Extracting data from disk images with a damaged file system
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…
Yara Yara Daze Anyone involved in malware analysis is certainly familiar with a tool like YARA 😉. With its help, many companies 🔴 build sets of signature rules…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…
A word about the obfuscated batch file... We're publishing this post as a follow-up to the recent one about the EXE hidden under a hex dump in a Base64 request…
🥷 Cobalt Strike Beacon and MSBuild The practice of our incident investigations shows that threat actors are still using the Microsoft Build Engine to compile .N…