logo

2022 Year in Review

ID: 7dbbf18a-77ee-54d3-998f-de3866a5c78f

STIX ID: report--7dbbf18a-77ee-54d3-998f-de3866a5c78f

Feed Name: The DFIR Report

Threat Score
75/100

Date Published: 2023-03-06

Date Updated: 2026-04-19

Author: editor

...
...

### Executive summary: This report provides a data-driven overview of 2022 intrusion activity, highlighting the prevalence of phishing-driven initial access, the shift from macro-based attachments to ISO/ZIP+LNK delivery, widespread use of Cobalt Strike and remote access tools (AnyDesk, Atera), common privilege-escalation and credential-theft techniques (LSASS dumps, Mimikatz, Kerberoasting), and observed exfiltration methods (Rclone, web shells); it also lists detection artifacts such as JA3 hashes and Suricata/Sigma rules to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.