View the latest
DFIR Report
X
Public Reports
Products
Products Overview
Threat Intel
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
-
Detection Pack
AI Training Ground
-
bruteratel
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
Read More
-
dragonforce
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Read More
Services
Services Overview
Training
Threat Hunting
-
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products
Products Overview
Threat Intel
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Services
Service Overview
Training
Threat Hunting
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Cold Intrusion
exploit
exploit
lockbit
ransomware
exploit
,
lockbit
,
ransomware
Confluence Exploit Leads to LockBit Ransomware
coinminer
exploit
coinminer
,
exploit
SELECT XMRig FROM SQLServer
CVE-2021-44077
Exfiltrate Data
exploit
CVE-2021-44077
,
Exfiltrate Data
,
exploit
,
Plink
Will the Real Msiexec Please Stand Up? Exploit Leads to Data Exfiltration
adfind
cobaltstrike
conti
adfind
,
cobaltstrike
,
conti
,
exploit
,
icedid
,
ransomware
Stolen Images Campaign Ends in Conti Ransomware
exploit
Fast Reverse Proxy
PHOSPHORUS
exploit
,
Fast Reverse Proxy
,
PHOSPHORUS
,
ProxyShell
PHOSPHORUS Automates Initial Access Using ProxyShell
exploit
Fast Reverse Proxy
PHOSPHORUS
exploit
,
Fast Reverse Proxy
,
PHOSPHORUS
,
Plink
,
ProxyShell
,
ransomware
Exchange Exploit Leads to Domain Wide Ransomware
cobaltstrike
exploit
hancitor
cobaltstrike
,
exploit
,
hancitor
From Zero to Domain Admin
cryptominer
CVE-2020-14882
exploit
cryptominer
,
CVE-2020-14882
,
exploit
Cryptominers Exploiting WebLogic RCE CVE-2020-14882