RSS
Security Operations
Threat Research
active adversary
Active Adversary Report
Compromised Credentials
detection
dwell time
Featured
impact
incident response
LOLBIN
MFA
Monitoring
RDP
Remote Ransomware
root cause
It takes two: The 2025 Sophos Active Adversary Report
April 2, 2025
featured
IR
LoLBINs
MDR
The Bite from Inside: The Sophos Active Adversary Report
December 12, 2024
Sophos X-Ops
RD Web Access abuse: Fighting back
June 12, 2024
Case Study
It’s Oh So Quiet (?): The Sophos Active Adversary Report for 1H 2024
April 3, 2024
Incident response tools
Remote Desktop Protocol: The Series
March 20, 2024
practitioners
tools
The song remains the same: The 2023 Active Adversary Report for Security Practitioners
November 14, 2023
Active Directory
attribution
MTR
Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders
August 23, 2023
CoinMiner
Conti
data breach
exfiltration
extortion
loader
Lockbit
Ransomware
Web shells
Everything Everywhere All At Once: The 2023 Active Adversary Report for Business Leaders
April 25, 2023
BlackCat
cryptominers
cybercrime forums
Hive
IABs
Karakurt
Multiple attackers increase pressure on victims, complicate incident response
August 9, 2022