We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system sh…
[ SECTION // DETECT // 122 ITEMS ]
4 groups across 19 tags
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system sh…
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the fi…
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…
Recently, the Department for Comprehensive Response to Cyberthreats (PT ESC IR) received a number of samples of an Android banking trojan with remote control ca…
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use tunneling. For example, to punch a reverse tunnel from a compromised…
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in Windows Server Update Services (WSUS) is a crit…
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Using DefendNot in XWorm Attacks 🪱 A cyber intelligence group has recorded phishing activity aimed at data theft followed by monetary extortion (screenshot 1)…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simples…
How to create rules for network traffic to address a future threat 🤨 This was discussed this week in China during the third cybersecurity summit, which included…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
Dissecting network traffic with ML in search of new malware 📖 🧪 We — the network expertise department team of the ESC antivirus laboratory and the machine learn…
A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…
In the first part, we examined the decryption of TLS connections, which are often used on the internet. But if we move inside a corporate environment, other pro…
🦈 Looking Under the Hood of Secure Connections in Wireshark. Part 1: TLS Our network experts often need to decrypt TLS connection traffic and analyze protected…
How long has it been since you reversed JavaScript? 😲 Continuing the phishing theme (we previously looked at targeted suspicious documents leading to initial ac…
🔄 Major malware rules update Suricata I hope you remember that we have a public Suricata rules repository (we wrote about launching the resource in another post…