logo

When the SOC Goes to Deadwood: A Night to Remember 

ID: 18394360-11bf-56c8-ae4c-fb359197a58a

STIX ID: report--18394360-11bf-56c8-ae4c-fb359197a58a

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2026-02-04

Date Updated: 2026-04-27

Author: BHIS

...
...

A first-person account of Black Hills Information Security's SOC responding to an active ransomware incident discovered during a company conference. The attackers exploited EDR exclusions to execute malicious binaries, delete VSS shadows, create scheduled tasks, and establish command-and-control and lateral movement. The entire SOC rapidly collaborated—removing exclusions, feeding IOCs, and performing containment actions—which stopped the ransomware before backups were impacted and prevented a ransom payment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.