The Infocyte Blog

Ransomware

Dealing with DarkSide

This post was last updated on September 23rd, 2021 at 03:28 pmBrian Krebs recently reviewed more details about ‘DarkSide’ and this ransomware group’s role in shutting down the Colonial Pipeline. DarkSide is a group that packages and provides ransomware capabilities as a service. Other ransomware gangs and organizations pay a fee for DarkSide tools and…

Read More »
Behavioral Analytics Blog

Practical MITRE ATT&CK Coverage Part II: Top 20 Focus

Follow up blog on why you should monitor for the Top 20 attacker behaviors: not 10, not 30.

Read More »

Top 20 Most Common Hacker Behaviors

This post was last updated on August 27th, 2021 at 03:59 pmThe top MITRE ATT&CK™ behaviors to monitor for on your endpoints and servers When the OWASP Top 20 Vulnerabilities was first published it revolutionized our industry’s approach to vulnerability management. Instead of playing wack-a-mole with thousands of individual vulnerabilities every time a new one…

Read More »

Practical MITRE ATT&CK Coverage

Chasing the unnecessary and unachievable need for FULL MITRE COVERAGE? Here’s why thats a bad idea.

Read More »
cyber endpoints bkg

Exchange Week 2 – Ransomware Joins The Fray

This post was last updated on August 24th, 2021 at 10:02 amFollowing exposure and publication of a major remote execution vulnerability like Exchange’s ProxyLogon (CVE-2021-26855), we expect other threat actors to join the race against system administrators trying to patch their systems. Initial reporting showed the threat actor dubbed HAFNIUM were quietly exploiting these vulnerabilities since…

Read More »

HAFNIUM Exchange Zero-Day Scanning

This post was last updated on August 10th, 2021 at 05:54 pmThe Microsoft Exchange Zero-day exploit drop this week is a big one with far reaching implications for organizations in 2021. Infocyte recommends the following actions organizations need to take when these exploits are being used in the wild: 1. Take inventory Do you host…

Read More »
cyber endpoints bkg

Responding to Microsoft 365 Attacks

This post was last updated on August 24th, 2021 at 10:02 amResponding to the December 2020 SolarWinds Supply Chain Attack (“Solarigate”) solidified one of the most pressing security gaps of this new decade: visibility and defense against cloud application attacks. In Solarigate, attackers used the tainted SolarWinds software as an entry vector into servers and…

Read More »
Sunburst Malware Scanner Image

SUNBURST – Where We Are Now – 2021

Many of us spent the holidays hunting for Solarwinds backdoors. So where are we now? What did we learn? Whats left to be done? SUNBURST in 2021.

Read More »
cyber endpoints bkg

Hunting for SolarWinds Orion Compromises

Infocyte has published an official Infocyte extension which scans servers for all reported host-based indicators of compromise related to the Solarwinds Orion compromise.

Read More »
infocyte mid-market threat and incident response cyber report

Mid-market Threat and Incident Response Report: Our Methodology

This post was last updated on August 11th, 2021 at 11:14 amLast month, we released our inaugural Mid-market Threat and IR Report on the types of threats we’re finding in customer- and partner-led threat assessments and incident response investigations. One of the most interesting and controversial data points is the enormous amount of dwell time…

Read More »