As cited
Copy frozen at (site build).
threat intel
Velociraptor WSUS Exploitation, Pt. I: WSUS-Up?
Huntress has observed an increase in threat actors leveraging Velociraptor, an open-source digital forensics and incident response (DFIR) tool, for various attacks including exploitation of Windows Server Update Services (WSUS). The activity suggests adversaries are repurposing legitimate security tools to conduct offensive operations.
Why it matters: Security teams should monitor for suspicious Velociraptor activity and WSUS exploitation attempts in their environments, as these techniques could indicate post-compromise activity or lateral movement by attackers using legitimate tools to evade detection.
- Source published
- First seen by Cybersecurity Tracker