Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type ip · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
tags: report:secureworks
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
2608-volatility-interlock <p>Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists</p> Categories: Threat Research Interlock ransomware gang creates volatile situation | SOPHOS Skip to Content Open search Get started Experiencing a cyberattack? Get
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft Introduction Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These ope
Welcome to BlackFile: Inside a Vishing Extortion Operation Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under
Deduped connector weight from graph context.