimited 18-1528-43. } |