Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:mandiant, report:microsoft_mstic, report:secureworks, report:talos
tags: report:microsoft_mstic, report:secureworks
tags: report:mandiant, report:talos
tags: report:microsoft_mstic, report:talos
tags: report:microsoft_mstic
tags: report:talos
tags: report:talos
tags: report:secureworks
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI
Introduction to COM usage by Windows threats Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it use
2608-volatility-interlock <p>Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists</p> Categories: Threat Research Interlock ransomware gang creates volatile situation | SOPHOS Skip to Content Open search Get started Experiencing a cyberattack? Get
Crypto Clipper uses Tor and worm-like propagation for persistence and control Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocu
Deduped connector weight from graph context.