CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Sophos 2026 Active Adversary Report

report · report:sophos-active-adversary-2026 single-source

Sophos 2026 Active Adversary Report, identity-dominant root causes; Impacket/AnyDesk

Coverage
1
first 2026-06-03 → last 2026-06-03
Latest activity
2026-06-03
Sophos 2026 Active Adversary Report: identity is the dominant intrusion root cause
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance, manufacturing
Sources cited
1
1 hosts

Story timeline

  1. 2026-06-03Sophos 2026 Active Adversary Report: identity is the dominant intrusion root cause
    research

Entries about Sophos 2026 Active Adversary Report (1)

2026-06-03 · view entry permalink →

NOTABLE

Sophos 2026 Active Adversary Report: identity is the dominant intrusion root cause

Sophos published its 2026 Active Adversary Report (drawing on 661 IR/MDR cases) on 2026-06-02 (Sophos X-Ops, 2026-06-02). Per PD-9 this report gets one treatment; the findings that change defender priorities rather than the survey scorecard: identity-based compromise (stolen/valid credentials, brute force, and phishing) was the leading root cause, and missing or misconfigured MFA was present in a majority of incidents. Time from initial access to Active Directory compromise has compressed materially, with Impacket among the most frequently observed post-exploitation toolkits and AnyDesk the most-abused legitimate remote-access tool. The recurring telemetry blind spots are the actionable part: firewall logs were missing in roughly half of ransomware cases, and a meaningful share of compromised Windows Servers were running end-of-life builds. [SINGLE-SOURCE] (vendor IR telemetry report).

Why it matters to us: The hunt targets generalise directly to public-sector AD estates, alert on Impacket artefacts (impacket-* tool names in process trees, secretsdump-style NTDS access, SMBExec/WMIExec parent processes), instrument the initial-access-to-DC-compromise window, inventory EOL Windows Servers, and verify firewall log retention before an incident rather than during one.

annual-report03 Jun 05:00Zsingle-sourceOpen finding →
Sources: Sophos X-Ops

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • sophos.com1 (100%)