Sign in

Hunt & Hackett

@huntandhackett.com
94 followers 0 following 132 posts

We are experts in cybersecurity, our specialists operate on the frontlines to help customers prevent, detect and respond to today’s most advanced adversaries. Visit our website: www.huntandhackett.com

PostsRepliesMedia
Hunt & Hackett @huntandhackett.com · 23/02/2026
The 2026 edition of our Trend Report is out now ⬇️ Underpinned by data from more than 54,000 investigations conducted by our SOC and Incident Response team in 2025, the report provides a bottom-up view of the threats facing Dutch organisations. Download here: www.huntandhackett.com/2026-cyber-t...
huntandhackett.com
2026 Cyber Trend Report | Hunt & Hackett
Discover key cybersecurity trends for 2026, including the rise in identity-based attacks, exploitation of technical debt, and how attackers are using AI to scale their operations.
010
Hunt & Hackett @huntandhackett.com · 10/10/2025
ENISA released its Threat Landscape 2025. It offers a detailed look at how Europe’s cyber ecosystem is evolving. The picture that emerges shows growing strain, where interconnected systems and persistent threats keep testing resilience. Read the report here: www.enisa.europa.eu/publications...
020
Hunt & Hackett @huntandhackett.com · 21/08/2025
🔐 New #blogpost At H2, we recently moved from authenticator apps to #YubiKey (FIDO2) for company-wide MFA in Entra ID. Why? Because it enables phishing-resistant, passwordless sign-ins at scale, raising the bar for our security. Read about our journey here: www.huntandhackett.com/blog/raising...
huntandhackett.com
Raising security with organization-wide YubiKey (FIDO2) in Entra ID
Find out how Hunt & Hackett transforms incident response challenges into scalable solutions using open-source software and a DevOps mindset.
010
Hunt & Hackett @huntandhackett.com · 14/08/2025
Cyber espionage impacts more organisations than you think. Join our next CyberConnect on Sept 9 in The Hague to learn how these operations work, who gets targeted, and see a live demo of tracking campaigns. Sign up today: www.huntandhackett.com/understandin...
010
Hunt & Hackett @huntandhackett.com · 12/08/2025
𝐖𝐡𝐚𝐭 𝐚𝐫𝐞 𝐨𝐮𝐫 𝐇𝐮𝐧𝐭𝐞𝐫𝐬 𝐢𝐧𝐭𝐨 𝐫𝐢𝐠𝐡𝐭 𝐧𝐨𝐰? 👀 We stumble across so many good things from the cybersecurity community and beyond, and we thought it'd be nice to share them. So, here are some of the things our Hunters have been diving into lately: 🧵1/7
110
Hunt & Hackett @huntandhackett.com · 10/07/2025
⚠️ Malware campaigns are hijacking SEO to trick users into downloading fake tools like PuTTY and ChatGPT. A recent article by @thehackernews.bsky.social shows over 8,500 SMB users were targeted. Head over to their website to read the full article: thehackernews.com/2025/07/seo-...
thehackernews.com
SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI Tools
SEO poisoning delivers trojanized tools, targeting SMBs and spreading malware via fake websites
000
Hunt & Hackett @huntandhackett.com · 09/07/2025
Threat Actor Profile: Sandworm Linked to Russia’s GRU and active in 60+ countries, Sandworm targets critical infrastructure with sabotage, espionage, and disruption. Curious to learn more about this APT? Explore their threat profile in our Members' Portal: www.huntandhackett.com/members/acto...
huntandhackett.com
Hunt & Hackett
000
Hunt & Hackett @huntandhackett.com · 04/07/2025
🚨New #blogpost: This week we’re unpacking our journey using open-source software to build a cloud-based IR lab from scratch, highlighting key obstacles and how we turned them into opportunities. 🔗https://www.huntandhackett.com/blog/turning-incident-response-challenges-into-scalable-solutions
huntandhackett.com
Turning incident response challenges into scalable solutions
Find out how Hunt & Hackett transforms incident response challenges into scalable solutions using open-source software and a DevOps mindset.
