Yours Truly, Signed AV Driver: Weaponizing an Antivirus Driver

February 26, 2022 | Eduardo Mattos and Rob Homewood

In 2021, Stroz Friedberg observed novel indicators of compromise (IOCs) and a ...

Trustwave's Action Response: Multiple Log4j Zero-Day Vulnerabilities

December 10, 2021 | SpiderLabs Researcher

Updates: Dec. 29: Updated to cover three additional CVEs: CVE-2021-4104, ...

Cloudy with a Chance of Persistent Email Access

January 29, 2021 | Partha Alwar, Carly Battaile and Alex Parsons

How an advanced threat group leveraged Microsoft Azure to gain persistent ...

APT X – Process Hollowing

January 27, 2021 | Faisal Tameesh

A detailed walkthrough of the process hollowing injection technique.

See ya in S3!

November 14, 2020 | Mary Braden Murphy

Stroz Friedberg has unique insight on how attackers attempt to cover their ...

Into Defray

October 08, 2020 | Daniel Spicer

Stroz Friedberg provides a look into the techniques and patterns of the ...

Close, but no Ragnar

August 19, 2020 | Daniel Spicer and Partha Alwar

Stroz Friedberg Incident Response Services has observed Ragnar Locker use ...

Copy-Paste Threat Actor in the Asia Pacific Region

June 19, 2020 | Reegun Jayapaul

Summary Australian Prime Minister Australian Prime Minister Scott Morrison ...

Hardcoded Credentials in Uniguest Kiosk Software Lead to API Compromise

July 11, 2019 | Adrian Pruteanu

If you've traveled at all within North America, you've likely at some point ...

Wowza Streaming Engine Manager Directory Traversal And Local File Inclusion

February 11, 2019 | Sean Melia

CVE-2018-19365: Root local file inclusion in Wowza SRM 4.7.4.01.

The Petya/NotPetya Ransomware Campaign

June 27, 2017 | SpiderLabs Researcher

This is an ongoing, emerging story and may be updated after posting.

SSH Weak Diffie-Hellman Group Identification Tool

August 03, 2015 | Fabian Foerg

Check SSH servers for weak Diffie-Hellman key exchange configurations.