Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the fi…
[ SECTION // PRACTICE // 97 ITEMS ]
5 groups across 15 tags
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the fi…
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely known Mimikatz tool, but unlike it, VMkatz's goal is to extract…
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use tunneling. For example, to punch a reverse tunnel from a compromised…
Rare persistence techniques. Part 4 Also read about: Zabbix Agent, TimeProvider, COM Hijacking, WMICLNT. 5️⃣ Systemd Generator A Systemd Generator is an executa…
How did CaT entangle several groups at once? 🧶 In the fall of 2024, our attention was drawn to an interesting tool discovered while studying the activity of the…
Truly subtle interaction 🕊 During reverse engineering of the protocol of one of the Brazilian banking trojans, the use of an interesting network framework was d…
What is the steganographic mafia hiding from us? 👤 In November 2024, we told you about the PhaseShifters group and also mentioned the subscription-based crypter…
Tools for Working with Python 😦 Attackers are not shy about using Python for their purposes. LazyStealer, packaged with PyInstaller, the Python backdoor in Shad…
Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…
😏 Useful tools: Mandiant capa Imagine the situation: you are a malware analyst or an incident response specialist and you need to analyze a large volume of bina…
Dissecting network traffic with ML in search of new malware 📖 🧪 We — the network expertise department team of the ESC antivirus laboratory and the machine learn…
One on One with Rust ☹️ Recently, the complex threat research group of Positive Technologies' TI department has been increasingly encountering malware written i…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Click trap: not only for users, but also for link analyzers 🐭 When manually analyzing links, we typically ask ourselves only one question — “is it safe?” ✔️❌ Tr…
In addition to the previous post we are looking at additional tools for decrypting network traffic. Let's look at an alternative to PolarProxy that is no…
MITM attack is a fairly popular feature of various sandboxes and application analysis systems. Typically, tools that enable MITM attacks are a proxy serv…
🦈 Looking Under the Hood of Secure Connections in Wireshark. Part 1: TLS Our network experts often need to decrypt TLS connection traffic and analyze protected…
😐 “Why aren't you answering?”, or The Story of How to Steal a Telegram Account Without Registration or SMS Recently we published an article about the most popul…
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system sh…
Dirty Frag 🐧💥 A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag. As…
We would very much like to give you an overview of "tomato gose," but on Friday you voted for a new analysis of (Ex)Cobalt... 🙄 This is one of the most active a…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
🐾 Following in Puma's Footsteps: How to Detect a Rootkit Through Its Own Interface Today, our review covers a technically interesting and multifunctional Linux…
Gsocket: how to find one of the most popular tools 🙂 In the course of investigating numerous incidents involving the compromise of Linux nodes, we often discove…