View the latest
DFIR Report
X
Public Reports
Products
Products Overview
Threat Intel
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
-
Detection Pack
AI Training Ground
-
bruteratel
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
Read More
-
dragonforce
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Read More
Services
Services Overview
Training
Threat Hunting
-
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products
Products Overview
Threat Intel
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Services
Service Overview
Training
Threat Hunting
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Cold Intrusion
cobaltstrike
bruteratel
cobaltstrike
latrodectus
bruteratel
,
cobaltstrike
,
latrodectus
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
blacksuit
bruteratel
cobaltstrike
blacksuit
,
bruteratel
,
cobaltstrike
,
ransomware
,
sectoprat
Fake Zoom Ends in BlackSuit Ransomware
lockbit
cobaltstrike
ransomware
lockbit
,
cobaltstrike
,
ransomware
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware
cobaltstrike
more_eggs
cobaltstrike
,
more_eggs
The Curious Case of an Egg-Cellent Resume
cobaltstrike
opendir
cobaltstrike
,
opendir
Inside the Open Directory of the “You Dun” Threat Group
blackcat
cobaltstrike
ransomware
blackcat
,
cobaltstrike
,
ransomware
,
sliver
Nitrogen Campaign Drops Sliver and Ends With BlackCat Ransomware
adfind
blacksuit
cobaltstrike
adfind
,
blacksuit
,
cobaltstrike
,
ransomware
BlackSuit Ransomware
alphv
cobaltstrike
icedid
alphv
,
cobaltstrike
,
icedid
,
ransomware
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment
dagonlocker
adfind
cobaltstrike
dagonlocker
,
adfind
,
cobaltstrike
,
icedid
From IcedID to Dagon Locker Ransomware in 29 Days
bluesky
cobaltstrike
ransomware
bluesky
,
cobaltstrike
,
ransomware
SQL Brute Force Leads to BlueSky Ransomware