Skip to main content
Need help with a cyber incident now?
Call 24/7: +31 88-2747800

Three attack scenarios after ZeroLogon exploit

By 23 February 2021 March 10th, 2021 Blog, CERT
aanvalsscenario's na misbruik ZeroLogon

In recent months, the Tesorion CERT (T-CERT) identified an attacker that was able to execute commands, using an account with Domain Administator privileges, only three minutes after initial access. Further analysis identified exploitation of the ZeroLogon vulnerability (CVE-2020-1472).

We investigated three possible attack scenarios which an attacker could use after exploiting the ZeroLogon vulnerability. The T-CERT simulated each scenario to identify Indicators of Compromise which are related to these attack scenarios when carried out using the Mimikatz tool.

Brute force authentication of the ZeroLogon vulnerability

The above illustration shows the network traffic used to exploit the vulnerability. You can see a brute force of the authentication which we describe in detail in the white paper ZeroLogon: Exploit, Detect & Mitigate.