010
Hunt & Hackett @huntandhackett.com · 05/06/2025
Launching #DetectionsFromTheSOC 🚀 We're excited to announce our new series, 𝘋𝘦𝘵𝘦𝘤𝘵𝘪𝘰𝘯𝘴 𝘧𝘳𝘰𝘮 𝘵𝘩𝘦 𝘚𝘖𝘊, in which we share a behind-the-scenes look of how our SOC detects, investigates, and responds to real-world threats. Head on over to our LinkedIn to check it out: www.linkedin.com/feed/update/...
linkedin.com
#detectionsfromthesoc #captcha #infostealer #cryptbot #soc #bec | Hunt & Hackett
Launching #DetectionsFromTheSOC 🚀 We're happy to announce our new series, 𝘋𝘦𝘵𝘦𝘤𝘵𝘪𝘰𝘯𝘴 𝘧𝘳𝘰𝘮 𝘵𝘩𝘦 𝘚𝘖𝘊, in which we share a behind-the-scenes look of how our SOC detects, investigates, and responds t...
000
Hunt & Hackett @huntandhackett.com · 04/06/2025
🎤 We’re taking the stage at Hague TIX on June 10! Hunt & Hackett is proud to sponsor and speak at one of Europe’s leading threat intel events. Diving into strategic cyber defence, Lazarus & SeaTurtle ops, and Europe’s cyber resilience. #HagueTIX #ThreatIntel
000
Hunt & Hackett @huntandhackett.com · 16/05/2025
Our next CyberConnect session is coming up: Security in Motion! Visit our website for more information, and to sign-up: www.huntandhackett.com/security-in-...
010
Hunt & Hackett @huntandhackett.com · 15/05/2025
🚨 New blog! We dive into reverse-engineering AFD.sys (a hidden part of Windows networking) to surface live socket data from other processes. This unlocks new capabilities for forensics, debugging, and reverse engineering. Read it here: www.huntandhackett.com/blog/improvi...
huntandhackett.com
Improving AFD Socket Visibility for Windows Forensics & Troubleshooting
This blog post explains the basics of Ancillary Function Driver API and how it can help explore networking activity on Windows systems.
020
Hunt & Hackett @huntandhackett.com · 14/05/2025
We've updated our threat landscape on the logistics sector 🚛 On it, you'll find detailed actor overviews, analyses of recent cyberattacks in the logistics sector, and insights into emerging cybersecurity trends. Curious? Take a look: www.huntandhackett.com/members/sect...
000
Hunt & Hackett @huntandhackett.com · 23/04/2025
Op 16 mei organiseren we een interactieve workshop voor advocaten die cliënten adviseren op het gebied van privacy, informatiebeveiliging en incident response. Meer informatie kun je vinden op onze website: www.huntandhackett.com/crisisworksh...
huntandhackett.com
Crisisworkshop voor advocaten
Cyberincidenten zijn aan de orde van de dag – en als advocaat ben je vaak de eerste persoon die gebeld wordt. Maar wat zijn je eerder acties?
000
Hunt & Hackett @huntandhackett.com · 22/04/2025
Join us at Google Amsterdam for our next session: Securing Operational Technology: Fast Response, Strong Recovery We’re hosting a session on how to boost operational resilience, secure OT environments, and align with evolving regulations. Sign-up now: www.huntandhackett.com/securing-ot
huntandhackett.com
Securing Operational Technology: Fast Response, Strong Recovery
In this session, Hunt & Hackett and Xebia will collaborate to strengthen Operational Technology security, ensuring rapid response and resilient recovery. Register now.
000
Hunt & Hackett @huntandhackett.com · 16/04/2025
Yesterday, our security experts discussed the evolving threat landscape surrounding the upcoming NATO summit in The Hague. A great opportunity to highlight cyber threats beyond the traditional security community; cross-domain awareness is key in today’s threat landscape.
000
Hunt & Hackett @huntandhackett.com · 15/04/2025
Our hunters tackled the 44th edition NN Marathon Rotterdam! 🏁 Their legs might be sore today, but the bliss of victory was more than worth it. After all, every win starts with a challenge. Huge respect to everyone who took on #demooiste with us. See you at the next one.
000
Hunt & Hackett @huntandhackett.com · 01/04/2025
New #blog post in collaboration with Xebia ⚔️ As businesses become more interconnected, Operational Technology (OT) is increasingly targeted by cyber threats. In this blog, we explore OT security and raise awareness about its growing risks. Read it here: www.huntandhackett.com/blog/evolvin...
huntandhackett.com
The Evolving Threat of OT: Do You Know Your Weak Spots?
Discover how operational technology (OT) is becoming an increasingly attractive target for cyber threats—and learn how to identify and secure your organisation’s most vulnerable entry points.
