Conti Collect and Exfiltrate

Опубликовано: 21 Июнь 2026
на канале: Prelude
90
1

TTP Tuesday release for 08 Feb 2022, this is the fifth chain for our Conti ransomware theme. we enumerate the users home directory then attempt to dump hashes via Kerberoasting and AS-REProasting. Once we have target data, the ingress and configure Rclone to work with an ephemeral Mega account then automatically exfiltrate to a Data folder in Mega. We have 1 more week to go in our Conti theme providing you with an entire Conti adversary attack from beginning to end.

Please subscribe and reach out with any feedback. We love to hear from our community!

There are several ways to follow us and learn more about Prelude and our team members:

GET OUR PRODUCTS
----------------
Download Prelude Operator: https://www.prelude.org/download/current
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg

JOIN OUR COMMUNITY
------------------
Discord:   / discord  
Reddit:   / preludeorg  
Twitter:   / preludeorg  

READ, WATCH, AND LISTEN
-----------------------
Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org/
Watch our live streams:   / preludeorg  
Watch our pre-recorded content:    / preludeorg  

FOLLOW OUR TEAM
---------------
David:   / privateducky  
Alex:   / khyberspache  
Kris:   / xanthonus  
Octavia:   / vv_x_7  
Sam:   / wasupwithuman