DFIR_TNT
@dfir_tnt
DFIR Tips N Tricks | Andrew Skatoff | Husband+Father | Cyber+DFIR | Seeker of Truth | Hunter of Threats
ID: 142720294
http://www.dfirtnt.com 11-05-2010 15:40:06
698 Tweet
989 Takipçi
1,1K Takip Edilen
From ScreenConnect to Hive Ransomware in 61 hours ➡️Initial Access: ScreenConnect ➡️Defense Evasion: BITS Jobs, Embedded Payloads ➡️Lateral Movement: Impacket, RDP, SMB ➡️C2: ScreenConnect, Atera, Splashtop, Cobalt Strike, Metasploit ➡️Exfil: Rclone thedfirreport.com/2023/09/25/fro… 1/X
Another deeply technical report filled with tons of actionable intelligence from The DFIR Report Highlights more malicious use of RMMs ConnectWise, Splashtop and Atera. Awesome work!!
Another tight RMM forensics blog entry hit this week. Check out HackUponTheGale 's entry about Microsoft Quickassist!! hackuponthegale.github.io/blog/dfir/Quic…
HuntableGPT now uses retrieval-augmented context. - 250 intel samples - 170 linked SIGMA rules - SIGMA rule guides by Thomas Patzke Florian Roth ⚡️ Refining hunt logic generation through clearer examples + references. 🔗 lnkd.in/eqSky_UU #Huntable #ThreatHunting #SIGMA