Professional Blogs
Red Canary Blog
- Beyond the bomb: When adversaries bring their own virtual machine for persistence
- A taxonomy of Mac stealers: Distinguishing Atomic, Odyssey, and Poseidon
- Node problem: Tracking recent npm package compromises
- Defying tunneling: A Wicked approach to detecting malicious network traffic
- Stealers evolve to bypass Google Chrome’s new app-bound encryption
- MSIX installer malware delivery on the rise across multiple campaigns
- The Goot cause: Detecting Gootloader and its follow-on activity
- KMSPico and Cryptbot: A spicy combo
- When Dridex and Cobalt Strike give you Grief
- Microsoft Exchange server exploitation: how to detect, mitigate, and stay calm
- Clipping Silver Sparrow’s wings: Outing macOS malware before it takes flight
- Hunting for GetSystem in offensive security tools
- Connecting Kinsing malware to Citrix and SaltStack campaigns
- Keeping tabs on Blue Mockingbird
- Introducing Blue Mockingbird
- Lateral Movement with Secure Shell (SSH)
- Trapping the Netwire RAT on Linux
- Context matters: harnessing creativity to triage security alerts
- Detection déjà vu: a tale of two incident response engagements
- ATT&CK; T1501: Understanding systemd service persistence
- Using visibility to gather context and find persistence mechanisms
- It’s all fun and games until ransomware deletes the shadow copies
- FrameworkPOS and the adequate persistent threat
- Threat Hunting in Linux for Indicators of Rocke Cryptojacking
- Shutting Down OSX/Shlayer
- Detecting All the Things with Limited Data
- Threat Hunting for PsExec, Open-Source Clones, and Other Lateral Movement Tools
- Mining off the Land: Cryptomining Enabled by Native Windows Tools
- Breathing Life into Detection Capability: the Creation of Detector #1236
- Tried-and-True Tactics: How an Adversary Mixed Lateral Movement and Cryptomining
- When Web Servers Go Cryptocurrency Mining
- Damage from Malicious Admins and Credential Access
- Lateral Movement Using WinRM and WMI