
Ben
@polygonben
Followers
671
Following
1K
Media
54
Statuses
246
SOC analyst @HuntressLabs | GCFA | Views are my own
Joined November 2022
Interesting hands-on-keyboard case today @HuntressLabs . -> Suspected VPN initial access.-> TA used this to RDP to DC & RDS.-> TA created a hidden accounts for persistence.-> TA attempted to clear logs for defence evasion.-> Huntress evicted TA 😎.
5
26
174
RT @gleeda: We’ve started seeing Crux ransomware, which seems to be related to / affiliated with BlackByte ransomware (maybe?). Since we ha….
0
15
0
RT @EncapsulateJ: If your organisation uses a third-party managed IT provider, and said IT provider says you have a shiny VPN with logging….
0
1
0
RT @HuntressLabs: Congratulations to @RussianPanda9xx & @polygonben for having talks accepted at #defcon33! . Follow these folks and if you….
0
19
0
RT @virusbtn: Researchers from The DFIR Report, in partnership with Proofpoint, have identified a PHP variant of Interlock RAT (aka NodeSna….
0
17
0
RT @BSidesChelt: It's the week of BSides Cheltenham, and we're looking for some final prize donations for our Charity Raffle. We're suppo….
0
5
0
RT @sudo_Rem: I've started the rather tedious project of labeling every Cloudflared account ID that is observed on multiple, unrelated orga….
0
1
0
RT @0xBurgers: Always learned about these but never seen ITW myself until yesterday. WebDAV abuse in phishing kits isn’t dead. file:// UNC….
0
8
0
RT @ajpc500: Turns out the same ClickFix mitigation of ‘disabling’ the Win+R shortcut (HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Polic….
0
77
0
RT @MalwareVillage: The Call for Sponsors for #MalwareVillage at @DEFCON 33 is open until July 7, 2025!. 📄 Sponsor Package: .
0
10
0
RT @BSidesChelt: Announcing our Opening Keynote 🎉. @NCSC CTO @ollieatnowhere will give us an overview of what a nation scale set of challen….
0
14
0
RT @Antonlovesdnb: Coming up on my 1 year anniversary with @HuntressLabs ! . Taking this opportunity to go over some things myself and the….
0
47
0
RT @Level_Effect: Workshops, or dare we say "micro courses"? We’re talking full malware labs, not just slides and talking for 20 minutes. T….
0
6
0
Following on from this, I only just realised their was a linked Telegram bot embedded with. the infostealer binary. Message @Phantomsoftwares_bot to buy using crypto
0
0
2