000
Hunt & Hackett @huntandhackett.com · 06/03/2025
🌎With the U.S. deprioritizing Russian cyber threats, barriers that once deterred Russian hackers from targeting Europe are fading. Is your organization prepared? www.bbc.com/news/article...
bbc.com
Hegseth orders pause in offensive US cyber operations against Russia
The reported directive from the defence secretary comes during an American push to end the war in Ukraine.
121
Hunt & Hackett @huntandhackett.com · 27/02/2025
Excited to share our 2025 Trend Report, which explores key themes shaping the cybersecurity landscape, including the #cybercrime economy, the impact of #GenAI, nation-state threats, the #NIS2 Directive, and more! Download the full report here: www.huntandhackett.com/2025-trend-r...
huntandhackett.com
2025 Cyber Trend Report | Hunt & Hackett
Discover key cybersecurity trends for 2025, including increasing nation-state attacks and the impact of Gen-AI, with expert insights and practical guidance for Dutch organizations to enhance resilienc...
020
Hunt & Hackett @huntandhackett.com · 25/02/2025
🚜 We've updated our Threat Landscape of the Agriculture sector 🌱 Find out about all our latest insights - including APTs, TTPs, recent developments, and a look behind-the-scenes - here ➡️ huntandhackett.com/threats/sect... #CyberSecurity #Agriculture #ThreatIntel #ThreatLandscape
huntandhackett.com
Cybersecurity for the Agriculture sector | Hunt & Hackett
We help you with the strategic, tactical and operational side of a cybersecurity program, fully optimized for the real threats in the agriculture sector.
000
Hunt & Hackett @huntandhackett.com · 30/01/2025
🚨Dutch universities are facing more cyberattacks than ever - but many still lack the security measures to stop them. In an interview with @telegraaf.nl, our co-founder Ronald Prins stresses the need for a proactive cybersecurity approach. Read the article here ➡️ www.telegraaf.nl/nieuws/29515...
telegraaf.nl
Universiteiten kwetsbaar voor cyberaanvallen: ’Bevinden ons in kennisoorlog’
Zijn Nederlandse onderwijsinstellingen wel voldoende voorbereid op digitale aanvallen? Donderdag debatteert de Tweede Kamer over kennisveiligheid en de screeningswet die moet regelen dat onderzoekers ...
030
Hunt & Hackett @huntandhackett.com · 14/01/2025
#Cyberattack at TU Eindhoven: What can we learn? This weekend, TU Eindhoven's network was taken offline after detecting a cyberattack. The investigation raises key questions: what risks do such institutions face, and how can they better prepare? www.tue.nl/en/news-and-... 1/7
tue.nl
Update on cyberattack: no education on Tuesday
100
Hunt & Hackett @huntandhackett.com · 09/01/2025
Sector Threat Profile: #Energy Explore the energy #threatlandscape - shifting to renewables brings increasing cyber threats. Learn about attack motivations, protection strategies, and past cases like SolarWinds. Read the report on our Members Portal: www.huntandhackett.com/members/regi...
000
Hunt & Hackett @huntandhackett.com · 10/12/2024
We’re excited to share that Hunt & Hackett has successfully achieved SOC 2 Type II compliance, with Securance as our independent auditor! 🎉 This means our security practices and policies meet the highest industry standards. We’re proud to report that our audit passed with zero exceptions! ✅
010
Hunt & Hackett @huntandhackett.com · 05/12/2024
Country Threat Profile: #Russia Discover Russia’s cyber threat landscape, with insights into high-profile attacks, #APTs (Advanced Persistent Threats), #TTPs (Techniques, Tactics, Procedures), and advanced tools. Access the full report via our Members’ Portal: www.huntandhackett.com/members/regi...
000
Hunt & Hackett @huntandhackett.com · 05/11/2024
Threat actor profile: #CozyBear (APT29) Read our comprehensive report about the Russian hacking group behind attacks such as #SolarWinds, the 2016 #DNC hack, and operations related to the war in Ukraine. 👉 Access the full report through our Members’ Portal: www.huntandhackett.com/members/regi...
020
Hunt & Hackett @huntandhackett.com · 31/10/2024
Exciting update! Hunt & Hackett has been nominated by @hackernoon.bsky.social for Startups of the Year 2024 in the Cybersecurity Services & Products category. Voting is now open, and we’d love your support: hackernoon.com/startups/ind...
hackernoon.com
Startups of the Year Awards 2024
The annual startup awards by HackerNoon. Voted by the community, we reward the brightest minds in software, crypto and the future of the internet.
