Skip to content
Stories
 2026-08-23 Weekly Threat Advisory: 50 Concurrent Ransomware Operators + 5 Dominant C2 Cluster + 11 APT Clusters (Aug 17-23, 2026)  2026-08-23 The TaHiTI Finalize Doctrine · Why 90% of Threat Hunting Programs Never Compound (and the 5-Deliverable Playbook That Fixes It)  2026-08-22 The AIaaS Doctrine · Attack Infrastructure as a Service · What 1.86 Million Cloud-Hosted IOCs Tell Every CISO  2026-08-17 Weekly Threat Advisory: Drive-By Doubles + Phishing-Framework Surge + DPRK APT Triple-Track (Aug 10-16, 2026)  2026-08-09 Weekly Threat Advisory: Drive-By Domain Surge + 9 Concurrent Ransomware Operators (Aug 3-9, 2026)  2026-08-06 The TaHiTI Investigation Abstract: Turning Threat Intelligence Into Targeted Hunts  2026-08-03 Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)  2026-07-30 Stop Searching, Start Hunting: A TaHiTI Hunt-Program Walkthrough Against This Week’s Threat Surface  2026-07-26 Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)  2026-07-19 Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)  2026-07-12 Weekly Threat Advisory: Beyond Ransomware — 11 RATs, 7 APTs, 1 WIPER, HASH Still Leads (Jul 6 – 12, 2026)  2026-07-05 Weekly Threat Advisory: 5 APTs, 200 RATs, 74% High-Severity — The Week the C2 Flood Went Quiet (Jun 29 – Jul 5, 2026)  2026-06-28 Weekly Threat Advisory: APT Surge, Ransomware Full-Pivot, Messaging Weaponised — June 22-28, 2026  2026-06-25 Indicators of Compromise and Threat Intelligence: A Practitioner Reference  2026-06-22 Weekly Threat Advisory: Cluster Analysis & Top IOCs, June 15 – 21, 2026  2026-06-19 The Complete AWS Threat Hunting Library: 27 Cloud Hunts, 7 Flagship Playbooks, and the Full Archive (2026)  2026-06-19 AWS Organizations Compromise: Hunting the Multi-Account Federation Attack  2026-06-19 Athena and S3 Data Lake Exfiltration: Hunting the SQL-Powered Data Heist  2026-06-19 EventBridge and SNS as Covert C2: Hunting Native AWS Messaging Abuse  2026-06-19 Hunting CI/CD Compromise in AWS: CodeBuild, CodePipeline, and the Buildspec Backdoor  2026-06-19 GuardDuty Evasion Hunt: 9 Techniques Adversaries Use to Stay Silent on AWS  2026-06-19 AWS KMS Ransomware Hunt: When Your Encryption Keys Become the Attacker’s Weapon  2026-06-19 CloudTrail Blind Spots: 12 Places AWS Doesn’t Log (And How to Hunt There Anyway)  2026-06-19 From SOC Analyst to Threat Hunter in 15 Months: The Complete 2026 Career Roadmap  2026-06-15 12 Must-Know AI Terms in 2026: The Complete Glossary for Builders, Defenders, and Learners  2026-06-15 Weekly Threat Advisory: Top Cyber Adversaries, June 8 – 14, 2026  2026-06-07 Weekly Threat Advisory: Top Cyber Adversaries, June 1 – 7, 2026  2026-06-06 The Threat Hunter’s Sigma Playbook: 7 Hunts Every Modern SOC Must Run  2026-06-03 A Practical Detection Engineering Framework Used by Modern SOCs  2026-06-03 What Cloud Logs You Actually Need for Threat Hunting (And Why Most Teams Fail)  2026-06-03 How to Measure Detection Quality: Metrics Every Detection Engineer Must Track  2026-06-01 Weekly Threat Advisory: Top Cyber Adversaries May 24 – 31, 2026  2026-05-25 Weekly Threat Advisory: Top Cyber Adversaries May 18 – 24, 2026  2026-05-18 Weekly Threat Advisory: Top Cyber Adversaries May 11 – 17, 2026  2026-05-16 Living-off-the-Cloud Attack-Chain Detection: CloudTrail and VPC Flow Fusion  2026-05-16 Insider Threat Detection from VPC Flow Logs (UEBA Without Endpoints)  2026-05-16 Kubernetes East-West Attack Hunting from VPC Flow Logs  2026-05-16 Tor and Anonymizer Egress Hunting on VPC Flow Logs  2026-05-16 Cloud Cryptojacking Detection at Scale: Mining-Pool Hunting on AWS  2026-05-16 TLS Fingerprinting (JA3, JA4, JARM) for Encrypted C2 Hunting  2026-05-16 DGA and DNS-Tunnel Hunting at Scale on VPC Flow Logs  2026-05-15 Lateral Movement Detection via Graph Analysis on VPC Flow Logs  2026-05-15 Detecting Low-and-Slow Data Exfiltration with Isolation Forest + LSTM  2026-05-15 Hunting Botnet Coordination and DDoS Staging with Clustering  2026-05-15 Living-off-the-Land Kill Chain Detection with Markov Chains  2026-05-13 Adaptive C2 Beacon Detection: FFT and DBSCAN on VPC Flow Logs  2026-05-11 Weekly Threat Advisory: Top Cyber Adversaries May 04 – 10, 2026  2026-05-09 AWS Bedrock Threat Hunting: A CloudTrail Log Analysis Playbook  2025-10-22 Weekly Threat Advisory: The Most Active Cyber Adversaries October 13 – October 19, 2025  2025-10-22 Weekly Threat Advisory: The Most Active Cyber Adversaries October 06 – October 12, 2025

