Context During 2022, a company discovered that one of their equipments was communicating with a known command and control server. As a result, the company decided to contact CERT Intrinsec in order to get help to handle the security breach and manage the crisis. CERT...
This article shares a method & tool developped by Intrinsec to reconstruct attack path using Microsoft Protection logs. Enjoy reading & hunting ! During incident response, CERT Intrinsec performs investigation so as to find indicators of compromise and...
Dans le cadre du salon de cybersécurité de LeHack 2022, Intrinsec a proposé un ensemble d’épreuves afin de divertir et challenger les visiteurs du salon. Ce CTF conçu par notre consultant Thibaud ROBIN est constitué de 12 épreuves. Il évolue dans un contexte réaliste...
Chaque année, l’école ESGI organise le Security Day, une journée durant laquelle les étudiants de la filière Sécurité Informatique et des professionnels de la sécurité ont la possibilité d’assister à des conférences animées par des consultants IT. Ce mardi...
Introduction Since a couple of years, ransomware attacks are one of organizations’ biggest threats. Indeed, those attacks can dramatically disturb operations by stopping production, order intake or orders shipments for days. Starting from isolated and capable...
Selon une étude de Allianz Global Corporate & Specialty réalisée en 2022, 57% des professionnels interrogés (dont des directeurs généraux et des gestionnaires de risques) considèrent que les risques en matière de cyber sécurité (menace d’attaques de ransomware,...
Context Numerous clashes have continued in the country over the past week, with Ukrainian armed forces resisting, while the Russian army officially seized the cities of Melitopol and Kherson, before announcing the expansion of its offensive against Ukraine despite a...
Surge in ransomware attacks 2722 That’s the total number of ransomware attacks claimed in 2021, corresponding to 7 claims per day Targeted geographyWhen looking at the victimology of ransomware operators, one significant fact stands out: the geographical distribution...
ALPHV (or BlackCat or Noberus) ransomware emerged only last December and is already considered as a genuine threat that blue teams should be ready to fight against while little is known on the employed entry vector(s). This conjecture relies not only on the high level...