@TheDFIRReport

Real Intrusions by Real Attackers, the Truth Behind the Intrusion

thedfirreport.com/contact
Joined April 2020
"The privilege escalation tool the threat actors brought with them was written as a text file and then decoded using certutil into a binary file." Read the full report: buff.ly/DL3KZOC #DFIR #ThreatIntel
1
21
2,067
πŸ™Œ That's a wrap on the DFIR Labs Digital Forensics Challenge. Thank you to everyone who joined and dug into the case with us, we hope you had fun. We'll be posting the winners soon, so keep an eye out. Missed it or want another go? See what's next πŸ‘‰ buff.ly/dfbvzRT
1
6
2,109
🚨 It's here! The DFIR Labs Digital Forensics Challenge runs today. One real intrusion, 4 hours in Splunk or Elastic, 20+ questions, with live support in our Discord the whole way. It's not too late, sign up now πŸ‘‰ buff.ly/dfbvzRT
1
2
11
2,725
🚨 And we’re off! The DFIR Labs Digital Forensics Challenge is officially underway. πŸ”ŽπŸ’» It’s not too late to jump in and test your DFIR skills! πŸ‘‰ dfirlabs.thedfirreport.com/d… Good luck, and have fun! πŸ”₯
1
2
1
5
1,025
⏳ Last call: the DFIR Labs Digital Forensics Challenge kicks off tomorrow. 4 hours, one real intrusion, 20+ questions, live support in our Discord, and a shot at joining The DFIR Report as a volunteer analyst. Splunk or Elastic, your call. It's not too late, sign up now πŸ‘‰ buff.ly/dfbvzRT
7
24
3,406
"Once the encryption process was complete a file called RecoveryManual.html was left across the filesystem with the instructions on how to contact the threat actors for the ransom negotiations." Read the full report: buff.ly/MdzLOu9 #DFIR #ThreatIntel
6
19
2,473
The DFIR Report retweeted
🧩 The DFIR Labs Digital Forensics Challenge is a solo event, but teams are welcome too. One real intrusion, 4 hours in Splunk or Elastic, 20+ questions from beginner to expert, with live support in our Discord throughout. Want to work as a team, contact us before the event and we'll set you up as a team. Sign up or get in touch πŸ‘‰ buff.ly/eV6uLRp
5
27
4,510
πŸ”Ž We’re currently investigating an intrusion involving activity associated with the Iranian threat actor tracked as Peach Sandstorm / PULSAR KITTEN / Mirage Kitten. As part of the investigation, we’ve identified the following domains: healthy-handles[.]com healthyselfeducation[.]com If you see either domain in your environment, start IR immediately. If you need additional context or help with the investigation, reach out, we’re happy to help. In our case, after moving laterally, the actor surfaced on a Linux host with a backdoor/proxy communicating over WebSockets. Seeing similar activity or have additional context to share? We’d like to hear from you. Get in touch πŸ‘‰ buff.ly/iBfNhIo
3
20
1
86
8,088
πŸ† The DFIR Labs Digital Forensics Challenge is this Saturday, and here's the prize pool so far: 🎟️ Full-access ticket to HACKLU 2026 πŸ› οΈ Full Arsenal license 🎫 3 DeathCon online tickets πŸ”¬ 3 DFIR Labs Pro licenses 🏒 1 DFIR Labs Enterprise license A huge thank you to our sponsors for supporting the DFIR community! One real intrusion. 4 hours in Splunk or Elastic. 20+ questions ranging from beginner to expert, with live support in our Discord throughout. Compete solo, with team options available. Sign up πŸ‘‰ buff.ly/dfbvzRT
5
21
2,649
"They then inspected the documents they collected prior to exfiltrating them over to Mega storage servers using the Rclone application." Read the full report: buff.ly/9SUamWk #DFIR #ThreatIntel
8
36
3,531
πŸ› οΈ Tool Tuesday: PsExec Sysinternals' remote-execution classic, and the ransomware operator's deployment tool of choice. In our cases, actors use PsExec to push the locker to dozens of hosts in seconds. πŸ”Ž Hunt tip: watch for PSEXESVC service creation and remote service starts fanning out from a single host. See it across real intrusions πŸ‘‰ buff.ly/8k7Bink
5
44
3,318
"In this case they created a "minidump" using the LOLBIN comsvcs.dll. This was dropped to disk as ssasl.pmd (lsass.dmp reversed) and then zipped before exfiltration." Read the full report: buff.ly/7VJkhSK #DFIR #ThreatIntel
5
13
59
5,538
"The unsigned DLL, with descriptor Cancel Autoplay 2 was executed using regsvr32.exe" Read the full report: buff.ly/3xlWb5b #DFIR #ThreatIntel
4
11
1
46
4,287
πŸ”’ Private DFIR Report: ViewState of Mind, Gladinet Exploit Opens the Door A binary, wacs.exe, was written to C:\CentreStack\ and executed, the Stowaway proxy tool, connecting to a remote server at 167.99.74[.]134:443 to establish deeper access and run initial discovery. Request access or a demo πŸ‘‰ buff.ly/431UFIv #DFIR #ThreatIntel
5
18
3,111
"The threat actors have been using the associated Monero wallet for 738+ days and have netted around $5,159." Read the full report: buff.ly/o2eGMMG #DFIR #ThreatIntel
2
3
10
2,788
πŸ›‘οΈ Let the attackers tell you what they're after. Active Defense Threat Insights deploys strategic decoys that attract adversaries and capture their moves 24/7, turning real interactions into high-fidelity IOCs and mapped TTPs specific to your organization. Understand adversaries before they reach your core systems. Learn more πŸ‘‰ buff.ly/sYub7rU
4
19
2,649
πŸ”Ž Indicators from a case we are actively investigating: C2: 178[.]16[.]54[.]112:56001 Payload URL: hxxps://panaderiacoronado[.]com/temp/Frqzbx[.]exe node.exe running from AppData with an unusual flag: "C:\Users\\AppData\Local\Nodejs\node-v26.4.0-win-x64\node.exe" --experimental-ffi C:\Users\\AppData\Local\Nodejs\Zqn9A2phOI.js If you defend a network, hunt your logs for these now. Seeing the same thing, or have additional context? Get in touch πŸ‘‰ buff.ly/FHZ2Ts9
21
69
4,606
TukTuk showed up later in the intrusion as a SaaS-heavy malware framework. We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHouse and Supabase for C2, with multiple backup transports available. Full report: buff.ly/YxjNJGN #DFIR #ThreatIntel
17
27
3,385
"Using the native Windows utility wbadmin.exe, the threat actor created a volume shadow copy backup containing the ntds.dit file and the SYSTEM and SECURITY registry hives." Read the full report: buff.ly/D9knm4l #DFIR #ThreatIntel
3
32
121
7,452
πŸ’¬ "The best single-player blue team CTF I've ever participated in, and I learned a lot while playing." a past participant The DFIR Labs Digital Forensics Challenge is back: one real intrusion, 20+ questions, 4 hours in Splunk or Elastic, and live support in our Discord the whole way. See what the buzz is about, register πŸ‘‰ buff.ly/eV6uLRp
5
1
37
5,274