C2 hunting: part 1
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…
Proxying WebSocket nginx — payload detection 👀 Checking configurations of various services sometimes helps find unknown malware that is not detected by antiviru…
By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…
Where to look for network indicators of compromise on Windows? For example, in the DNS cache 💡 The DNS cache is a mechanism for caching records that map domain…
Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…
🫡 Hellhounds remains one of the most advanced groups attacking companies in Russia We have already covered Hellhounds' activity in the articles "Operation Lahat…
DPAPI — a popular vector for attacks on Windows-family OS 💻 Wi-Fi keys, certificates, credentials, browser cookies, DropBox, Skype — and that's only part of the…
🥷 Cobalt Strike Beacon and MSBuild The practice of our incident investigations shows that threat actors are still using the Microsoft Build Engine to compile .N…
💻 While investigating an incident, we discovered a useful artifact, smb_context C:\Windows\SysWOW64\smb_context.log — the SMB event log from a well-known antivi…
📬 Exchange_SSRF Our practice shows that a fairly large number of organizations still have not installed updates on their public Microsoft Exchange mail servers…
utmpdump dual-use Default Unix systems have little forensic information (vs Windows) and a lot of useful utilities. For example, there is a "wonderful" utility…