An insider insights into Conti operations – Part two
ID: 348ae7c7-8031-5fe6-adcb-ce8aecb159df
STIX ID: report--348ae7c7-8031-5fe6-adcb-ce8aecb159df
Feed Name: Sekoia.com
Threat Score
This blog post analyzes leaked Conti operator manuals and demonstrates practical detection rules for their observed techniques — including disabling Windows Defender via PowerShell, dumping NTDS.dit from Volume Shadow Copies, domain discovery with nltest and net commands, data exfiltration using Rclone, and Cobalt Strike C2 infrastructure — with guidance for Windows/Sysmon event-based detection and references to Sigma rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
