Your Employee Got Hacked. Now What? | Ep 198
Show notes
Users will get compromised. Someone will click the link, and credentials will get stolen. The question that really matters is what happens next.
In this episode, Spencer and Brad walk through the Post-Compromise Risk Framework (PRID), a simple, repeatable way for IT and security teams to judge how exposed their environment is once an attacker gets in. Using a real-world-style ClickFix scenario involving "Susie in accounting," they trace how one compromised account can lead to lateral movement, credential dumping and sensitive data exposure. They also cover why so many of those steps go undetected.
In this episode:
- Why the assume breach mindset is the best way to measure your security
- Privileges: what can a compromised user actually do?
- Reach: where can they go with that access?
- Impact: how bad would it be?
- Detection: would you even know it happened?
- How least privilege and network segmentation map to each step
- Why PS Remoting to a domain controller goes undetected nine times out of 10
- Why "that couldn't happen here" is not proof, and how to verify your controls
- "Inspect what you expect": testing your EDR instead of trusting it
Pick a user, assume they're compromised, and walk the path. You'll learn more about your environment, and you'll likely find issues you didn't know were there.
Work with Us: https://securit360.com
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com