INTEL_REPORT
Microsoft Security Blog · published 5/12/2026, 3:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise Microsoft Incident Response investigated an attack operated through legitimate and trusted administrative mechanisms to blend seamlessly into routine operations and remain undetected demonstrating that intrusions have increasingly avoided using noisy exploits, obvious malware, or custom tooling, instead leveraging systems that organizations already trust within their environment…
https://www.microsoft.com/en-us/security/blog/2026/05/12/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-through-third-party-compromise
sha256:692d3a8aacc367b7dd4b7a6a3c200c5dc286b1b8c2842a46b7af011fa44003e0
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| ghost.inc |
| Open → |
| domain | dredeactede.net | Open → |