Please enable JavaScript.
Coggle requires JavaScript to display documents.
Ransomware scenario - Coggle Diagram
Ransomware scenario
Remediation
-
-
-
Execution of .exe .js ...
- whitelisting of trusted applications
-
-
-
-
-
14 Issues
3 High
-
-
- Zerologon Attack (CVE-2020-1472)
9 Medium
- Command and Scripting Interpreter in
Use
-
- Insufficient Antivirus Policies
- Insufficient Host-Based Windows Firewall
Configuration
-
- Lack of Network Level Control
- Persistence via Task Scheduler
- Proxy Setup Script Can Be Turned Off
- PowerShell Version 2 in Use
2 Low
-
- Writeable Shares Accessible by Domain
User