Click here to download all references as Bib-File.•
2021-01-25
⋅
SOC Prime
⋅
Affiliates vs Hunters: Fighting the DarkSide DarkSide |
2021-01-22
⋅
Symantec
⋅
SolarWinds: How Sunburst Sends Data Back to the Attackers SUNBURST |
2021-01-20
⋅
Twitter (@malwrhunterteam)
⋅
Tweet on Vovalex ransomware Vovalex |
2021-01-18
⋅
Symantec
⋅
Raindrop: New Malware Discovered in SolarWinds Investigation Cobalt Strike Raindrop SUNBURST TEARDROP |
2021-01-15
⋅
Symantec
⋅
SolarWinds: Insights into Attacker Command and Control Process SUNBURST |
2021-01-11
⋅
Palo Alto Networks Unit 42
⋅
xHunt Campaign: New BumbleBee Webshell and SSH Tunnels Used for Lateral Movement |
2021-01-07
⋅
Symantec
⋅
SolarWinds: How a Rare DGA Helped Attacker Communications Fly Under the Radar SUNBURST |
2021-01-06
⋅
Red Canary
⋅
Hunting for GetSystem in offensive security tools Cobalt Strike Empire Downloader Meterpreter PoshC2 |
2021-01-06
⋅
Malwarebytes
⋅
Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat RokRAT |
2021-01-02
⋅
Twitter (MalwareHunterTeam)
⋅
Tweet on Knot Ransomware Knot |
2021-01-01
⋅
Symantec
⋅
Supply Chain Attacks:Cyber Criminals Target the Weakest Link Cobalt Strike Raindrop SUNBURST TEARDROP |
2020-12-22
⋅
CrowdStrike
⋅
Leftover Lunch: Finding, Hunting and Eradicating Spicy Hot Pot, a Persistent Browser Hijacking Rootkit Spicy Hot Pot |
2020-12-22
⋅
Symantec
⋅
SolarWinds Attacks: Stealthy Attackers Attempted To Evade Detection SUNBURST |
2020-12-21
⋅
Bloomberg
⋅
SolarWinds Adviser Warned of Lax Security Years Before Hack |
2020-12-19
⋅
Twitter (@GossiTheDog)
⋅
A twitter thread on Azure sentinel hunting queries for detecting UNC2452 activity |
2020-12-16
⋅
Microsoft
⋅
SolarWinds Post-Compromise Hunting with Azure Sentinel SUNBURST |
2020-12-15
⋅
Cyborg Security
⋅
Threat Hunt Deep Dives: SolarWinds Supply Chain Compromise (Solorigate / SUNBURST Backdoor) SUNBURST |
2020-12-15
⋅
ThreatConnect
⋅
Infrastructure Research and Hunting: Boiling the Domain Ocean |
2020-12-15
⋅
Github (sophos-cybersecurity)
⋅
solarwinds-threathunt Cobalt Strike SUNBURST |
2020-12-14
⋅
Symantec
⋅
Sunburst: Supply Chain Attack Targets SolarWinds Users SUNBURST TEARDROP |