The DFIR Report - Blog post I worked on
If you've arrived here, you're probably aware that I've been working with the guys from The DFIR Report for several years. To make it easier for readers who want to know which reports I worked on, I've included all of the references below:
- WebLogic RCE Leads to XMRig
- From Zero to Domain Admin
- Exchange Exploit Leads to Domain Wide Ransomware
- Diavol Ransomware
- APT35 Automates Initial Access Using ProxyShell
- Quantum Ransomware
- BumbleBee Zeros in on Meterpreter
- Emotet Strikes Again – Lnk File Leads to Domain Wide Ransomware
- 2022 Year in Review