Exposing Data Exfiltration: Detecting LOLBins, TTPs, and Ransomware Tactics
ID: 14247e3c-4aec-5c29-a48c-8a9644e18bc9
STIX ID: report--14247e3c-4aec-5c29-a48c-8a9644e18bc9
Feed Name: Huntress Blog
Threat Score
Huntress outlines common data staging and exfiltration techniques used by ransomware actors, providing real-world command-line examples and observed tool usage (archivers, backup utilities, cloud-sync tools, LOLBins and s5cmd) across multiple incidents; the report highlights that attackers commonly exfiltrate data immediately prior to encryption (enabling double extortion) and emphasizes detection challenges for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
