[ SECTION // PRACTICE // 97 ITEMS ]

PRACTICE

5 groups across 15 tags

Tips

#tips 79

// Threats

We will croc you

We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…

oUth0R
// Detection

A look inside ESE

Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…

oUth0R

> ещё 73 по тегам этой группы

Tools

#tools 8 #hacktool 7

// Threats

Tools for working with Python

Tools for Working with Python 😦 Attackers are not shy about using Python for their purposes. LazyStealer, packaged with PyInstaller, the Python backdoor in Shad…

ti_author
// Threats

Lok'tar ogar!

Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…

global_author

> ещё 9 по тегам этой группы

Languages & runtimes

#ml 1 #python 1 #rust 1

// Threats

One on one with Rust

One on One with Rust ☹️ Recently, the complex threat research group of Positive Technologies' TI department has been increasingly encountering malware written i…

ti_author

> ещё 1 по тегам этой группы

Network & mail

#tls 4 #web 4 #mitm 2 #cryptography 1 #mail 1 #url 1

> ещё 4 по тегам этой группы

Unix & macOS

#linux 5 #macos 2 #unix 2

// Threats

Dirty Frag 🐧

Dirty Frag 🐧💥 A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag. As…

global_author
// Threats

(Ex)Cobalt == (Ex)Carbanak

(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…

oUth0R

> ещё 2 по тегам этой группы