Detection engineering, threat hunting, malware analysis. One defender bit at a time.

Join for free →
Ayush Anand retweeted
2 binaries. 6 failed connections. 1 operator IP exposed. AnyDesk attempts direct P2P (TCP 7070) before relay, ON by default. When it's blocked, the operator's real IP logs as ConnectionFailed in DeviceNetworkEvents. The relay never hid them. Hunt the failures.
1
2
8
478
Ayush Anand retweeted
Storm-2570 drops Qilin, DragonForce, Anubis and BERT. Consistent discovery tool: NetScan. 31 ransomware groups use it, per the Tool Matrix. The cmdline is the tell, not the filename: /hide = no GUI /auto:<file> = scan, write XML Hunt queries:
Across intrusions leading to different ransomware payloads, the ransomware affiliate Storm-2570 has used consistent post-compromise tools and techniques, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. msft.it/6015a9GkD Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.
1
2
5
694
Ayush Anand retweeted
Ever remediated the ScreenConnect implant your alert fired on and moved on? A real sample dropped two, 9 min apart. The second, self-hosted one (wonderxp[.]top:8041) shipped its own app.config: - AccessShowUnderControlBanner = false - AccessShowBalloonOnConnect = false - AccessShowSystemTrayIcon = false Every "you are being watched" cue the client shows, switched off in XML. The cloud client beside it had no app.config. Two implants means two services. Count them before you close the case.
12
27
3,451
2 binaries. 6 failed connections. 1 operator IP exposed. AnyDesk attempts direct P2P (TCP 7070) before relay, ON by default. When it's blocked, the operator's real IP logs as ConnectionFailed in DeviceNetworkEvents. The relay never hid them. Hunt the failures.
1
2
8
478
Caveat: a careful operator can disable direct connections and force relay-only. Treat the IP as a pivot IOC, not attribution. If they stayed behind the relay, use this method to check for hits:
AnyDesk logs the operator's real IP to disk. NetFlow, proxy, EDR network events: all show the relay. Dead end. The host trace file has the actual source. Grep "Logged in from": Service: %PROGRAMDATA%\AnyDesk\ad_svc.trace Portable: %APPDATA%\AnyDesk\ad.trace Egress IP, not attribution. Pivot on it 🔍
90
Storm-2570 drops Qilin, DragonForce, Anubis and BERT. Consistent discovery tool: NetScan. 31 ransomware groups use it, per the Tool Matrix. The cmdline is the tell, not the filename: /hide = no GUI /auto:<file> = scan, write XML Hunt queries:
Across intrusions leading to different ransomware payloads, the ransomware affiliate Storm-2570 has used consistent post-compromise tools and techniques, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. msft.it/6015a9GkD Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.
1
2
5
694
An attacker pointed a signed ScreenConnect client at their own relay. The command line gave it up. ?e=Access&y=Guest&h=<relay>&p=<port> - e= is the role. Access = unattended, Support = attended - h= and p= are the relay. instance-*[.]screenconnect[.]com:443 = cloud, 8041 = theirs 1. Never filter on e=Access. Operators start on Support, then upgrade 2. Baseline h=. Alert on an unseen relay Mine: wonderxp[.]top and relay[.]robertsonins[.]co. Both 8041, both unseen. Deep dive lands Thursday.
2
10
886
There are plenty of ways to build a detection lab, but elastic-container is the fastest Elastic stack setup I know. One script gives you: - Elasticsearch + Kibana + Fleet - Detection Engine on, prebuilt rules bulk-enabled by OS - 100% containerized, one command up or down Have Claude or Codex set it up for you. Credit: Andrew Pease (@andythevariable). github.com/peasead/elastic-c…
5
9
681
Ever closed a ScreenConnect case on EDR timestamps alone? My EDR's last event on the operator: 17:09. The product's own Application log had them working until 17:17. Get-WinEvent -FilterHashtable @{LogName='Application'; ProviderName='ScreenConnect'; Id=100,101,201} | Sort-Object TimeCreated | fl TimeCreated, Id, Message - 100/101 = operator connect/disconnect with session label - 201 = file transfer. Two implants on one box: scream care, then spacex7. A 4 min incident was 12 min.
1
3
17
1,138
BlackFile shut down in May. The crew is still in play as Redact, Pink, Helix and Falcon. Helpdesk call to your personal phone, then a "passkey enrolment" AiTM page. EDR sees nothing. 3 identity tells (GTIG): - MFA factor registered right after abandoned pushes - UAL FileAccessed from a python-requests / PowerShell UA - SSO sign-in via commercial VPN or residential proxy cloud.google.com/blog/topics…
3
13
4,266
Ever closed an RMM alert because the tool was sanctioned? Stop hunting AnyDesk by filename. Rank it by how rare it is across your fleet. A sanctioned tool is everywhere. A renamed copy on 1 host is the lead, even as Invoice_Viewer.exe still carrying AnyDesk's PE metadata. Full case, 32 ransomware groups and why your EDR sees a legit tool, in my Article below. 🔎
1
1
19
2,437
One process. 254 IPs. 5 ports. One time window. That's a network sweep, and the binary name never entered the logic. A dcount threshold on DeviceNetworkEvents catches Advanced IP Scanner, Advanced Port Scanner, and NetScan the same way. Signature-free 🔎
8
514
Ayush Anand retweeted
Been testing GPT-6 Astra against some recent malware we collected through IR engagements. I used the ChatGPT Chrome extension with Guacamole running a @ThruntingLabs FlareVM environment directly inside the browser. Samples included a recent SynkLoader, SystemBC and a few fairly nasty obfuscated DLLs. Using high effort, Astra got through the analysis in roughly 15 minutes and found pretty much everything I was looking for, including obfuscated configuration, encrypted passwords embedded in the binaries and the important execution behaviour. That part impressed me, but overall, computer use is insane! Compared with GPT-5.6 Sol, the difference is huge. Astra was much better at understanding what was on screen, interacting with the tooling and moving through the analysis without getting lost. This changes the automation angle quite a bit. You can now start thinking about automating workflows around the actual tools analysts already use, rather than having to rebuild everything around APIs and custom integrations. Just throw Computer Use at it and let it do the work. Very interesting direction for DFIR and malware analysis!
5
50
298
19,500
Your FileZilla alert is buried under installer and auto-update traffic. Cut that chatter and one connection is left standing. 🔎 The vendor noise lives on 80/443. Filter it. What survives on a file server: fzsftp.exe to a public IP on a custom port (3333), non-IT user, outside change windows. That's the connection to triage.
1
2
14
7,953
One SSH tunnel made 302 connections. 296 of them failed. That's not a pivot, that's a subnet sweep. Two signals: destination cardinality and failure rate. A fixed forward holds one IP, one port, zero failures. A subnet sweep churns many IPs, many ports, successes and failures together. Same mechanism. Different shape. I reproduced all three in the lab and put the rows side by side. Full breakdown 👇
1
1
381