#dfir
155 posts · Last used 9d
"The privilege escalation tool the threat actors brought with them was written as a text file and then decoded using certutil into a binary file."
Read the full report: https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver
#DFIR #ThreatIntel
2026-09-26 RDP #Honeypot IOCs - 366 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
66.163.119.35 - 240
104.64.217.122 - 30
165.22.190.202 - 18
Top ASNs:
AS63023 - 240
AS63949 - 45
AS396982 - 36
Top Accounts:
hello - 300
rg5hhbrn - 12
Administr - 9
Top ISPs:
GTHost - 240
Google LLC - 36
Akamai Technologies, Inc. - 33
Top Clients:
Unknown - 366
Top Software:
Unknown - 366
Top Keyboards:
Unknown - 366
Top IP Classification:
Unknown - 243
hosting - 114
hosting & proxy - 9
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
State-aligned threat actors continue to evolve their operations and infrastructure tactics. Feike Hacquebord will be speaking at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) about APT campaigns by Russia-, China-, and DPRK-aligned actors targeting Europe in 2026.
Feike will examine China-aligned residential proxy networks built on compromised IoT devices, DPRK-aligned operations run from static Russian IP addresses and hundreds of VPS servers, and a decade of Pawn Storm (APT28/Fancy Bear) activity. He will also explain how domestic Chinese AI capabilities have reduced China-aligned actors' dependence on frontier Western models.
Seating is limited. Register now to secure your spot: https://luma.com/0qtkw49c
#dfir #threatintel #apt
"Once the encryption process was complete a file called RecoveryManual.html was left across the filesystem with the instructions on how to contact the threat actors for the ransom negotiations."
Read the full report: https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours
#DFIR #ThreatIntel
2026-09-23 RDP #Honeypot IOCs - 216 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
20.51.184.62 - 39
104.64.217.122 - 27
80.66.83.43 - 18
Top ASNs:
AS8075 - 39
AS396982 - 36
AS63949 - 36
Top Accounts:
hello - 84
Administr - 24
(empty) - 21
Top ISPs:
Microsoft Corporation - 39
Google LLC - 36
Akamai Technologies, Inc. - 36
Top Clients:
Unknown - 216
Top Software:
Unknown - 216
Top Keyboards:
Unknown - 216
Top IP Classification:
hosting - 195
Unknown - 9
hosting & proxy - 6
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
Quoting
Reading the Linux Process Tree During Triage
A flat process list tells you what is running. The tree tells you what started it. This guide covers reading Linux process lineage, exposing renamed processes and recovering a deleted binary through /proc.
https://www.halkynconsulting.co.uk/a/2026/09/linux-process-tree/
Open quoted post----------------
🛠️ Tool
===================
IRDoc is a self-hostable, open-core incident response documentation platform designed for SOC analysts, IR engineers, and MSSPs. It provides a structured workspace to document an incident from initial detection through the final report, replacing the fragmented workflow of switching between a ticket system, a Word document, and a SharePoint folder.
🔹 Key Features
• Timeline-first workspace: Chronological event logging across detection, analysis, containment, evidence, and communications phases. This approach ensures that the report is built progressively as the investigation unfolds.
• IOC management: Automated tracking and detection of IPs, domains, hashes, emails, and URLs within the platform. This eliminates the need to maintain separate IOC lists.
• Evidence attachments: Drag-and-drop or paste screenshots directly into the incident timeline. This keeps visual evidence contextually aligned with the investigation steps.
• Task management: Phase-grouped tasks generated from incident templates. Analysts can track containment and remediation actions without leaving the workspace.
• Inbound webhook API: Create cases from ServiceDesk Plus, Jira, or any system capable of POSTing JSON. This allows seamless integration with existing alerting pipelines.
• Investigation graph: Visual relationship map linking IOCs, timeline entries, and attached evidence. This provides a quick overview of how different components of the incident interact.
• Self-hosted architecture: Incident data remains on the deploying organization's infrastructure, addressing data residency and privacy concerns.
🔹 Technical Implementation
The core repository is licensed under AGPL-3.0. The project integrates automated security scanning, including CodeQL, secret scanning, dependency audits, and an OpenSSF Scorecard. The maintainers state they aim to release patches for critical vulnerabilities within 24 hours of confirmation. Inbound webhooks allow integration with existing ticketing systems, ensuring IRDoc can act as a dedicated documentation layer rather than a replacement for alerting or case creation.
🔹 Use Cases
Primary use cases include structured IR case management for SOCs that require strict data residency via self-hosting. It is also suited for MSSPs needing a structured documentation framework that can map relationships between indicators and evidence across multiple client incidents. The visual investigation graph is particularly useful for complex incidents involving multiple overlapping IOCs.
🔹 Limitations
The core is free under AGPL-3.0, but the open-core model implies there may be paid features or enterprise extensions not detailed in the repository. The repository does not specify the underlying database or deployment framework in the provided summary, though documentation is available at their docs site. Performance under high concurrency is not documented.
🔹 tool #IncidentResponse #SOC #OpenSource #DFIR
🔗 Source: https://github.com/soc-irdoc/irdoc-app
Following @volexity@infosec.exchange’s September 9 blog post on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity discovered another threat actor, UTA0565, had been using the same exploits on Sept 3-4, 2026, while they were still unpatched.
UTA0565 used multiple fake websites, posing as media organizations and an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening.
