View the latest
DFIR Report
X
Public Reports
Products
Products Overview
Threat Intel
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
-
Detection Pack
AI Training Ground
-
bruteratel
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
Read More
-
dragonforce
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Read More
Services
Services Overview
Training
Threat Hunting
-
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products
Products Overview
Threat Intel
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Services
Service Overview
Training
Threat Hunting
Professional Services
Integration
CTI Program Advisory
Incident Response Playbook
Company
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Cold Intrusion
ransomware
blackcat
cobaltstrike
ransomware
blackcat
,
cobaltstrike
,
ransomware
,
sliver
Nitrogen Campaign Drops Sliver and Ends With BlackCat Ransomware
adfind
blacksuit
cobaltstrike
adfind
,
blacksuit
,
cobaltstrike
,
ransomware
BlackSuit Ransomware
alphv
cobaltstrike
icedid
alphv
,
cobaltstrike
,
icedid
,
ransomware
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment
dagonlocker
adfind
cobaltstrike
dagonlocker
,
adfind
,
cobaltstrike
,
icedid
From IcedID to Dagon Locker Ransomware in 29 Days
nokoyawa
adfind
Exfiltrate Data
nokoyawa
,
adfind
,
Exfiltrate Data
,
icedid
,
ransomware
From OneNote to RansomNote: An Ice Cold Intrusion
Exfiltrate Data
ransomware
rdp
Exfiltrate Data
,
ransomware
,
rdp
,
trigona
Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours
bluesky
cobaltstrike
ransomware
bluesky
,
cobaltstrike
,
ransomware
SQL Brute Force Leads to BlueSky Ransomware
Hive
cobaltstrike
ransomware
Hive
,
cobaltstrike
,
ransomware
,
wmiexec
From ScreenConnect to Hive Ransomware in 61 hours
nokoyawa
adfind
Attribution
nokoyawa
,
adfind
,
Attribution
,
icedid
,
ransomware
HTML Smuggling Leads to Domain Wide Ransomware
nokoyawa
adfind
cobaltstrike
nokoyawa
,
adfind
,
cobaltstrike
,
icedid
,
macro
,
ransomware
,
xls
IcedID Macro Ends in Nokoyawa Ransomware