Ultimate Threat Hunting Playbook for Russian Cyber Operations in a Hybrid Threat Environment
ID: 769e9f46-5302-52a6-90b4-94a9a53c7821
STIX ID: report--769e9f46-5302-52a6-90b4-94a9a53c7821
Feed Name: Detect FYI
**Executive Summary:** This threat-hunting playbook documents Russian APT campaigns against energy and critical infrastructure—detailing TTPs used by APT28, Sandworm and related groups (including destructive wipers like HermeticWiper and CaddyWiper), abuse of native OT engineering tools (e.g., MicroSCADA scilc.exe), prioritized hunt steps across edge/endpoint/identity/OT, recommended detection queries, extensive IOCs (file hashes, IPs, domains) and clear escalation criteria for incidents with potential operational impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
