RSS
Security Operations
Threat Research
active adversary
Active Adversary Report
Compromised Credentials
detection
dwell time
Featured
impact
incident response
LOLBIN
MFA
Monitoring
RDP
Remote Ransomware
root cause
It takes two: The 2025 Sophos Active Adversary Report
April 2, 2025
IR
LoLBINs
MDR
The Bite from Inside: The Sophos Active Adversary Report
December 12, 2024
featured
Microsoft
Patch Tuesday
Windows
December Patch Tuesday arrives bearing 71 gifts
December 11, 2024
Sophos X-Ops
RD Web Access abuse: Fighting back
June 12, 2024
Case Study
It’s Oh So Quiet (?): The Sophos Active Adversary Report for 1H 2024
April 3, 2024
Incident response tools
Remote Desktop Protocol: The Series
March 20, 2024
Remote Desktop Protocol: Exposed RDP (is dangerous)
Remote Desktop Protocol: Queries for Investigation
Remote Desktop Protocol: How to Use Time Zone Bias