Divination by Goffee grounds
Fortune Telling on Goffee Grounds: Current Tools and Grouping Features of Goffee in Attacks on Russia ☕️ Throughout 2024-2025, experts from the TI department ha…
Fortune Telling on Goffee Grounds: Current Tools and Grouping Features of Goffee in Attacks on Russia ☕️ Throughout 2024-2025, experts from the TI department ha…
Malware in SYSVOL: finding the source 😐 Let's say we're investigating a ransomware incident. The attackers used a Group Policy to launch the ransomware (for exa…
In addition to the previous post, we want to talk about some other potential ways of detecting the execution of malicious code in the "1C" system 😳 • First, if…
Following the 1C_Shell trail. Investigating attacks using the event log 🐾 In one of our previous posts, we wrote about detecting attacks on the 1C system in whi…
Exchange Mutation. How We Caught Anomalies in Outlook Pages 😮 Continuing our series of incident investigation stories (you can read about them here, here, and p…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
1C_shell for "1C" 🦞 Sometimes situations arise when, during an information security incident investigation, the traditionally used OS artifacts contain extremel…
(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…
By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…