Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-access-methodlateral-movement-methodpersistence-methodcommand-and-control-method

Compromise Assessments Expose Missed Intrusions and Security Control Failures

Updated 8d agoFirst seen May 21, 20261 source

Securelist reported that real-world compromise assessments repeatedly uncovered active and historical intrusions that had bypassed layered defenses, often because basic security controls failed in practice. Investigators linked successful breaches to delayed patching of internet-facing systems, employee and third-party policy violations, missed detections by MSSPs and SOCs, incomplete incident response, and misconfigured or ineffective tooling that left attackers operating undisturbed.

In one case, attackers exploited a late-patched public web server, deployed a SILENTTRINITY C2 stager, used a custom-packed Mimikatz variant and LSASS memory dumping to steal credentials, then performed SMB reconnaissance until gaining domain administrator access. Other assessments found credential exposure through a third-party consultant, repeated webshell activity that an MSSP failed to escalate despite antivirus alerts, and malicious Active Directory Group Policy changes that enabled reversible password storage and weakened Kerberos auditing, underscoring compromise assessment as a last-resort method for finding hidden attacker persistence and validating whether defenses are actually working.

Share:
Compromise Assessments Expose Missed Intrusions and Security Control Failures
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 21, 20261mo ago

Malicious AD Group Policy changes weakened domain security

One investigated case uncovered malicious Active Directory Group Policy changes that enabled reversible password storage and reduced Kerberos auditing. These changes were highlighted as attacker actions that degraded security controls and hindered detection.

Compromise assessment in cybersecurity: real-world cases | Securelist

MSSP repeatedly missed webshell activity despite AV detections

A separate compromise assessment case found that an MSSP failed multiple times to detect or act on webshell activity even though antivirus detections were present. The case was cited as an example of SOC or MSSP detection failure allowing an intrusion to persist.

Compromise assessment in cybersecurity: real-world cases | Securelist

Third-party consultant credential leakage enabled compromise

Another case described credential leakage through a third-party consultant as a root cause contributing to compromise. The article presents this as a real-world investigation finding tied to policy violations and weak third-party security practices.

Compromise assessment in cybersecurity: real-world cases | Securelist

Delayed patching led to web server compromise and domain admin access

In one compromise assessment case, a public-facing web server was left unpatched and was subsequently compromised. The attacker deployed a SILENTTRINITY C2 stager, used a custom packed Mimikatz and LSASS memory dumping, conducted SMB reconnaissance, and ultimately obtained domain administrator credentials.

Compromise assessment in cybersecurity: real-world cases | Securelist
SOURCE COVERAGE

Sources

1 reference tracked. Mallory keeps watching after this page renders.

1 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Compromise Assessments Expose Missed Intrusions and Security Control Failures | Mallory