[ ARCHIVE ]

Author: oUth0R

// Threats

(Ex)Cobalt in container

(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…

oUth0R
// Detection

Mount point. Pt 2

Mount point. Pt 2 Hello! We decided to talk about disk mounting again. Today we'll tell you how to work with LVM containers. Here's a short manual so you don't…

oUth0R
// Detection

Mount Point — pt.1

Mount Point — pt.1 🙂 Any investigation is an analysis of operating system artifacts. And to obtain them, you often have to work with virtual machine images, suc…

oUth0R
// Threats

OWOWA

⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…

oUth0R
// Threats

Gapucino* is GOFFEE

Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…

oUth0R
// Threats

How to get on the internet

How to get to the internet 🚶‍♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…

oUth0R