The Commented Kill Chain: Why Old Ransomware Playbooks Never Die
ID: 622f370b-e8ae-5426-ac89-49344a6f67da
STIX ID: report--622f370b-e8ae-5426-ac89-49344a6f67da
Feed Name: Huntress Blog
This Huntress report details a ransomware intrusion in which attackers deployed a publicly shared script (linked Gist) that disabled Microsoft Defender, Defender for Endpoint services, WMI autologgers, scheduled tasks, and boot-time protections (ELAM) and altered Defender policies to allow threats. Huntress observed lateral movement via RDP and removal of shadow copies before preventing file encryption; the report enumerates the exact reg.exe, sc, schtasks, bcdedit, and Set-MpPreference commands used, maps them to Sigma rules, and emphasizes building behavior-based detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
