[ ARCHIVE ]

Author: oUth0R

// Threats

By the way, about Offzone

By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…

oUth0R
// Detection

Exfiltration gone wrong

😈 Exfiltration Gone Wrong When investigating incidents, we periodically encounter threat actors exfiltrating data before encrypting infrastructure. One of the e…

oUth0R
// Detection

Analysis of reports.db

☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described i…

oUth0R
// Threats

Industrial-scale exfiltration

Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…

oUth0R
// Detection

Exchange_SSRF

📬 Exchange_SSRF Our practice shows that a fairly large number of organizations still have not installed updates on their public Microsoft Exchange mail servers…

oUth0R
// Detection

utmpdump dual-purpose

utmpdump dual-use Default Unix systems have little forensic information (vs Windows) and a lot of useful utilities. For example, there is a "wonderful" utility…

oUth0R