logo

2025 Threat Detection Report: Practitioner playbook

ID: 889e4848-2f2c-5f1a-bb08-701e4d30e7c6

STIX ID: report--889e4848-2f2c-5f1a-bb08-701e4d30e7c6

Feed Name: Red Canary

Date Published: 2025-03-27

Date Updated: 2026-04-29

Author: Tony Lambert

...
...

Red Canary analysts distill five priorities from the 2025 Threat Detection Report: audit and restrict RMM tools commonly abused by adversaries (e.g., ScreenConnect, TeamViewer, NetSupport Manager) including in ransomware operations; maintain EDR on endpoints alongside cloud monitoring; enforce MFA to counter valid-credential abuse driven by stealer malware; harden Windows via GPO to open script types in editors to mitigate families like SocGholish, Scarlet Goldfinch, and Gootloader; and train users to recognize browser-based lures such as fake CAPTCHAs, fake updates, and paste-and-run prompts (Win+R/Win+X followed by Ctrl+V PowerShell). The guidance emphasizes practical mitigations against prevalent e-crime TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.