Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:microsoft_mstic, report:secureworks, report:talos, report:the_hacker_news
tags: report:microsoft_mstic, report:secureworks, report:the_hacker_news
tags: report:secureworks, report:the_hacker_news
tags: report:talos, report:the_hacker_news
tags: report:microsoft_mstic, report:talos
tags: report:microsoft_mstic, report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. By Ron Scott-Adams Mo
deno-case-studies Attack TTPs combine fileless execution, wide LOLBin use Categories: Threat Research Abuse of alternative runtime environments Deno-tes defender headaches | SOPHOS Skip to Content Open search Get started Experiencing a cyberattack? Get help now Sign in Sophos C
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution wh
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full
Crypto Clipper uses Tor and worm-like propagation for persistence and control Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocu
Deduped connector weight from graph context.