"The privilege escalation tool the threat actors brought with them was written as a text file and then decoded using certutil into a binary file."
Read the full report: buff.ly/DL3KZOC#DFIR#ThreatIntel
π That's a wrap on the DFIR Labs Digital Forensics Challenge. Thank you to everyone who joined and dug into the case with us, we hope you had fun.
We'll be posting the winners soon, so keep an eye out.
Missed it or want another go? See what's next π buff.ly/dfbvzRT
π¨ It's here! The DFIR Labs Digital Forensics Challenge runs today.
One real intrusion, 4 hours in Splunk or Elastic, 20+ questions, with live support in our Discord the whole way.
It's not too late, sign up now π buff.ly/dfbvzRT
π¨ And weβre off!
The DFIR Labs Digital Forensics Challenge is officially underway. ππ»
Itβs not too late to jump in and test your DFIR skills!
π dfirlabs.thedfirreport.com/dβ¦
Good luck, and have fun! π₯
β³ Last call: the DFIR Labs Digital Forensics Challenge kicks off tomorrow.
4 hours, one real intrusion, 20+ questions, live support in our Discord, and a shot at joining The DFIR Report as a volunteer analyst. Splunk or Elastic, your call.
It's not too late, sign up now π buff.ly/dfbvzRT
"Once the encryption process was complete a file called RecoveryManual.html was left across the filesystem with the instructions on how to contact the threat actors for the ransom negotiations."
Read the full report: buff.ly/MdzLOu9#DFIR#ThreatIntel
π Weβre currently investigating an intrusion involving activity associated with the Iranian threat actor tracked as Peach Sandstorm / PULSAR KITTEN / Mirage Kitten.
As part of the investigation, weβve identified the following domains:
healthy-handles[.]com
healthyselfeducation[.]com
If you see either domain in your environment, start IR immediately. If you need additional context or help with the investigation, reach out, weβre happy to help.
In our case, after moving laterally, the actor surfaced on a Linux host with a backdoor/proxy communicating over WebSockets.
Seeing similar activity or have additional context to share? Weβd like to hear from you.
Get in touch π buff.ly/iBfNhIo
π The DFIR Labs Digital Forensics Challenge is this Saturday, and here's the prize pool so far:
ποΈ Full-access ticket to HACKLU 2026
π οΈ Full Arsenal license
π« 3 DeathCon online tickets
π¬ 3 DFIR Labs Pro licenses
π’ 1 DFIR Labs Enterprise license
A huge thank you to our sponsors for supporting the DFIR community!
One real intrusion. 4 hours in Splunk or Elastic. 20+ questions ranging from beginner to expert, with live support in our Discord throughout.
Compete solo, with team options available.
Sign up π buff.ly/dfbvzRT
"They then inspected the documents they collected prior to exfiltrating them over to Mega storage servers using the Rclone application."
Read the full report: buff.ly/9SUamWk#DFIR#ThreatIntel
π οΈ Tool Tuesday: PsExec
Sysinternals' remote-execution classic, and the ransomware operator's deployment tool of choice. In our cases, actors use PsExec to push the locker to dozens of hosts in seconds.
π Hunt tip: watch for PSEXESVC service creation and remote service starts fanning out from a single host.
See it across real intrusions π buff.ly/8k7Bink
"In this case they created a "minidump" using the LOLBIN comsvcs.dll. This was dropped to disk as ssasl.pmd (lsass.dmp reversed) and then zipped before exfiltration."
Read the full report: buff.ly/7VJkhSK#DFIR#ThreatIntel
π Private DFIR Report: ViewState of Mind, Gladinet Exploit Opens the Door
A binary, wacs.exe, was written to C:\CentreStack\ and executed, the Stowaway proxy tool, connecting to a remote server at 167.99.74[.]134:443 to establish deeper access and run initial discovery.
Request access or a demo π buff.ly/431UFIv#DFIR#ThreatIntel
"The threat actors have been using the associated Monero wallet for 738+ days and have netted around $5,159."
Read the full report: buff.ly/o2eGMMG#DFIR#ThreatIntel
π‘οΈ Let the attackers tell you what they're after.
Active Defense Threat Insights deploys strategic decoys that attract adversaries and capture their moves 24/7, turning real interactions into high-fidelity IOCs and mapped TTPs specific to your organization.
Understand adversaries before they reach your core systems.
Learn more π buff.ly/sYub7rU
π Indicators from a case we are actively investigating:
C2: 178[.]16[.]54[.]112:56001
Payload URL:
hxxps://panaderiacoronado[.]com/temp/Frqzbx[.]exe
node.exe running from AppData with an unusual flag:
"C:\Users\<user>\AppData\Local\Nodejs\node-v26.4.0-win-x64\node.exe" --experimental-ffi C:\Users\<user>\AppData\Local\Nodejs\Zqn9A2phOI.js
If you defend a network, hunt your logs for these now.
Seeing the same thing, or have additional context? Get in touch π buff.ly/FHZ2Ts9
TukTuk showed up later in the intrusion as a SaaS-heavy malware framework.
We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHouse and Supabase for C2, with multiple backup transports available.
Full report: buff.ly/YxjNJGN#DFIR#ThreatIntel
"Using the native Windows utility wbadmin.exe, the threat actor created a volume shadow copy backup containing the ntds.dit file and the SYSTEM and SECURITY registry hives."
Read the full report: buff.ly/D9knm4l#DFIR#ThreatIntel
π¬ "The best single-player blue team CTF I've ever participated in, and I learned a lot while playing."
a past participant
The DFIR Labs Digital Forensics Challenge is back: one real intrusion, 20+ questions, 4 hours in Splunk or Elastic, and live support in our Discord the whole way.
See what the buzz is about, register π buff.ly/eV6uLRp