Analysis of reports.db
☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described i…
☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described i…
ℹ️ Exfiltration using PowerShell/C# During an incident investigation, while analyzing Windows event logs on one of the compromised hosts, we discovered that a P…
Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…
DPAPI — a popular vector for attacks on Windows-family OS 💻 Wi-Fi keys, certificates, credentials, browser cookies, DropBox, Skype — and that's only part of the…
🥷 Cobalt Strike Beacon and MSBuild The practice of our incident investigations shows that threat actors are still using the Microsoft Build Engine to compile .N…
📬 Exchange_SSRF Our practice shows that a fairly large number of organizations still have not installed updates on their public Microsoft Exchange mail servers…