RSS
Security Operations
Threat Research
active adversary
Active Adversary Report
Compromised Credentials
detection
dwell time
Featured
impact
incident response
LOLBIN
MFA
Monitoring
RDP
Remote Ransomware
root cause
It takes two: The 2025 Sophos Active Adversary Report
IR
LoLBINs
MDR
The Bite from Inside: The Sophos Active Adversary Report
featured
Sophos X-Ops
RD Web Access abuse: Fighting back
Case Study
It’s Oh So Quiet (?): The Sophos Active Adversary Report for 1H 2024
Incident response tools
Remote Desktop Protocol: The Series
practitioners
tools
The song remains the same: The 2023 Active Adversary Report for Security Practitioners
Active Directory
attribution
MTR
Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders
CoinMiner
Conti
data breach
exfiltration
extortion
loader
Lockbit
Ransomware
Web shells
Everything Everywhere All At Once: The 2023 Active Adversary Report for Business Leaders
act
anti-EDR
AuKill
backstab
EDR
EDR killer
malware
Process Explorer
procexp
targeted attacks
‘AuKill’ EDR killer malware abuses Process Explorer driver