Full details and IOCs can be found here: https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/
#DFIR #threatintel
2026-09-19 RDP #Honeypot IOCs - 183 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
104.64.217.122 - 30
118.69.191.219 - 24
165.22.190.202 - 18
Top ASNs:
AS396982 - 48
AS63949 - 36
AS18403 - 24
Top Accounts:
hello - 78
Administr - 21
ident - 18
Top ISPs:
Google LLC - 48
Akamai Technologies, Inc. - 36
Vietnam Internet Network Information Center - 24
Top Clients:
Unknown - 183
Top Software:
Unknown - 183
Top Keyboards:
Unknown - 183
Top IP Classification:
hosting - 120
Unknown - 39
proxy - 18
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
2026-09-18 RDP #Honeypot IOCs - 756 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
134.209.180.117 - 510
104.64.217.122 - 87
118.69.191.219 - 42
Top ASNs:
AS14061 - 510
AS63949 - 90
AS18403 - 42
Top Accounts:
hello - 642
Administr - 18
ident - 18
Top ISPs:
DigitalOcean, LLC - 510
Akamai Technologies, Inc. - 90
Vietnam Internet Network Information Center - 42
Top Clients:
Unknown - 756
Top Software:
Unknown - 756
Top Keyboards:
Unknown - 756
Top IP Classification:
hosting - 684
Unknown - 48
proxy - 18
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs).
I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.
#DFIR #IDS #Honeypots
2026-09-15 RDP #Honeypot IOCs - 2343 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
147.182.250.28 - 2263
104.64.217.122 - 10
80.66.83.43 - 6
Top ASNs:
AS14061 - 2270
AS63949 - 15
AS4766 - 13
Top Accounts:
hello - 2298
142.93.8.59 - 11
anonymous - 7
Top ISPs:
DigitalOcean, LLC - 2270
Akamai Technologies, Inc. - 15
Korea Telecom - 13
Top Clients:
Unknown - 2343
Top Software:
Unknown - 2343
Top Keyboards:
Unknown - 2343
Top IP Classification:
hosting - 2317
Unknown - 18
hosting & proxy - 4
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
iLEAPP, ALEAPP, RLEAPP, VLEAPP and DLEAPP v2026.4.0 are out!
💽 Raw disk images and E01s read directly
🖥️ GUI stays responsive while processing
📱 iLEAPP: Garmin Connect, Tutanota, MEGA
🤖 ALEAPP: Blink, Avast Cleanup, Kwai, YouCam Perfect
📑 RLEAPP: Synchronoss DV access log workbooks, quarantined CyberTip media
🚗 VLEAPP: E01, HFS+ and APFS volumes
🍎 DLEAPP: macOS iMessage, Safari, Keychain, Slack Desktop
https://leapps.org/releases
#DFIR #DigitalForensics #FOSS #MobileForensics
While you're selecting a product, I am advising strategy.
https://resilience-theatre.com/permission/
#preparedness #strategy #dfir #resilience #redteam #opensource
2026-09-09 RDP #Honeypot IOCs - 3946 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
152.42.198.23 - 2200
168.144.34.49 - 1666
80.66.83.43 - 12
Top ASNs:
AS14061 - 3878
AS396982 - 28
AS216473 - 12
Top Accounts:
hello - 3900
Administr - 12
Test - 4
Top ISPs:
DigitalOcean, LLC - 3878
Google LLC - 28
Bashinskii Vadim Ruslanovich - 12
Top Clients:
Unknown - 3946
Top Software:
Unknown - 3946
Top Keyboards:
Unknown - 3946
Top IP Classification:
hosting - 3940
Unknown - 4
hosting & proxy - 2
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
2026-08-08 RDP #Honeypot IOCs - 2091 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
155.117.13.211 - 726
170.64.227.228 - 642
206.189.58.63 - 564
Top ASNs:
AS14061 - 1236
AS16276 - 726
AS396982 - 30
Top Accounts:
hello - 2007
Domain - 18
zgrab - 6
Top ISPs:
DigitalOcean, LLC - 1236
OVH SAS - 726
Google LLC - 30
Top Clients:
Unknown - 2091
Top Software:
Unknown - 2091
Top Keyboards:
Unknown - 2091
Top IP Classification:
hosting - 1320
Unknown - 765
proxy - 6
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
2026-08-08 RDP #Honeypot IOCs - 1394 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
155.117.13.211 - 484
170.64.227.228 - 428
206.189.58.63 - 376
Top ASNs:
AS14061 - 824
AS16276 - 484
AS396982 - 20
Top Accounts:
hello - 1338
Domain - 12
zgrab - 4
Top ISPs:
DigitalOcean, LLC - 824
OVH SAS - 484
Google LLC - 20
Top Clients:
Unknown - 1394
Top Software:
Unknown - 1394
Top Keyboards:
Unknown - 1394
Top IP Classification:
hosting - 880
Unknown - 510
proxy - 4
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security
2026-08-08 RDP #Honeypot IOCs - 697 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSec
Top IPs:
155.117.13.211 - 242
170.64.227.228 - 214
206.189.58.63 - 188
Top ASNs:
AS14061 - 412
AS16276 - 242
AS396982 - 10
Top Accounts:
hello - 669
Domain - 6
zgrab - 2
Top ISPs:
DigitalOcean, LLC - 412
OVH SAS - 242
Google LLC - 10
Top Clients:
Unknown - 697
Top Software:
Unknown - 697
Top Keyboards:
Unknown - 697
Top IP Classification:
hosting - 440
Unknown - 255
proxy - 2
Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key
#CyberSec #SOC #Blueteam #SecOps #Security


