Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Investigating Intrusions From Intriguing Exploits

released on 2023-02-10 @ 01:27:56 PM
Share on LinkedIn Share on Facebook Share on Reddit Summary On 02 February 2023, an alert triggered in a Huntress-protected environment. At first glance, the alert itself was fairly generic - a combination of certutil using the urlcache flag to retrieve a remote resource and follow-on scheduled task creation - but further analysis revealed a more interesting set of circumstances. By investigating the event in question and pursuing root cause analysis (RCA), Huntress was able to link this intrusion to a recently-announced vulnerability as well as to a long-running post-exploitation framework linked to prominent ransomware groups.