The untold story of incident response: A Christmas Miracle
ID: 5c30f49c-1c76-58ee-a108-145b52090ef5
STIX ID: report--5c30f49c-1c76-58ee-a108-145b52090ef5
Feed Name: Group-IB Blog
Threat Score
**Group-IB recounts a rapid incident response where Threat Intelligence identified a SystemBC C2 and DFIR/Managed XDR teams stopped a ransomware intrusion before file encryption; the report details timelines, artifacts (Mimikatz outputs, net scanner configs, AnyDesk, dfControl, PCHunter, Cobalt Strike), evidence of an initial access broker and a follow-on ransomware actor, and remediation steps including blocking malicious binaries and neutralizing the C2.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
