Other
Storm clouds on the horizon: Resurgence of TeamTNT?
Investigations into recent campaigns may suggest the reemergence of TeamTNT in 2023 to present day, since evaporating in 2022.
Investigations into recent campaigns may suggest the reemergence of TeamTNT in 2023 to present day, since evaporating in 2022.
Group-IB dark web investigations: To avoid prying eyes, find out how adversaries increasingly shift from the dark web to social media to execute attacks, leak credentials, share exploitable vulnerabilities, and more.
GCP administrators face challenges in managing HMAC keys within their organizations, lacking visibility into which user accounts have generated these keys and whether they are actively being used to access storage objects. Additionally, there's a lack of functionality to revoke keys associated with other users, restricting their ability to enforce security policies effectively. Similarly, GCP incident response teams rely on Cloud Logging to monitor Cloud Storage object access, but they lack spe…
Learn how you can streamline incident response with Huntress Managed EDR's Active Remediation. Sleep soundly while we thwart threats on your behalf.
Ransomware is spreading like wildfire. Learn about its growing threat to healthcare, its impact on patient care, and how Huntress managed solutions can better protect your organization from cyberattacks.
The publication of the first blog post led a Huntress SOC analyst to identify and escalate a second, similar incident. A deeper investigation into the activity made it clear that the Huntress SOC had obviated several Trigona ransomware attacks, protecting customers from the impact of a ransomware infection.
Take a deep dive into the operations of one of the most active players in the Ransomware-as-a-Service market.
Get a close look at details of the most notable cases faced by Group-IB’s Digital Forensics and Incident Response (DFIR) team
Twas the night before Christmas, when out came the cry, a cyberattack is happening, so stop them, won’t you try?
Gather valuable insights on how incident response can be a make-or-break factor in securing your business.
How to investigate phishing campaigns
In this blog, we’ll go on a short journey of how we dissected a vague Managed Antivirus alert and offer some ideas and methods for security analysts.
Incident response is a lot like a choose your own adventure exercise. We cover the ground rules and talk about some incidents we’ve helped partners with.
The Group-IB Incident Response Team investigated an incident related to a DeadBolt attack and analyzed a DeadBolt ransomware sample
We unravel an investigation that details one way threat actors are able to gather cleartext passwords via NPPSPY.
A digital forensics investigation can be tedious. Fortunately, there are some efficient ways that you can still achieve success as an investigator.
This blog dives into triangulation as a guiding concept during investigations and reporting.
Learn about our investigation regarding unauthorized access to our QA and product testing environment.
Learn manual malware analysis techniques used by threat researchers. Explore static & dynamic analysis, reverse engineering tools, and real-world investigation methods.
Top 11 books on digital forensics, incident response, and malware analysis
Useful feature that can help forensic analysts and incident responders to reconstruct user activities.
Windows Prefetch files were introduced in Windows XP and since that time have helped digital forensics analysts and incident responders find evidence of execution.
All about WhatsApp forensics and the wealth of data extracted from a device through forensic analysis.
Igor Mikhailov gave his review of the best software and hardware solutions for computer forensics.
When it comes to breaches, it’s hard to find a silver lining when the end result is customer down time, data theft, or damaged reputations. For Managed Service Providers with tens to hundreds (or even thousands) of clients, the stakes are even higher. In this MSP Moment, we’re highlighting how NTConnections, a Washington DC based MSP, responded to a database outage which quickly escalated into an incident response effort.