Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the fi…
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the fi…
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…
PT ESC specialists have recorded signs of attackers carrying out an attack through the standard functionality of the ViPNet MFTP service. As of the publication…
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely known Mimikatz tool, but unlike it, VMkatz's goal is to extract…
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…
Rare persistence techniques. Part 4 Also read about: Zabbix Agent, TimeProvider, COM Hijacking, WMICLNT. 5️⃣ Systemd Generator A Systemd Generator is an executa…
Rare persistence techniques. Part 3 Also read about: Zabbix Agent, TimeProvider, COM Hijacking. 4️⃣ WMICLNT This persistence technique is based on hijacking a D…
Rare persistence techniques. Part 2 Also read about: Zabbix Agent, TimeProvider. 3️⃣ COM Hijacking For persistence in the infrastructure, the attackers used a r…
Rare persistence techniques In the first six months of 2026, the PT ESC IR team recorded a number of rare persistence techniques on compromised hosts, which we…