Here is a retrospective of the major trends observed by Intrinsec’s Cyber Threat Intelligence team regarding the month of January 2023. This threat landscape analysis will particularily concentrate on two elements: The most active ransomware operators, detailing...
Vice Society is a financially motivated organization encompassing operators and opportunistic intrusion sets known for intrusion, exfiltration and extorsion against a large sample of victims since June 2021. The operator(s) of these alleged intrusion sets offer(s) an...
Context By the end of 2022, CERT Intrinsec dealt with the newly discovered bypass of ProxyNotShell named OWASSRF. This article details the modus operandi of a threat actor that exploited this vulnerability. On day one, the attackers leveraged vulnerable Exchange...
Context During 2022, a company discovered that one of their equipments was communicating with a known command and control server. As a result, the company decided to contact CERT Intrinsec in order to get help to handle the security breach and manage the crisis. CERT...
This article shares a method & tool developped by Intrinsec to reconstruct attack path using Microsoft Protection logs. Enjoy reading & hunting ! During incident response, CERT Intrinsec performs investigation so as to find indicators of compromise and...
Dans le cadre du salon de cybersécurité de LeHack 2022, Intrinsec a proposé un ensemble d’épreuves afin de divertir et challenger les visiteurs du salon. Ce CTF conçu par notre consultant Thibaud ROBIN est constitué de 12 épreuves. Il évolue dans un contexte réaliste...
Chaque année, l’école ESGI organise le Security Day, une journée durant laquelle les étudiants de la filière Sécurité Informatique et des professionnels de la sécurité ont la possibilité d’assister à des conférences animées par des consultants IT. Ce mardi...
Introduction Since a couple of years, ransomware attacks are one of organizations’ biggest threats. Indeed, those attacks can dramatically disturb operations by stopping production, order intake or orders shipments for days. Starting from isolated and capable...