Reports

The Digital Forensics and Incident Response (DFIR) Report. Real Intrusions by Real Attackers, The Truth Behind the Intrusion. A new report comes out every month! Read the rest of the reports at https://thedfirreport.com/. In addition to our publicly available reports, we provide a range of specialized services to meet your needs, such as private reports, Command and Control tracking, personalized mentoring, and access to an exclusive detection ruleset. Explore our comprehensive offerings on our Services page at https://thedfirreport.com/services/.

BlackSuit Ransomware

Report: ⁠https://thedfirreport.com/2024/08/26/blacksuit-ransomware/ Contact Us: ⁠⁠⁠⁠⁠https://thedfirreport.com/contact/⁠⁠⁠⁠⁠ Services: ⁠⁠⁠⁠⁠https://thedfirreport.com/services/⁠⁠⁠⁠

08-26
05:15

Threat Actors' Toolkit: Leveraging Sliver, PoshC2 & Batch Scripts

Report: https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts Contact Us: https://thedfirreport.com/contact/⁠⁠⁠⁠⁠ Services: ⁠https://thedfirreport.com/services/⁠⁠⁠⁠

08-12
05:45

IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment

Report: https://thedfirreport.com/2024/06/10/icedid-brings-screenconnect-and-csharp-streamer-to-alphv-ransomware-deployment/⁠ Contact Us: ⁠⁠⁠⁠https://thedfirreport.com/contact/⁠⁠⁠⁠ Services: ⁠⁠⁠⁠https://thedfirreport.com/services/⁠⁠⁠

06-10
07:24

DFIR Discussions: From IcedID to Dagon Locker Ransomware in 29 Days

We discuss our latest report "From IcedID to Dagon Locker Ransomware in 29 Days" Host: ⁠⁠⁠@Kostastsale⁠⁠⁠ Analysts: ⁠⁠⁠@r3nzsec & @angelo_violetti  Special Guest: ⁠⁠@nas_bench Report: ⁠⁠⁠https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/ Contact Us: ⁠⁠⁠https://thedfirreport.com/contact/⁠⁠⁠ Services: ⁠⁠⁠https://thedfirreport.com/services/⁠⁠⁠ Music by FASSounds from Pixabay

05-13
56:46

From IcedID to Dagon Locker Ransomware in 29 Days

Report: https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days Contact Us: ⁠⁠⁠https://thedfirreport.com/contact/⁠⁠⁠ Services: ⁠⁠⁠https://thedfirreport.com/services/⁠⁠

04-29
07:52

DFIR Discussions: From OneNote to RansomNote: An Ice Cold Intrusion - Part 2

We discuss our latest report From OneNote to RansomNote: An Ice Cold Intrusion Host: ⁠⁠@Kostastsale⁠⁠ Analysts: ⁠⁠@iiamaleks⁠, ⁠@IrishD34TH⁠, & ⁠@Miixxedup⁠ Special Guest: ⁠@techspence⁠ Feedback: https://forms.office.com/r/LR9NsEWYye Report: ⁠⁠https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion/⁠ Contact Us: ⁠⁠https://thedfirreport.com/contact/⁠⁠ Services: ⁠⁠https://thedfirreport.com/services/⁠⁠ Music by FASSounds from Pixabay

04-15
21:37

DFIR Discussions: From OneNote to RansomNote: An Ice Cold Intrusion - Part 1

We discuss our latest report From OneNote to RansomNote: An Ice Cold Intrusion Host: ⁠@Kostastsale⁠ Analysts: ⁠@iiamaleks, @IrishD34TH, & @Miixxedup Special Guest: @techspence Report: ⁠https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion/ Contact Us: ⁠https://thedfirreport.com/contact/⁠ Services: ⁠https://thedfirreport.com/services/⁠ Music by FASSounds from Pixabay

04-09
25:51

From OneNote to RansomNote: An Ice Cold Intrusion

Full Report - https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion Feedback: https://forms.office.com/r/YY6w3gwd6A

04-01
07:15

DFIR Discussions: SEO Poisoning to Domain Control: The Gootloader Saga Continues

Our first DFIR Discussions podcast on our latest report SEO Poisoning to Domain Control: The Gootloader Saga Continues Host: @Kostastsale Analysts: @_pete_0, @malforsec, & @r3nzsec Special Guest: @HackingLZ⁠ Feedback: https://forms.office.com/r/mK2Jp8vPXj Report: https://thedfirreport.com/2024/02/26/seo-poisoning-to-domain-control-the-gootloader-saga-continues/ Contact Us: https://thedfirreport.com/contact/ Services: https://thedfirreport.com/services/ Music by FASSounds from Pixabay

03-11
52:13

SEO Poisoning to Domain Control: The Gootloader Saga Continues

Report - https://thedfirreport.com/2024/02/26/seo-poisoning-to-domain-control-the-gootloader-saga-continues Provide feedback for a chance to win free swag - https://forms.office.com/r/MwZXkBrUNv

02-26
08:07

Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours

Report: https://thedfirreport.com/2024/01/29/buzzing-on-christmas-eve-trigona-ransomware-in-3-hours/ Feedback: https://forms.office.com/r/pPajTA4Vwy

01-29
06:08

Recommend Channels