logo

The Commented Kill Chain: Why Old Ransomware Playbooks Never Die

ID: 622f370b-e8ae-5426-ac89-49344a6f67da

STIX ID: report--622f370b-e8ae-5426-ac89-49344a6f67da

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-07-31

Date Updated: 2026-04-28

...
...

This Huntress report details a ransomware intrusion in which attackers deployed a publicly shared script (linked Gist) that disabled Microsoft Defender, Defender for Endpoint services, WMI autologgers, scheduled tasks, and boot-time protections (ELAM) and altered Defender policies to allow threats. Huntress observed lateral movement via RDP and removal of shadow copies before preventing file encryption; the report enumerates the exact reg.exe, sc, schtasks, bcdedit, and Set-MpPreference commands used, maps them to Sigma rules, and emphasizes building behavior-based detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.