SC Media October 7, 2022
A new white paper from the Department of Health and Human Services Cybersecurity Coordination Center reminds healthcare providers that some of the legitimate security tools they rely on are also commonly abused by threat actors to deploy attacks or worsen the impact of an exploit.
The resource names a number of commonly used security tools, like Cobalt Strike, PowerShell, Mimikatz, Sysinternals, Anydesk, and Brute Ratel, as examples.
“The same tools used to operate, maintain and secure healthcare systems and networks can also be turned against their own infrastructure,” HC3 warned.
HC3 is not endorsing or criticizing the legitimate tools detailed in the report, “nor is it a call for healthcare organizations to avoid them.” Rather, it’s a call for...