[ TAG // DFIR // 63 ITEMS ]

#dfir

← Detection // General

// Threats

(Ex)Cobalt == (Ex)Carbanak

(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…

oUth0R
// Detection

A complex password won't help

A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…

oUth0R
// Threats

1C_shell for "1C"

1C_shell for "1C" 🦞 Sometimes situations arise when, during an information security incident investigation, the traditionally used OS artifacts contain extremel…

oUth0R
// Detection

CVE-2024-37085

Net group "babyk" /add During the investigation of one of the incidents, we discovered the exploitation of the CVE-2024-37085 vulnerability. It allows…

oUth0R
// Detection

Mount point. Pt 2

Mount point. Pt 2 Hello! We decided to talk about disk mounting again. Today we'll tell you how to work with LVM containers. Here's a short manual so you don't…

oUth0R
// Detection

Mount Point — pt.1

Mount Point — pt.1 🙂 Any investigation is an analysis of operating system artifacts. And to obtain them, you often have to work with virtual machine images, suc…

oUth0R
// Threats

OWOWA

⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…

oUth0R