Click here to download all references as Bib-File.•
2021-05-25
⋅
Huntress Labs
⋅
Cobalt Strikes Again: An Analysis of Obfuscated Malware Cobalt Strike |
2021-05-20
⋅
Github (microsoft)
⋅
Microsoft 365 Defender Hunting Queries for hunting multiple threat actors' TTPs and malwares STRRAT OceanLotus BabyShark Elise Revenge RAT WastedLocker Zebrocy |
2021-05-19
⋅
Medium Mehmet Ergene
⋅
Enterprise Scale Threat Hunting: Network Beacon Detection with Unsupervised ML and KQL — Part 2 Cobalt Strike |
2021-05-17
⋅
Telekom
⋅
Let’s set ice on fire: Hunting and detecting IcedID infections IcedID |
2021-05-12
⋅
Medium Mehmet Ergene
⋅
Enterprise Scale Threat Hunting: Network Beacon Detection with Unsupervised ML and KQL — Part 1 Cobalt Strike |
2021-05-10
⋅
⋅
Anheng Threat Intelligence Center
⋅
Analysis of U.S. Oil Products Pipeline Operators Suspended by Ransomware Attacks DarkSide |
2021-05-07
⋅
Medium svch0st
⋅
Stats from Hunting Cobalt Strike Beacons Cobalt Strike |
2021-05-06
⋅
Black Hat
⋅
Threat Hunting in Active Directory Environment |
2021-05-06
⋅
Cyborg Security
⋅
Ransomware: Hunting for Inhibiting System Backup or Recovery Avaddon Conti DarkSide LockBit Mailto Maze Mespinoza Nemty PwndLocker RagnarLocker RansomEXX REvil Ryuk Snatch ThunderX |
2021-05-05
⋅
Symantec
⋅
Multi-Factor Authentication: Headache for Cyber Actors Inspires New Attack Techniques CHINACHOPPER |
2021-05-02
⋅
The Record
⋅
DOJ hiring new liaison prosecutor to hunt cybercriminals in Eastern Europe |
2021-04-27
⋅
Positive Technologies
⋅
Lazarus Group Recruitment: Threat Hunters vs Head Hunters |
2021-04-26
⋅
getrevue
⋅
Hunting Cobalt Strike DNS redirectors by using ZoomEye Cobalt Strike |
2021-04-19
⋅
InfoSec Handlers Diary Blog
⋅
Hunting phishing websites with favicon hashes |
2021-04-15
⋅
Medium BI.ZONE
⋅
Hunting Down MS Exchange Attacks. Part 1. ProxyLogon (CVE-2021–26855, 26858, 27065, 26857) |
2021-04-05
⋅
Huntress Labs
⋅
From PowerShell to Payload: An Analysis of Weaponized Malware |
2021-03-25
⋅
Microsoft
⋅
Web Shell Threat Hunting with Azure Sentinel CHINACHOPPER |
2021-03-18
⋅
Github (cisagov)
⋅
CISA Hunt and Incident Response Program (CHIRP) SUNBURST |
2021-03-18
⋅
Elastic
⋅
Hunting for Lateral Movement using Event Query Language |
2021-03-08
⋅
Symantec
⋅
How Symantec Stops Microsoft Exchange Server Attacks CHINACHOPPER MimiKatz |