I hunted for plaintext passwords in files and configurations and addressed weak Active Directory passwords and NTLMv1 authentication. This work accompanied the SQL and SMB detections within the wider Red Team follow-up, connecting observed attack opportunities to credential exposure and authentication controls.
Viewed
UK Water Utility
Hunt for credentials and strengthen authentication
From Red Team findings to SQL and SMB detections
Return to the full story ←