Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics. Filtered to series-cases.

tag: series-cases2

AnalysisMembers

Case study: the update was signed, and that was the problem

A trusted software update that carried a backdoor, worked as a case. Signing proved the build was the vendor's; it proved nothing about what was in it. Eight questions on detection, scope and the uncomfortable part, which is that nothing your endpoint controls were watching for was wrong.

about 55 minutes of workT1195.002T1071.004T1553.002

Full write-up available to members subscribers. See what is included.

AnalysisMembers

Case study: one appliance, and the disclosure that followed

CL0P against MOVEit Transfer, worked as a case rather than read as news. A zero-day in an internet-facing file transfer product, a web shell, and a scope question that has nothing to do with how many hosts were touched. Nine questions, and the answers are in the advisory.

about 1 hours of workCVE-2023-34362T1190T1505.003T1567

Full write-up available to members subscribers. See what is included.