[ TAG // C2 // 12 ITEMS ]

#c2

← Threats // Indicators & C2

// Threats

New window in dark mode

A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…

global_author
// Threats

C2 hunting: part 2.

C2 hunting: part 2. Hunting for hacker servers by external signs 😁 In the previous part, we talked about how to expand knowledge about hackers' infrastructure u…

ti_author
// Threats

Your hash, please… Thank you!

Your hash, please… Thank you! 🙏 In early January, we discovered a file that drew attention for its content and structure. An examination of the document's metad…

ti_author
// Threats

Lok'tar ogar!

Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…

global_author
// Threats

Gapucino* is GOFFEE

Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…

oUth0R
// Threats

How to get on the internet

How to get to the internet 🚶‍♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…

oUth0R
// Threats

C2 hunting: part 1

C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…

ti_author
// Threats

Proactive hunting for C2 servers

Proactive Hunting for C2 Servers 👨‍💻 In the process of hunting for C2 servers, an important question arises — which artifacts to use for better effectiveness an…

ti_author