Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

thedfirreport.com

The DFIR Report

Get the latest updates from The DFIR Report directly as they happen.

Follow now 188 followers

Latest posts

Last updated about 1 month ago

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

about 1 month ago

Overview Bumblebee malware has been an initial access tool used by threat...

KongTuke FileFix Leads to New Interlock RAT Variant

about 2 months ago

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a...

Hide Your RDP: Password Spray Leads to RansomHub Deployment

2 months ago

Key Takeaways Case Summary This intrusion began in November 2024 with a...

Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware

4 months ago

Key Takeaways The DFIR Report Services Table of Contents: Case Summary In...

Navigating Through The Fog

4 months ago

Key Takeaways An open directory associated with a ransomware affiliate, likely linked...

Fake Zoom Ends in BlackSuit Ransomware

5 months ago

Key Takeaways Case Summary This case from May 2024 started with a...

Confluence Exploit Leads to LockBit Ransomware

6 months ago

Key Takeaways Case Summary The intrusion started with the exploitation of CVE-2023-22527...

Cobalt Strike and a Pair of SOCKS Lead to Lockbit Ransomware

7 months ago

Key Takeaways Case Summary This intrusion began near the end of January...

The Curious Case of an Egg-Cellent Resume

9 months ago

Key Takeaways Private Threat Briefs: Over 20 private DFIR reports annually. Threat...

Inside the Open Directory of the “You Dun” Threat Group

10 months ago

Key Takeaways The DFIR Report Services Reports such as this one are...

Nitrogen Campaign Drops Sliver and Ends With BlackCat Ransomware

11 months ago

Key Takeaways Table of Contents: Case Summary Services Analysts Initial Access Execution...

BlackSuit Ransomware

about 1 year ago

Key Takeaways In December 2023, we observed an intrusion that started with...