[ TAG // HUNT // 24 ITEMS ]

#hunt

← Detection // General

// Threats

C2 hunting: part 1

C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…

ti_author
// Threats

Team46 group attacks

Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…

ti_author
// Threats

By the way, about Offzone

By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…

oUth0R
// Threats

Industrial-scale exfiltration

Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…

oUth0R
// Detection

Exchange_SSRF

📬 Exchange_SSRF Our practice shows that a fairly large number of organizations still have not installed updates on their public Microsoft Exchange mail servers…

oUth0R
// Detection

utmpdump dual-purpose

utmpdump dual-use Default Unix systems have little forensic information (vs Windows) and a lot of useful utilities. For example, there is a "wonderful" utility…

oUth0R