Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:crowdstrike, report:eset, report:mandiant, report:microsoft_mstic, report:secureworks
tags: report:checkpoint_research, report:microsoft_mstic, report:secureworks, report:trend_micro
tags: report:checkpoint_research, report:mandiant, report:talos, report:unit42
tags: report:crowdstrike, report:talos
tags: report:talos, report:trend_micro
tags: report:trend_micro, report:unit42
tags: report:trend_micro, report:unit42
tags: report:trend_micro, report:unit42
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. By Ron Scott-Adams Mo
Webworm: New burrowing techniques ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal Webworm: New burrowing techniques Award-winning news, views, and insight from the ESET security community English Español Deutsch Portug
deno-case-studies Attack TTPs combine fileless execution, wide LOLBin use Categories: Threat Research Abuse of alternative runtime environments Deno-tes defender headaches | SOPHOS Skip to Content Open search Get started Experiencing a cyberattack? Get help now Sign in Sophos C
ACR Stealer: Two observed intrusion chains amid increased threat activity From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browse
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives
Deduped connector weight from graph context.