Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:mandiant
tags: report:checkpoint_research, report:mandiant
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
vSphere and BRICKSTORM Malware: A Defender's Guide Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. These operations directly targ
Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platfo
VECT: Ransomware by design, Wiper by accident Key Takeaways Background VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum. After claiming their first two victims in January 2026, the
Deduped connector weight from graph context.