The employee changed his Microsoft 365 password twice.
The attacker still logged back in.
That was the moment we knew we were not dealing with a normal stolen-password incident.
The first alert came from an impossible-travel sign-in. The employee had authenticated from Maryland, then the same account appeared from another country less than an hour later.
We reset the password.
Twenty minutes later, another suspicious session appeared.
So we reset it again and forced MFA re-registration.
The attacker came back.
At that point, I stopped looking at the account and started looking at the employee’s laptop.
Inside the Downloads folder was a file called:
Invoice_Viewer.exe
The employee remembered downloading it from a website that claimed he needed a special viewer to open an invoice.
Windows logs showed the file running at 9:14 AM.
Seconds later, it launched PowerShell in the background.
Then we found something else.
A scheduled task called MicrosoftEdgeUpdateCheck had been created on the machine.
The name looked legitimate enough to ignore if you were moving quickly, but it was not one of Microsoft Edge’s normal update tasks.
We also found an outbound HTTPS connection from the compromised host to an external IP address.
The file hash was submitted for malware analysis.
It came back as an information stealer.
That explained why changing the password had not solved the problem.
The malware had stolen browser data, including authentication cookies and active session information.
The attacker was not repeatedly discovering the employee’s new password.
They were reusing a session that had already been authenticated.
We revoked every active Microsoft 365 session, isolated the laptop from the network, removed the persistence, reset the credentials again, and rebuilt the endpoint.
The suspicious logins finally stopped.
A compromised account does not always mean the attacker still knows your password.
Sometimes you already changed the password.
The attacker is still inside because they stole the session.
Estoy en búsqueda de un nuevo desafío profesional.
Después de más de 20 años en tecnología y los últimos años dedicado de lleno a la ciberseguridad ofensiva y defensiva, llegó el momento de dar el siguiente paso.
Durante este tiempo tuve la oportunidad de:
• Ejecutar más de 150 proyectos de Pentesting y Red Team para empresas privadas y organismos públicos.
• Trabajar con clientes nacionales e internacionales realizando auditorías de aplicaciones web, APIs, infraestructura, Active Directory y entornos Cloud.
• Colaborar con equipos de Blue Team, respuesta a incidentes y hardening de infraestructura.
• Formar a miles de profesionales en ciberseguridad y construir una comunidad de más de 50.000 personas apasionadas por este campo.
Hoy estoy abierto a nuevas oportunidades como:
🔴 Senior Pentester
🔴 Red Team Operator
🔴 Offensive Security Engineer
🔴 Security Consultant
🔴 Application Security (AppSec)
🔴 Cloud Security
🔴 Technical Lead en Ciberseguridad
Busco un equipo donde pueda aportar experiencia técnica, criterio, liderazgo y seguir creciendo profesionalmente.
📍 Disponible para trabajo remoto, híbrido o presencial. También estoy abierto a relocalización.
Si conocés una empresa que esté buscando fortalecer su equipo de seguridad ofensiva, agradecería mucho que compartieras esta publicación o me pongas en contacto.
¡Muchas gracias!
#CyberSecurity #Pentest #RedTeam #EthicalHacking #OffensiveSecurity #AppSec #CloudSecurity #InformationSecurity #OpenToWork #Hiring
¡Seguimos buscando nuevos desafíos!
Gracias a todos los que compartieron y recomendaron mi búsqueda. Gracias a ustedes ya surgieron nuevos proyectos y propuestas laborales.
Pero la búsqueda continúa.
Estoy abierto a nuevas oportunidades en:
🔹 Pentesting / Ethical Hacking
🔹 Red Team / Offensive Security
🔹 AppSec / Cloud Security
🔹 Consultoría y liderazgo técnico
🔹 Ciberseguridad en general
También considero posiciones de Analista de Ciberseguridad o Técnico de TI.
📍 Remoto | Híbrido | Presencial
Si conocés una empresa que esté buscando un perfil como el mío, mandame un mensaje o compartí esta publicación.
Una recomendación puede hacer que llegue a la persona indicada.
Gracias por el apoyo. Vamos por el próximo desafío.
Most people want to become hackers.
Very few ever learn how computers actually work.
That's why Hacking: The Art of Exploitation (622 pages) has been a classic for years.
Instead of teaching tools, it teaches the fundamentals behind exploitation, memory, assembly, C, debugging, shellcode, and real hacking techniques.
I'm giving it away to the first 4500 people only.
Once the limit is reached, I'll stop sending it.
How to get
Follow me (so I can DM you)
Like + RT
Comment "HACK"
I'll DM it while the giveaway is still open.