This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use tunneling. For example, to punch a reverse tunnel from a compromised…
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in Windows Server Update Services (WSUS) is a crit…
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Using DefendNot in XWorm Attacks 🪱 A cyber intelligence group has recorded phishing activity aimed at data theft followed by monetary extortion (screenshot 1)…
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
How to CVE-2025-54916? Low-effort vulnerability research 💻 Hi, ESC-VR here. The Telegram post format is rarely suitable for analyzing complex vulnerabilities, b…
Malware in SYSVOL: finding the source 😐 Let's say we're investigating a ransomware incident. The attackers used a Group Policy to launch the ransomware (for exa…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
🧤 Now about the exploitation of the vulnerability CVE-2025-33073: • A domain account with the most ordinary privileges. • SMB signing is not enforced on the tar…