Securelist reported that real-world compromise assessments repeatedly uncovered active and historical intrusions that had bypassed layered defenses, often because basic security controls failed in practice. Investigators linked successful breaches to delayed patching of internet-facing systems, employee and third-party policy violations, missed detections by MSSPs and SOCs, incomplete incident response, and misconfigured or ineffective tooling that left attackers operating undisturbed.
In one case, attackers exploited a late-patched public web server, deployed a SILENTTRINITY C2 stager, used a custom-packed Mimikatz variant and LSASS memory dumping to steal credentials, then performed SMB reconnaissance until gaining domain administrator access. Other assessments found credential exposure through a third-party consultant, repeated webshell activity that an MSSP failed to escalate despite antivirus alerts, and malicious Active Directory Group Policy changes that enabled reversible password storage and weakened Kerberos auditing, underscoring compromise assessment as a last-resort method for finding hidden attacker persistence and validating whether defenses are actually working.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky's compromise assessment findings included a case of a dormant NSABuffMiner infection that had exploited EternalBlue and remained undetected in an environment. The case was cited as an example of long-lived hidden compromise uncovered during assessment work.
One investigated case uncovered malicious Active Directory Group Policy changes that enabled reversible password storage and reduced Kerberos auditing. These changes were highlighted as attacker actions that degraded security controls and hindered detection.
A separate compromise assessment case found that an MSSP failed multiple times to detect or act on webshell activity even though antivirus detections were present. The case was cited as an example of SOC or MSSP detection failure allowing an intrusion to persist.
Another case described credential leakage through a third-party consultant as a root cause contributing to compromise. The article presents this as a real-world investigation finding tied to policy violations and weak third-party security practices.
In one compromise assessment case, a public-facing web server was left unpatched and was subsequently compromised. The attacker deployed a SILENTTRINITY C2 stager, used a custom packed Mimikatz and LSASS memory dumping, conducted SMB reconnaissance, and ultimately obtained domain administrator credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securelist.ru
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.