View the latest
DFIR Report
X
Public Reports
Products
Products Overview
Threat Intel
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
-
Detection Pack
AI Training Ground
-
bruteratel
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
Read More
-
dragonforce
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Read More
Services
Services Overview
Training
Threat Hunting
-
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products
Products Overview
Threat Intel
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Services
Service Overview
Training
Threat Hunting
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Cold Intrusion
_pete_0
Back to Analysts
Reports by _pete_0
cobaltstrike
more_eggs
The Curious Case of an Egg-Cellent Resume
gootloader
SEO Poisoning to Domain Control: The Gootloader Saga Continues
quantum
adfind
cobaltstrike
Malicious ISO File Leads to Domain Wide Ransomware
cobaltstrike
Exfiltrate Data
ursnif
Unwrapping Ursnifs Gifts
adfind
cobaltstrike
Qbot
Follina Exploit Leads to Domain Compromise
coinminer
exploit
SELECT XMRig FROM SQLServer
Conference
SANS Ransomware Summit 2022, Can You Detect This?
adfind
cobaltstrike
conti
Stolen Images Campaign Ends in Conti Ransomware
Uncategorized
2021 Year In Review
adfind
bazar
cobaltstrike
CONTInuing the Bazar Ransomware Story
adfind
BazarCall
cobaltstrike
BazarCall to Conti Ransomware via Trickbot and Cobalt Strike
cobaltstrike
hancitor
Hancitor Continues to Push Cobalt Strike