logo

Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)

ID: 6ae463eb-0552-506d-b446-3257adcfd664

STIX ID: report--6ae463eb-0552-506d-b446-3257adcfd664

Feed Name: SANS ISC Diary

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

This SANS ISC diary reconstructs an Akira ransomware intrusion using only SSLVPN and Windows EVTX logs: attackers used credential stuffing against a deprovisioned local VPN account, performed discovery (nltest/net), Kerberoasted service accounts, RDP’d laterally to domain controllers, cleared logs and deleted shadow copies, then encrypted files; the report emphasizes the importance of joining perimeter and endpoint logs, provides concrete detection/hunting recommendations (SSLVPN MFA, EID 4688/4769/1102 monitoring, vssadmin auditing, time sync), and maps observed TTPs to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.