A cart full of hackers
Hackers' Telegram Cart According to the latest trends (e.g., Lazy Koala), attackers are increasingly resorting to data exfiltration or C2 channels via the Teleg…
Hackers' Telegram Cart According to the latest trends (e.g., Lazy Koala), attackers are increasingly resorting to data exfiltration or C2 channels via the Teleg…
Missed the moment a phishing attachment was launched again? 📩 So what? The accountant is sure it was an "invoice" from a trusted bank. It's time to teach SIEM s…
Do you see the authorization form? No. Neither do I. But it's there 🤔 During a recent investigation of one of the incidents, we encountered exploitation by atta…
🥷 Cobalt Strike Beacon and MSBuild The practice of our incident investigations shows that threat actors are still using the Microsoft Build Engine to compile .N…
💻 While investigating an incident, we discovered a useful artifact, smb_context C:\Windows\SysWOW64\smb_context.log — the SMB event log from a well-known antivi…
📬 Exchange_SSRF Our practice shows that a fairly large number of organizations still have not installed updates on their public Microsoft Exchange mail servers…
utmpdump dual-use Default Unix systems have little forensic information (vs Windows) and a lot of useful utilities. For example, there is a "wonderful" utility…