Hacker News new | ask | show | jobs
by marcinzm 2162 days ago
The attackers likely compromised the computers using the remote device management system which means it's either disabled or unsafe to use.
1 comments

Sure, you need to make sure your AD and device management is clean before starting the process. My point was that once you're bootstraped you shouldn't need a fully manual recovery process.
And I'm pointing out that when your attacker has control of device management they can also disable device management on all the devices after their attack is deployed.