[ TAG // DFIR // 63 ITEMS ]

#dfir

← Detection // General

// Threats

Gapucino* is GOFFEE

Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…

oUth0R
// Threats

How to get on the internet

How to get to the internet 🚶‍♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…

oUth0R
// Detection

Exfiltration gone wrong

😈 Exfiltration Gone Wrong When investigating incidents, we periodically encounter threat actors exfiltrating data before encrypting infrastructure. One of the e…

oUth0R
// Detection

Analysis of reports.db

☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described i…

oUth0R
// Threats

Industrial-scale exfiltration

Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…

oUth0R