Sign in

pcsc0ut.bsky.social

@pcsc0ut.bsky.social
53 followers 205 following 4 posts

DFIR, Cybersecurity

PostsRepliesMedia
Reposted by @pcsc0ut.bsky.social
Randy @irishdeath.bsky.social · 19/05/2025
thedfirreport.com/2025/05/19/a... It was fun working on this Report with @pcsc0ut.bsky.social && 0xtornado. I hope my #threathunting friends will find it helpful. We came up with a new detection for Impacket tools in this investigation
media.tenor.com
a cat and a dog are looking at each other with the words the dust another one written above them
ALT: a cat and a dog are looking at each other with the words the dust another one written above them
042
Reposted by @pcsc0ut.bsky.social
The DFIR Report @thedfirreport.bsky.social · 19/05/2025
🌟New report out today!🌟 Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware Analysis and reporting completed by @pcsc0ut.bsky.social, @irishdeath.bsky.social & @0xtornado 🔊Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/05/19/a...
thedfirreport.com
Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
Key Takeaways The threat actor first gained entry by exploiting a known vulnerability (CVE-2023-22527) on an internet-facing Confluence server, allowing for remote code execution. Using this access…
0103
Reposted by @pcsc0ut.bsky.social
The DFIR Report @thedfirreport.bsky.social · 13/03/2025
PYSA/Mespinoza Ransomware ➡️TTR 7.5 hours ➡️Koadic and Empire for C2 ➡️7+ Credential Access techniques ➡️ADRecon, APS, quser, arp, and nltest for Discovery ➡️RDP and PsExec for Lateral Movement ➡️Files exfiltrated ➡️PYSA ransomware for Impact Report link ⬇️
152
Reposted by @pcsc0ut.bsky.social
The DFIR Report @thedfirreport.bsky.social · 24/02/2025
🌟New report out today!🌟 Confluence Exploit Leads to LockBit Ransomware Analysis & reporting completed by Angelo Violetti, @malforsec, & @teddy_ROxPin Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/02/24/c...
thedfirreport.com
Confluence Exploit Leads to LockBit Ransomware
Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.…
084
Reposted by @pcsc0ut.bsky.social
The DFIR Report @thedfirreport.bsky.social · 05/02/2025
Will the Real Msiexec Please Stand Up? Exploit Leads to Data Exfiltration ➡️Initial Access: CVE-2021-44077 exploited ➡️Execution: Web shell ➡️Credential Access: WDigest + MiniDump ➡️Lat Movement: RDP using Plink ➡️Exfiltration: Sensitive data exfilled thedfirreport.com/2022/06/06/w...
thedfirreport.com
Will the Real Msiexec Please Stand Up? Exploit Leads to Data Exfiltration
In this multi-day intrusion, we observed a threat actor gain initial access to an organization by exploiting a vulnerability in ManageEngine SupportCenter Plus. The threat actor, discovered files o…
042
Reposted by @pcsc0ut.bsky.social
The DFIR Report @thedfirreport.bsky.social · 27/01/2025
🌟New report out today!🌟 Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware Analysis & reporting completed by @r3nzsec, @MyDFIR & @MittenSec. Audio: Available on Spotify, Apple, YouTube and more! thedfirreport.com/2025/01/27/c...
thedfirreport.com
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware
Key Takeaways This intrusion began with the download and execution of a Cobalt Strike beacon that impersonated a Windows Media Configuration Utility. The threat actor used Rclone to exfiltrate data…
12410