macdonaldcarl
Member
Joined:
September 03, 2023 23:21
Posts:
123
Threads Started by macdonaldcarl
This user hasn't started any threads yet.
Recent Posts by macdonaldcarl
Has anyone encountered a similar issue with UEBA solution in their environment?
Indicators of compromise (IOCs) were extracted and correlated with industry ISACs. This threat actor typically...
Read more →
Based on code similarities and infrastructure overlap, we can attribute this to Scattered Spider with low confidence. The C2 infrastructure leverages reflective DLL injection to evade DLP...
Read more →
The preliminary results suggest unsecured endpoint, but we need more configuration file to confirm.
Read more →
That's an interesting approach to incident response. Have you considered manual review? That's a really insightful analysis of network monitoring, especially the part about SIEM.
Read more →