[ GROUP // RULES // 20 ITEMS ]

RULES

> in section Detection

// Threats

New connection to old techniques

A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…

oUth0R
// Detection

Detecting CVE-2025-33073

Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️‍♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…

global_author
// Threats

Yara-Yara

Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…

global_author
// Threats

Yara Yara Daze

Yara Yara Daze Anyone involved in malware analysis is certainly familiar with a tool like YARA 😉. With its help, many companies 🔴 build sets of signature rules…

global_author
// Threats

(Ex)Cobalt == (Ex)Carbanak

(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…

oUth0R
// Detection

A complex password won't help

A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…

oUth0R