RSS
Security Operations
Threat Research
active adversary
Active Adversary Report
Compromised Credentials
detection
dwell time
Featured
impact
incident response
LOLBIN
MFA
Monitoring
RDP
Remote Ransomware
root cause
It takes two: The 2025 Sophos Active Adversary Report
April 2, 2025
featured
IR
LoLBINs
MDR
The Bite from Inside: The Sophos Active Adversary Report
December 12, 2024
Sophos X-Ops
RD Web Access abuse: Fighting back
June 12, 2024
Case Study
It’s Oh So Quiet (?): The Sophos Active Adversary Report for 1H 2024
April 3, 2024
Incident response tools
Remote Desktop Protocol: The Series
March 20, 2024
practitioners
tools
The song remains the same: The 2023 Active Adversary Report for Security Practitioners
November 14, 2023
Active Directory
attribution
MTR
Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders
August 23, 2023
CoinMiner
Conti
data breach
exfiltration
extortion
loader
Lockbit
Ransomware
Web shells
Everything Everywhere All At Once: The 2023 Active Adversary Report for Business Leaders
April 25, 2023
act
anti-EDR
AuKill
backstab
EDR
EDR killer
malware
Process Explorer
procexp
targeted attacks
‘AuKill’ EDR killer malware abuses Process Explorer driver
April 19, 2023