Kaseya VSA Supply-Chain Attack Ransomware
Kaseya VSA Supply-Chain Attack (REvil) – Technical Breakdown Date: July 2, 2021Threat Actor: REvil (Sodinokibi ransomware group)Attack…
continue reading..
REvil/Sodinokibi – Ransomware a Detailed Explanation, IOCs
REvil (also known as Sodinokibi) is a financially motivated ransomware-as-a-service (RaaS) operation that emerged in 2019 and…
continue reading..
DarkSide Ransomware – Detection Mapping
DarkSide Ransomware – Detection Mapping (Splunk | Sentinel | Elastic) 1. Initial Access – VPN Abuse (Valid…
continue reading..
DarkSide Ransomware
1. Executive Overview Victim: Colonial Pipeline Company (largest refined fuel pipeline in the U.S.) Date: Initial intrusion…
continue reading..
NotPetya: Incident Response and Defensive Strategies
Overview of NotPetya Ransomware What is NotPetya? NotPetya is a destructive wiper malware disguised as ransomware, first…
continue reading..
Golden Tickets: Full Access to the Domain
What is a Golden Ticket? A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT). This…
continue reading..
Silver Tickets: Forging VIP Access Pass
What is a Silver Ticket? A Silver Ticket is a forged Kerberos ticket that an attacker creates…
continue reading..
Kerberoasting: How Attackers Turn Tickets into Takeovers
What is Kerberoasting? Kerberoasting is an attack that happens in a network that uses a special security…
continue reading..
Kerberos Authentication Explained: The Smart Way Networks Verify You
What is Kerberos Authentication? In simple terms, Kerberos Authentication is a way of proving who you are…
continue reading..
