[ TAG // DFIR // 63 ITEMS ]

#dfir

← Detection // General

// Threats

Operation Chewbacca

At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…

oUth0R
// Threats

Your Zimbra server is at risk

Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…

oUth0R
// Threats

He's not your gsocket

He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…

oUth0R
// Threats

We will croc you

We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…

oUth0R
// Detection

A look inside ESE

Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…

oUth0R
// Detection

Rare retention techniques

Rare persistence techniques In the first six months of 2026, the PT ESC IR team recorded a number of rare persistence techniques on compromised hosts, which we…

oUth0R