[SCCM NTLM Relay]
[SCCM NTLM Relay] Hello everyone! 👋 My article about SCCM attacks was recently published. It describes in sufficient detail the testing lab, the attacks themsel…
[ FEED // CHRONO // 267 ITEMS ]
[SCCM NTLM Relay] Hello everyone! 👋 My article about SCCM attacks was recently published. It describes in sufficient detail the testing lab, the attacks themsel…
Radio enthusiasts, get ready 📻 The internal systems of the cyber intelligence group have discovered a hack of a website for radio enthusiasts. The site has exis…
Do you automate debugging? 🧐 The PT Sandbox expert team often has to debug various Windows kernel components in their work, and a kernel debugger is indispensab…
Where can the history of PowerShell commands be found? 🧐 Surely the first things that come to mind are Windows logs and the ConsoleHost_history.txt file, but th…
C2 hunting: part 2. Hunting for hacker servers by external signs 😁 In the previous part, we talked about how to expand knowledge about hackers' infrastructure u…
Move like water. Be still like a mirror. Respond like an echo... 🪞 In this post, we will discuss a discovered instance of a phishing page. It is notable for emp…
A fool and his money are soon parted, APK is not a video 🦣 In late 2024 — early 2025, information about the spread of the Mamont virus in Telegram was actively…
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…
Attacker published malicious packages deepseeek and deepseekai on the Python Package Index 🐳 The Supply Chain Security team of the Threat Intelligence departmen…
Rare Wolf is preparing to hunt 🐺 The PT ESC cyberthreat intelligence team consistently tracks down new command-and-control servers used by threat groups, as wel…
What happened to OpenSSH security in 2024 🚪 Let's look at the timeline: • Spring. Backdoor in xz-utils (CVE-2024-3094). As a result of its introduction, systems…