RSS
Threat Research
active adversary
Active Adversary Report
cve-2021-31207
cve-2021-34473
cve-2021-34523
featured
ProxyLogon
ProxyShell
Security Operations
Sophos X-Ops
Web shells
Active Adversary Playbook 2022 Insights: Web Shells
June 22, 2022
Artifacts
Attack Tools
cobalt strike
Cryptomining
cyberattacks
cyberthreats
dwell time
Exploit
initial access broker
malware delivery system
MITRE
Ransomware
ransomware as a service
Sophos Rapid Response
vulnerability
The Active Adversary Playbook 2022
June 7, 2022
email security
Exchange vulnerability
fraud
malspam
Squirrelwaffle
Vulnerable Exchange server hit by Squirrelwaffle and financial fraud
February 15, 2022
malware
MTR
Rapid Response
Sophos XDR
Rapid Response: The Squirrelwaffle Incident Guide
SophosLabs Uncut
LockFile
metasploit
NTLM
PetitPotam
How PetitPotam hijacks the Windows API, and what you can do about it
August 25, 2021
Epsilon Red
EpsilonRed
Exchange
Powershell
WMI
A new ransomware enters the fray: Epsilon Red
May 28, 2021
China Chopper
CVE-2020-14882
Lemon Duck
Oracle WebLogic Server
Web-Shell
New Lemon Duck variants exploiting Microsoft Exchange Server
May 7, 2021
ADRecon
Chisel
mimikatz
RDP
Remote Utilities
Intervention halts a ProxyLogon-enabled attack
May 5, 2021
cryptojacking
Monero
Outlook
OWA
QuickCPU miner
xmr-stak
Compromised Exchange server hosting cryptojacker targeting other Exchange servers
April 13, 2021