[ TAG // WIN // 27 ITEMS ]

#win

← Detection // Windows

// Threats

This is Siemens...

Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…

global_author
// Detection

A look inside ESE

Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…

oUth0R
// Threats

New connection to old techniques

A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…

oUth0R
// Detection

Detecting CVE-2025-33073

Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️‍♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…

global_author