From the field to the report and back again: How incident responders can use the Year in Review
ID: e57c9bd7-86f1-5bda-9299-e6f3c17e0f95
STIX ID: report--e57c9bd7-86f1-5bda-9299-e6f3c17e0f95
Feed Name: Cisco Talos
Cisco Talos' Year in Review distills IR engagements and telemetry into prioritized trends and operational guidance: identity-based attacks (60% of Talos IR cases) and Active Directory abuse are dominant, MFA bypass and device compromise are rising, specific vulnerabilities (e.g., React2Shell, ToolShell) are heavily exploited, ransomware (notably Qilin) and evolving phishing/AI-enabled threats remain major risks; the report emphasizes validating detections, mapping to MITRE ATT&CK, and exercising response plans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
