SEC.co Podcast

Attackers in 2025 aren't reinventing the wheel — they're refining techniques that defenders keep leaving open. This episode breaks down six post-exploitation tactics still delivering results, and the practical controls that can actually stop them.

Show Notes

Sophisticated breaches rarely hinge on novel zero-days. More often, they succeed because a handful of well-worn post-exploitation techniques continue to find gaps in enterprise defenses — year after year. This episode of Cybersecurity draws on this in-depth look at post-exploitation tactics still working in 2025 to examine exactly which methods attackers keep reaching for, why they remain effective, and what defenders can do beyond just alerting.

The episode walks through six tactics — each paired with actionable defensive guidance — covering the full arc from initial foothold to cloud-native lateral movement:

  • Living-off-the-Land Binaries (LOLBins): Attackers are chaining pre-installed, code-signed Windows tools — including WSL and IPv6-aware utilities — to blend into normal admin activity and bypass legacy egress filters. Defenders need behavioral baselines and auto-containment, not just alerting.
  • Kerberoasting in hybrid identity environments: Syncing on-premises Active Directory with Azure AD gives attackers a bridge from an offline-cracked ticket straight into cloud control — often bypassing MFA entirely. Group Managed Service Accounts and Azure AD risk policies are the core mitigations.
  • Cloud control-plane token theft: Cached CLI credentials and buried token files on developer workstations open a window for rapid cloud resource abuse and exfiltration before billing alerts fire. Near-real-time log streaming and just-in-time role assignment close the lag attackers depend on.
  • Bring-Your-Own-Driver EDR tampering: Sideloading a legitimately signed but vulnerable kernel driver can blind or crash EDR agents without triggering OS-level warnings. Kernel Mode Code Signing enforcement and automated vulnerable-driver hash checking are essential countermeasures.
  • Adversary-in-the-Middle phishing against MFA: Modern AiTM kits proxy real authentication sessions to harvest valid post-MFA cookies — some now using vision APIs to self-correct in real time. FIDO2/passkey adoption and device-posture-aware Conditional Access policies are the most durable defenses.
  • SaaS-to-SaaS lateral movement via OAuth: Over-permissive OAuth grants between sanctioned apps let attackers hop from a low-value marketing tool to a financial data warehouse through calls that look entirely legitimate on the wire. Full OAuth inventory, least-privilege scope enforcement, and SaaS Security Posture Management (SSPM) provide the needed visibility.

The episode closes by identifying the common thread across all six tactics: attackers exploit organizational gaps — between cloud and on-premises, between identity stores, between telemetry and analytics — not just technical vulnerabilities. The key takeaways center on response speed over tooling sophistication, unified telemetry with identity context, and automating repetitive security hygiene so teams can focus on hunting and strategy.

For more on defending against advanced evasion techniques, listen to Payload Detonation in Cloud Sandboxes: Evasion Tactics and Defenses, a related episode exploring how attackers bypass cloud-based analysis environments.

SEC

What is SEC.co Podcast ?

A podcast about latest trends, techniques and learnings in cybersecurity and cyberdefense.