PMAT: Ransomware.WannaHusky.exe.malz (and recovery!)
Ep. 4 - Road to PMRP (PJMR)
Feb 22, 20269 min read15

Search for a command to run...
Articles tagged with #dfir
Ep. 4 - Road to PMRP (PJMR)

Analysis of a stealthy and persistent LKM rootkit :3

Post-compromise analysis of a MacOS

An investigation into a memory dump which identified the presence of a rootkit dumped from process memory.

This incident is an emulation of APT29 following the CISA advisory regarding attacks exploiting JetBrains to target tech companies.

This Sherlock comprises a series of forensics challenges that involve analyzing memory dumps, disk images, logs, network traffic and malware on Window
