Posts in category: Incident Response

Volt Typhoon APT Intrusion Investigation Report

July 30, 2025

Comprehensive forensic investigation into a suspected Volt Typhoon intrusion. Covers initial access via Zoho ManageEngine ADSelfService Plus, execution using WMIC, credential dumping, lateral movement, and log tampering tactics.

Read more →

Hunt ransomware

February 1, 2025

An Exchange server was compromised with ransomware. Use Splunk to investigate how the attackers compromised the server.

Read more →

REvil Corp

February 1, 2025

You are involved in an incident response engagement and need to analyze an infected host using Redline

Read more →