2025 Threat Detection Report: Practitioner playbook
ID: 889e4848-2f2c-5f1a-bb08-701e4d30e7c6
STIX ID: report--889e4848-2f2c-5f1a-bb08-701e4d30e7c6
Feed Name: Red Canary
Red Canary analysts distill five priorities from the 2025 Threat Detection Report: audit and restrict RMM tools commonly abused by adversaries (e.g., ScreenConnect, TeamViewer, NetSupport Manager) including in ransomware operations; maintain EDR on endpoints alongside cloud monitoring; enforce MFA to counter valid-credential abuse driven by stealer malware; harden Windows via GPO to open script types in editors to mitigate families like SocGholish, Scarlet Goldfinch, and Gootloader; and train users to recognize browser-based lures such as fake CAPTCHAs, fake updates, and paste-and-run prompts (Win+R/Win+X followed by Ctrl+V PowerShell). The guidance emphasizes practical mitigations against prevalent e-crime TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
