DCSync Detection with NetWitness February 7, 2023 Introduction In this post we will look at the DCSync OS Credential Dumping technique targeting... Read More
Hafnium/Microsoft Exchange Breach Detection with NetWitness March 19, 2021 Hafnium, a state-sponsored APT group, is believed to have potentially compromised tens of thousands... Read More
Maze Ransomware Detection with RSA NetWitness April 20, 2020 The Maze ransomware has recently been making the news due to some high-profile infections. In... Read More
Zoom Meeting UNC Abuse and Detection with RSA NetWitness April 2, 2020 With the sudden surge in popularity for Zoom meetings, an increase interest has been seen by... Read More
SynAck Ransomware's Behavior in RSA NetWitness Endpoint May 14, 2018 A new variant of the SynAck ransomware has been seen in the wild using Process Doppleganging to... Read More
MS Excel Command Execution Without Macros October 16, 2017 There has recently been a reappearance of a method used to execute commands via malicious Excel... Read More
WannaCry from the RSA NetWitness Suite's Perspective May 14, 2017 In this post, I will quickly go through some aspects of the WannaCry ransomware from the... Read More
Post Exploitation - Sniff the Target's Encrypted Traffic in Clear-Text April 25, 2017 NetRipper is a post exploitation tool targeting Windows systems which uses API hooking in order to... Read More
Integrate RSA NetWitness Incident Management with Todoist April 5, 2017 This is not an RSA officially supported integration. This script will sync the incidents of a... Read More
Fileless Infection (and Detection) February 21, 2017 Fileless infection is a method used to compromise a system without writing any file to disk. This... Read More