Detecting CVE-2025-33073
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
In addition to the previous post, we want to talk about some other potential ways of detecting the execution of malicious code in the "1C" system 😳 • First, if…
Following the 1C_Shell trail. Investigating attacks using the event log 🐾 In one of our previous posts, we wrote about detecting attacks on the 1C system in whi…
Exchange Mutation. How We Caught Anomalies in Outlook Pages 😮 Continuing our series of incident investigation stories (you can read about them here, here, and p…
🛡 Puma: how a rootkit provides covert SSH access through stealthy key substitution Continuing our story about the activities of the ExCobalt group and its new t…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
🐾 Following in Puma's Footsteps: How to Detect a Rootkit Through Its Own Interface Today, our review covers a technically interesting and multifunctional Linux…
⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability The vulnerability CVE-2025-24071, affecting a wide range of Windows operati…
Graphics with a Surprise: When Vectors Hide Malicious Code 🤨 In this post, we will examine an example of a phishing email in which malicious content was deliver…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
😐 “Why aren't you answering?”, or The Story of How to Steal a Telegram Account Without Registration or SMS Recently we published an article about the most popul…
1C_shell for "1C" 🦞 Sometimes situations arise when, during an information security incident investigation, the traditionally used OS artifacts contain extremel…