000
Hunt & Hackett @huntandhackett.com · 22/10/2024
New #blogpost! When we started building a #DataWarehouse, our goal was to use it for training #AI models and enabling data analytics. However, as any data engineer knows, transforming raw data into AI insights requires well-designed ETL pipelines and data transformations. 1/4
100
Hunt & Hackett @huntandhackett.com · 13/09/2024
🚨 New #tool alert! Introducing Restart Manager Artifacts, an open-source tool for live extraction of #ransomware traces using Windows' Restart Manager API. www.huntandhackett.com/blog/introdu... 1/2
huntandhackett.com
Introducing the Restart Manager Artifacts Tool
Discover the Restart Manager Artifacts Tool for extracting valuable traces left by Akira ransomware using Windows' API. Explore database structure, tool usage, and detection suggestions.
101
Hunt & Hackett @huntandhackett.com · 05/09/2024
New #blogpost! Check out our latest blog on "Technical Curiosities of Akira Ransomware". #Akira is a new but highly dangerous #ransomware group, impacting over 300 organizations since April 2023. ⬇️Read on for more www.huntandhackett.com/blog/technic... 1/3
huntandhackett.com
Technical Curiosities of Akira Ransomware
Learn about the new Akira Ransomware group using dual extortion tactics, targeting various industries. Discover their encryption methods, use of Restart Manager API, and detectability. Subscribe for m...
100
Hunt & Hackett @huntandhackett.com · 20/08/2024
The countdown is on! 🙌 In just a few days, our CERT team will be presenting at the SANS Digital Forensics and Incident Response Summit & Training on August 22nd. They’ll reveal how #automation is transforming incident response, helping our CERT team move faster and smarter.
100
Hunt & Hackett @huntandhackett.com · 09/08/2024
As many people recently learned (hey #CrowdStrike!), the Blue Screen of Death can be a major headache. But what’s really behind these crashes? In our latest blog post, we argue that Windows’ recovery mechanisms are actually reasonable under the circumstances www.huntandhackett.com/blog/on-syst...
huntandhackett.com
On System Reliability and Why the (Conceptual) Design of the Blue Screen on Windows Is Actually a Good Thing
In light of the Crowdstrike incident, we explore the design principles behind system reliability on Windows machines, focusing on the importance of the Blue Screen of Death as a safety feature in hand...
000
Hunt & Hackett @huntandhackett.com · 30/07/2024
1️⃣Hackers don't take summer off and neither do we #Ransomware attacks are surging, with #LockBit 3.0 causing unprecedented disruptions. Recent data shows a 42.2% rise in victims, highlighting the ever-evolving tactics of cybercriminals.
100
Hunt & Hackett @huntandhackett.com · 23/07/2024
Be cautious of #cybercriminals looking to exploit the recent IT outage. They may use #phishing and fake updates disguised as Crowdstrike to target you. Check out the the article by Warehouse Totaal for more information and stay informed. www.warehousetotaal.nl/automatiseri...
warehousetotaal.nl
Mondiale IT-chaos: tweede golf door criminelen verwacht • Warehouse Totaal
Een aanzienlijke IT-storing heeft afgelopen vrijdag wereldwijd verstoringen veroorzaakt. Deze storing benadrukt de digitale afhankelijkheid en het belang
000
Hunt & Hackett @huntandhackett.com · 09/07/2024
1️⃣ New #blogpost! This week our Research & Innovation Lead Francisco Dominguez offers a new perspective for defending against #socialengineering attacks.
100
Hunt & Hackett @huntandhackett.com · 04/07/2024
Hear ye, hear ye. Our webinar with Xebia is now available on demand! If you haven't seen it yet, watch it for free on our page. Gain insights into making security easier, including topics like #cloud security, #SecOps with Chronicle #SIEM, and more www.huntandhackett.com/security-doe...
huntandhackett.com
Security Doesn't Have to Be Painful
Security Doesn't Have to Be Painful
000
Hunt & Hackett @huntandhackett.com · 27/06/2024
1️⃣New #blogpost! This week we’ll be delving into the topic of #automation and explaining our vision for an Incident Response approach that combines the investigative prowess of a digital detective with a #DevOps mindset.
