top of page
Work Overview
LATEST PROJECTS
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque

Blog
Search


Understanding the ToolShell Vulnerability in Microsoft SharePoint Servers
In the ever-evolving landscape of cybersecurity threats, Microsoft SharePoint servers have become a prime target for sophisticated exploits. As of July 2025, a zero-day vulnerability chain dubbed "ToolShell" is being actively exploited. This vulnerability allows unauthenticated remote code execution (RCE) on on-premises SharePoint installations. It poses significant risks to organizations relying on SharePoint for collaboration and data management. In this technical blog, we'
5 min read


Forensic Friday - Jump Lists
What are Jump Lists? Jump Lists are windows features introduced with Windows 7, and they contain information about recently accessed applications and files. They allow files and applications to be pinned to the taskbar. There are two forms of jump list that can be created in windows. The first form is called AUTOMATICDESTINATIONS-MS. Like its name, these jump lists are created automatically when the users open a file or an application. This jump list is located in the followi
2 min read


Remote Assistance Tools - T1219
Let's talk about remote assistance tools! As you would expect, a remote assistance tool is used to assist end-users from a remote location. These tools are great and are widely used by helpdesk and IT support staff to help users with various workstations issues. If allowed within the settings of the host computer, the remote user can also share control of the host computer, opening files, accessing information, and inputting data by mouse and keyboard. This is extremely helpf
2 min read


Microsoft Office - Arbitrary Code Execution
We have recently observed threat actors evolving their procedures in light of Microsoft disabling macros by default in office documents. This new technique would allow threat actors to continue to bypass security controls to infect one or more hosts in an environment. In light of the latest Microsoft Office vulnerabilities, we will likely see broad adoption of macro-less infected documents that will lead to many organizations getting hacked. While Microsoft has shared mitigat
3 min read


Forensic Friday - Profile Lists
What are Profile Lists? Windows keeps track of user-profiles and their locations in the registry. The profile location is stored under the key below: HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList This registry key contains one subkey for each user profile on a Windows machine. Inside of each of these subkeys is a registry value called ProfileImagePath that includes the profile path for all users. You can obtain information on user profiles such as profile las
3 min read


CVE-2022-1388 (F5 BIG-IP)
CVE-2022-1388 is a critical CVE (CVSS 9.8) in F5 Networks’ BIG-IP solution management interface. This CVE will allow threat actors to bypass F5’s iControl REST authentication to gain remote code execution. This is not the first significant vulnerability we have seen with the BIG-IP platform. In 2021, security practitioners worldwide observed attacks against the iControl REST API as well. This was tracked as CVE-2021-22986. The vulnerability is what security researchers call a
3 min read


Forensic Friday - Prefetch
What is Windows Prefetch? Windows Prefetch creates files when a user opens an application on a Windows host. The Windows Operating system will make a prefetch record when an application is run from a specific area for the absolute time. Microsoft introduced prefetch with the Windows XP operating system. The idea behind the prefetch is that it would accelerate the boot process and start-up process. In older versions of Windows, prefetch files were limited to 128 files. With ne
4 min read


Emotet Changing Techniques
Phishing attacks remain the number one technique used in cyberattacks. Some of the most common phishing attacks leveraged attachments to facilitate the initial infection chain. We disproportionally see Microsoft Office documents and PDF files used to embed the malicious code as far as the attachments themselves go. When we say Microsoft Office documents, we refer to files created by the Microsoft Office suite such as Microsoft Word, Excel, PowerPoint, etc. Historically we wou
3 min read


Cyberattacks On The Rise
As we look across the landscape, we see that cyberattacks continue to succeed in all business sectors. In the cases we have observed, the cyberattack leveraged weak security controls and, as a result, could have been prevented by organizations adopting security best practices. A new study shows that ransomware, phishing, social engineering, denial of service (DoS) attacks, and the business fallout of a data breach rank as the top concerns of global organizations. The recently
1 min read


What is Qbot / Qakbot
QBot, also known as Qakbot or pinkslipbot, is an information stealer that has been active since 2007. It is malware software that can monitor the browser's activities and lots of information on the victim's computer. It is also known as a banking trojan capable of stealing finance-related data from the infected device and loader by using c2 servers to target payload and downloads. Other important information that QBot can steal from a system are: Name of the account City Coun
3 min read


An Encounter with Pandora
Pandora ransomware came into the spotlight in March of 2022 after posting some high-profile victims on its leak site. The ransomware group announced its first victim on Feb 21st, 2022. Their biggest victim was Denso, a car parts manufacturer. After an attack on one of its offices in Germany, Denso confirmed that cybercriminals leaked stolen, classified information from the Japan-based car-components manufacturer. Pandora claims to have exfiltrated 1TB of data from Denso. So w
4 min read


What is Incident Response?
Incident response is a method for dealing with various forms of security events, cyber threats, and data breaches in an organized manner. The goal of the incident response approach is to identify, contain, eradicate, and reduce the cost of a cyberattack or live event. To be prepared for a future attack, a well-built incident response (IR) plan will be essential in limiting the potential business impacts of an incident. It is critical to address security breaches quickly and e
3 min read


Proxyshell Vulnerabilities
In Microsoft Exchange, the three known vulnerabilities that threat actors use to get initial access are often referred to collectively as Proxyshells. These three known vulnerabilities are CVE-2021-34473, CVE-2021-34523, and CVE-2021- 31207. The attackers use these three vulnerabilities by bypassing the authentication and running a remote code as a privileged user. Microsoft has classified the Proxyshell vulnerabilities as critical. However, the proxyshell vulnerability is re
4 min read


Incident Analysis
Despite the depth of implemented protection measures, cyber incidents are bound to happen at some time. An incident analysis process comprises carefully structured and orchestrated operations to determine the incident's root cause and prevent it from reoccurring in the future. Incident analysis is critical to responding and recovering from an adverse cyber event. The following are recommended incident analysis phases: Detection and observation IT security teams use various t
2 min read
bottom of page
