Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2021-03-11 ⋅ Rapid7 Labs ⋅ Caitlin Condon, Spencer McIntyre, William Vu
2020 Vulnerability Intelligence Report
2021-03-11 ⋅ IBM ⋅ Dave McMillen, Limor Kessem
Dridex Campaign Propelled by Cutwail Botnet and Poisonous PowerShell Scripts
Cutwail Dridex
2021-03-11 ⋅ Palo Alto Networks Unit 42 ⋅ Unit 42
Microsoft Exchange Server Attack Timeline
CHINACHOPPER
2021-03-11 ⋅ Flashpoint ⋅ Flashpoint
CL0P and REvil Escalate Their Ransomware Tactics
Clop REvil
2021-03-11 ⋅ Cofense ⋅ Elmer Hernandez
AutoHotKey Leveraged by Metamorfo/Mekotio Banking Trojan
Metamorfo
2021-03-11 ⋅ YouTube ( Malware_Analyzing_&_RE_Tips_Tricks) ⋅ Jiří Vinopal
Formbook Reversing - Part1 [Formbook .NET loader/injector analyzing, decrypting, unpacking, patching]
Formbook
2021-03-11 ⋅ Elastic ⋅ Daniel Stepanic
Update - Detection and Response for HAFNIUM Activity
2021-03-10 ⋅ CUJOAI ⋅ Albert Zsigovits
IoT Malware Journals: Prometei (Linux)
Prometei
2021-03-10 ⋅ Eli Shlomo Blog ⋅ Eli Shlomo
Azure Sentinel and Sysmon 4 B!ue T3amer$
2021-03-10 ⋅ Center for Security Studies (CSS) ⋅ Florian J. Egloff, Max Smeets
Publicly attributing cyber attacks: a framework
2021-03-10 ⋅ PICUS Security ⋅ Süleyman Özarslan
Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers
CHINACHOPPER
2021-03-10 ⋅ Twitter (@MSSPete) ⋅ Pete Bryan
Tweet on Sample KQL query for detecting usage of HAFNIUM PoC code floating ITW
2021-03-10 ⋅ FBI ⋅ CISA, FBI
Compromise of Microsoft Exchange Server
2021-03-10 ⋅ Proofpoint ⋅ Dennis Schwarz, Matthew Mesa, Proofpoint Threat Research Team
NimzaLoader: TA800’s New Initial Access Malware
BazarNimrod Cobalt Strike
2021-03-10 ⋅ Microsoft ⋅ Pete Bryan
Monitoring the Software Supply Chain with Azure Sentinel
2021-03-10 ⋅ DomainTools ⋅ Joe Slowik
Examining Exchange Exploitation and its Lessons for Defenders
CHINACHOPPER
2021-03-10 ⋅ US-CERT ⋅ CISA
Remediating Networks Affected by the SolarWinds and Active Directory/M365 Compromise
SUNBURST
2021-03-10 ⋅ Bleeping Computer ⋅ Lawrence Abrams
Norway parliament data stolen in Microsoft Exchange attack
2021-03-10 ⋅ Lemon's InfoSec Ramblings ⋅ Josh Lemon
Microsoft Exchange & the HAFNIUM Threat Actor
CHINACHOPPER
2021-03-10 ⋅ ESET Research ⋅ Mathieu Tartare, Matthieu Faou, Thomas Dupuy
Exchange servers under siege from at least 10 APT groups
Microcin MimiKatz PlugX Winnti APT27 APT41 Calypso Tick ToddyCat Tonto Team Vicious Panda