@drwhax I think the biggest lesson here is that Blue Team can't rely on patching to keep everything safe.
We have to actually do the rest of the stuff that security calls for, and not just keep everything patched but do more to minimize the risks when one of these unsleeping tools gets turned on us.
And so many companies don't even have a proper inventory of what-all needs to be kept up to date.
This is going to suck so much.