This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use tunneling. For example, to punch a reverse tunnel from a compromised…
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Using DefendNot in XWorm Attacks 🪱 A cyber intelligence group has recorded phishing activity aimed at data theft followed by monetary extortion (screenshot 1)…
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
How to CVE-2025-54916? Low-effort vulnerability research 💻 Hi, ESC-VR here. The Telegram post format is rarely suitable for analyzing complex vulnerabilities, b…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
🧤 Now about the exploitation of the vulnerability CVE-2025-33073: • A domain account with the most ordinary privileges. • SMB signing is not enforced on the tar…
Reflection Relay. It never happened before, and now it's happening again (CVE-2025-33073) 😐 One of the most popular techniques for privilege escalation in an Ac…
Did you know that malicious actors don't like LNK file parsers? 👿 In March we wrote about XDSpy attacks on Russian organizations. The LNK files used in this att…