CSI: Evidence Indicators for Targeted Ransomware Attacks – Part II
ID: da87adcf-b03b-5dd2-825b-d93419c2b1c1
STIX ID: report--da87adcf-b03b-5dd2-825b-d93419c2b1c1
Feed Name: McAfee Labs Blog
This article explains the typical kill-chain of targeted ransomware attacks: initial compromise often via info-stealers to harvest credentials, escalation and lateral movement using tools like Mimikatz and post-exploitation frameworks (Empire, Cobalt Strike), and eventual distribution/execution of ransomware. It outlines observable indicators (PowerShell logs, Event logs, network URIs, memory/process artifacts), emphasizes detecting behaviors over signatures, and provides hunting and evidence-preservation guidance for responders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