100
Hunt & Hackett @huntandhackett.com · 21/06/2024
We’re excited to announce that Mattijs D. and Zawadi Done – the backbone of our #CERT team – have been invited to speak at the upcoming SANS DFIR Summit & Training, taking place on August 22. 1/5
100
Hunt & Hackett @huntandhackett.com · 06/06/2024
New #blogpost!   We’re concluding our passive persistence series by taking a deep dive into methods for accessing and recovering replicated secrets. In this blog, we explore how #replication works, the data structures involved and how to create an #NDRdecoder for replication events.  1/2
100
Hunt & Hackett @huntandhackett.com · 30/05/2024
New #blogpost! Welcome to Part 2 of our blog series on achieving eternal #persistence in an #ActiveDirectory environment. Last week, we explored methods for intercepting and decrypting password resets without domain controllers But eternal persistence wasn't achieved just yet. 1/🧵
100
Hunt & Hackett @huntandhackett.com · 23/05/2024
New #blogpost! ✍️ Introducing a new 3-part series on achieving passive persistence in an Active Directory (AD) environment. Part 1 covers methods for intercepting and decrypting password reset events without interacting with domain controllers. Read it here: www.huntandhackett.com/blog/how-to-...
huntandhackett.com
How to achieve eternal persistence in an Active Directory environment - Part 1
Explore passive techniques for surviving remediation and achieving eternal persistence in an AD environment.
300
Hunt & Hackett @huntandhackett.com · 07/05/2024
1️European intelligence agencies are raising alarm as #Russia escalates its acts of #sabotage across the continent. Recent reports reveal a concerning increase in covert bombings, arson, and infrastructure damage, with little concern for civilians. www.ft.com/content/c885...
ft.com
Russia plotting sabotage across Europe, intelligence agencies warn
Assessments suggest Kremlin agents preparing covert bombings, arson and attacks on infrastructure
100
Hunt & Hackett @huntandhackett.com · 25/04/2024
New #blog post! In our latest blog, we explore methods to detect the #Sliver framework and explore how to hunt down threat actors like #APT29 (Cozy Bear) who have harnessed its power. www.huntandhackett.com/blog/hunting... 1/🧵
huntandhackett.com
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.
100
Hunt & Hackett @huntandhackett.com · 23/04/2024
Recent reports from German media expose a major breach: #Volkswagen was targeted in a cyber #espionage campaign from 2010-2015. Hackers allegedly seized 19,000 documents, including data on engine development and emerging vehicle technologies. nos.nl/artikel/2517... 1/🧵
nos.nl
Duitse media: hackers zaten jarenlang in systemen van Volkswagen
De hackers, vermoedelijk uit China, waren op zoek naar informatie over de ontwikkeling van benzinemotoren en versnellingsbakken. Ook zochten ze naar gegevens over de ontwikkeling van schonere auto's.
100
Hunt & Hackett @huntandhackett.com · 17/04/2024
New #blog post! Dive into the complexities of collecting samples for #malware analysis as we introduce an innovative forensic approach for dumping #executables on Windows. From evasion techniques to transient file interactions, we explore the challenges faced by defenders. 1/10
100
Hunt & Hackett @huntandhackett.com · 22/03/2024
New #blogpost! The newest chapter of our Definitive Guide to Ransomware is out! Following our exploration of ransomware actors and mechanisms in Chapters 1 & 2, Chapter 3 dives into the history of #ransomware. 1/🧵
100
Hunt & Hackett @huntandhackett.com · 11/03/2024
New #blog post! Our latest blog post dives into the recent #iSoon leak, shedding light on China's expansive hacker-for-hire ecosystem. The leak, comprising over 500 files, unveils iSoon's operations, challenging many preconceptions within the cybersecurity community. 1/🧵
100
Hunt & Hackett @huntandhackett.com · 01/03/2024
New #blogpost! Recently our CERT team devised a plugin for the #Dissect incident response framework, allowing us to parse log files from Atop, a performance monitoring solution for Linux. Find out how we did this, and how it supports our cloud-based IR lab: www.huntandhackett.com/blog/parsing...
huntandhackett.com
Parsing Atop log files with Dissect
Learn how Hunt & Hackett created a Dissect plugin to parse ATOP files for Incident Response investigations.
000
Hunt & Hackett @huntandhackett.com · 27/02/2024
Leaked documents provide rare insight into Chinese state-sponsored #espionage. On February 16, a whistleblower leaked numerous documents on GitHub exposing the operations of #iSoon, a Shanghai-based company tied to Chinese state-sponsored hacking. 1/🧵
100