#edr — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #edr, aggregated by home.social.
-
The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
Indicators extracted from public reporting. Source: https://www.sophos.com/en-gb/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation
Pulse ID: 6a99442e4ccc39298527e2be
Pulse Link: https://otx.alienvault.com/pulse/6a99442e4ccc39298527e2be
Pulse Author: CyberHunter_NL
Created: 2026-09-03 09:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Sophos #bot #CyberHunter_NL
-
The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
Indicators extracted from public reporting. Source: https://www.sophos.com/en-gb/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation
Pulse ID: 6a99442e4ccc39298527e2be
Pulse Link: https://otx.alienvault.com/pulse/6a99442e4ccc39298527e2be
Pulse Author: CyberHunter_NL
Created: 2026-09-03 09:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Sophos #bot #CyberHunter_NL
-
The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
Indicators extracted from public reporting. Source: https://www.sophos.com/en-gb/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation
Pulse ID: 6a99442e4ccc39298527e2be
Pulse Link: https://otx.alienvault.com/pulse/6a99442e4ccc39298527e2be
Pulse Author: CyberHunter_NL
Created: 2026-09-03 09:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Sophos #bot #CyberHunter_NL
-
The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
Indicators extracted from public reporting. Source: https://www.sophos.com/en-gb/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation
Pulse ID: 6a99442e4ccc39298527e2be
Pulse Link: https://otx.alienvault.com/pulse/6a99442e4ccc39298527e2be
Pulse Author: CyberHunter_NL
Created: 2026-09-03 09:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Sophos #bot #CyberHunter_NL
-
The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
Indicators extracted from public reporting. Source: https://www.sophos.com/en-gb/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation
Pulse ID: 6a99442e4ccc39298527e2be
Pulse Link: https://otx.alienvault.com/pulse/6a99442e4ccc39298527e2be
Pulse Author: CyberHunter_NL
Created: 2026-09-03 09:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Sophos #bot #CyberHunter_NL
-
Inside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research
Analysis of server infrastructure revealed a complete TukTuk C2 framework (version 2.0) with cross-platform capabilities, including Windows and Linux agents, backend infrastructure, and management panel. The server contained eb.sys matching GentleKiller, along with comprehensive EDR neutralization training materials organized in four progressive lessons covering BYOVD techniques, vulnerable driver hunting, and kernel-level research. DLL sideloading configurations targeting Greenshot, ProcMon, Slack, and Postman were identified. Exfiltrated data included 224 Jira tickets from a global technology company containing information related to U.S. defense organizations and defense contractors, plus credentials from a global healthcare company's Infrastructure-as-Code platform exposing AWS keys, production databases, Azure AD, and Bitbucket access.
Pulse ID: 6a9869cb21bbf3f757424b7f
Pulse Link: https://otx.alienvault.com/pulse/6a9869cb21bbf3f757424b7f
Pulse Author: AlienVault
Created: 2026-09-02 18:24:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #EDR #Healthcare #InfoSec #Linux #OTX #OpenThreatExchange #RAT #SideLoading #UK #Windows #bot #AlienVault
-
A researcher claims a CrowdStrike Falcon vulnerability enabling privilege escalation and published a PoC. CrowdStrike has not confirmed it; no CVE exists.
#CrowdStrike #FalconFlank #0day #PrivilegeEscalation #PoC #EDR #InfoSec #Unverified