user avatar
The DFIR Report
@TheDFIRReport
Real Intrusions by Real Attackers, the Truth Behind the Intrusion
thedfirreport.com/contact
Joined April 2020
  • Pinned
    user avatar
    New logo. New website. Same DFIR Report team. πŸ”Ž Check out the incredible analysts behind the research:
  • user avatar
    Cobalt Strike, a Defender's Guide - Part 2 ➑️In this report we talk about domain fronting, SOCKS proxy, C2 traffic, Sigma rules, JARM, JA3/S, RITA & more. Big shout-out to @Kostastsale for helping put this together! thedfirreport.com/2022/01/24/cob…
  • user avatar
  • user avatar
    Sodinokibi (aka REvil) Ransomware ➑️TTR: 4 hours ➑️Initial Access: IcedID ➑️Discovery: nltest, net, wmic, AdFind, BloodHound, etc. ➑️PrivEsc: UAC-TokenMagic & Invoke-SluiBypass ➑️Defense Evasion: Safe Mode & new GPO ➑️Exfil: Rclone ➑️C2: CobaltStrike thedfirreport.com/2021/03/28/sod…
  • user avatar
    Here's a thread on some of the interesting things we've seen in the #ContiLeaks. If you would like to read the chat logs and TrickBot Forum information, @Kostastsale has translated them to English here: github.com/tsale/translat…. He will be adding more as things get leaked.
  • user avatar
    Exchange Exploit Leads to Domain Wide Ransomware TTR: 42 Hours Initial Access: Exchange Exploited (ProxyShell) Discovery: ipconfig, nslookup, ping, KPortScan, etc. Execution: Fast Reverse Proxy & Plink Lateral Movement: RDP Impact: Data Encryption
  • user avatar
    πŸŽ‰ Announcing DFIR Labs! πŸŽ‰ Introducing our DFIR Labs based on real intrusions from our public reports and private threat briefs! Whether you're starting out or looking to deepen your skills, our labs can help. 1/2
    00:00
  • user avatar
    BumbleBee Roasts Its Way to Domain Admin ➑️Initial Access: BumbleBee (zipped ISO /w LNK+DLL) ➑️Persistence: AnyDesk ➑️Discovery: VulnRecon, Seatbelt, AdFind, etc. ➑️Credentials: Kerberoast, comsvcs.dll, ProcDump ➑️C2: BumbleBee, CobaltStrike, AnyDesk
  • user avatar
    From Zero to Domain Admin ➑️Initial Access: Maldoc deploys Hancitor ➑️C2: #CobaltStrike & #Hancitor ➑️Discovery: net, nltest, check.exe, AD module, scan for backup systems ➑️Privilege Escalation: Zerologon CVE-2020-1472
  • user avatar
  • user avatar
    Quantum Ransomware ➑️TTR: 3h 48 minutes ➑️Initial Access: IcedID ISO ➑️Persistence: Scheduled Tasks ➑️Discovery: WMIC, net, nltest, AdFind, etc. ➑️C2: Cobalt Strike ➑️Lateral Movement: PsExec, WMI, RDP ➑️Impact: Domain wide ransomware
  • user avatar
    From ScreenConnect to Hive Ransomware in 61 hours ➑️Initial Access: ScreenConnect ➑️Defense Evasion: BITS Jobs, Embedded Payloads ➑️Lateral Movement: Impacket, RDP, SMB ➑️C2: ScreenConnect, Atera, Splashtop, Cobalt Strike, Metasploit ➑️Exfil: Rclone thedfirreport.com/2023/09/25/fro… 1/X
  • user avatar
    Malicious ISO File Leads to Domain Wide Ransomware ➑️Initial Access: IcedID ISO ➑️Credentials: DCsync ➑️PrivEsc: ZeroLogon ➑️Lateral: RDP, SMB/Remote Service, WMI ➑️C2: IcedID, Cobalt Strike, Anydesk ➑️Exfil: Rclone to Mega ➑️Impact: Quantum Ransomware
  • user avatar
    Replying to @TheDFIRReport
    Ryuk in 5 Hours ➑️Zerologon (CVE-2020-1472) exploited 2 hours after initial execution of Bazar ➑️Cobalt Strike & Bazar for C2 ➑️AdFind, Net, Ping, Nltest & PowerShell for Discovery ➑️WMI & RDP for Execution ➑️Ryuk ransomware for Impact thedfirreport.com/2020/10/18/ryu…