Detect Diagnose Defeat Cyber Threat

Detect Diagnose Defeat Cyber Threat

  • Home
  • Threat Intelligence
    • Weekly Advisories
    • Adversary Profiles
    • MITRE Coverage
  • Threat Hunting
    • VPC Flow Log Hunting
    • Cloud Threat Hunting
    • Detection Engineering
  • Platform
    • Intelligence Overview
    • Platform Architecture
    • Threat Actors
    • C2 Operations
    • Knowledge Graph
  • Blog
    • Cyber Threat
    • Packet Forensics and Analytics
    • Threat Intelligence
    • Linux Forensics
    • General
    • Digital Forensics
    • Data Recovery
    • ProDiscover
×

Tag: Credential Theft via FTP

Malicious Processes Creating Network Traffic-
0 590
Posted in Cyber Threat Packet Forensics and Analytics

Hunting Strategies and Techniques of Malicious Processes Creating Network Traffic

Project Name: Hunting Strategies and Techniques of Malicious Processes Creating… read out Hunting Strategies and Techniques of Malicious Processes Creating Network Traffic

Rohit Sadgune 20th October 2024 0 Comment

Recent Posts

  • Weekly Threat Advisory: 50 Concurrent Ransomware Operators + 5 Dominant C2 Cluster + 11 APT Clusters (Aug 17-23, 2026)
  • The TaHiTI Finalize Doctrine · Why 90% of Threat Hunting Programs Never Compound (and the 5-Deliverable Playbook That Fixes It)
  • The AIaaS Doctrine · Attack Infrastructure as a Service · What 1.86 Million Cloud-Hosted IOCs Tell Every CISO
  • Weekly Threat Advisory: Drive-By Doubles + Phishing-Framework Surge + DPRK APT Triple-Track (Aug 10-16, 2026)
  • Weekly Threat Advisory: Drive-By Domain Surge + 9 Concurrent Ransomware Operators (Aug 3-9, 2026)
  • The TaHiTI Investigation Abstract: Turning Threat Intelligence Into Targeted Hunts
  • Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)
  • Stop Searching, Start Hunting: A TaHiTI Hunt-Program Walkthrough Against This Week’s Threat Surface
  • Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)
  • Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)

Hackforlab Category

SOCIAL HACKFORLAB

FaceBook Page

FaceBook Page

SIEM | UEBA




GridView List Posts Widget

HackForLab Weekly Threat Advisory · Aug 17-23 2026 · dark HUD cover · fifty concurrent ransomware operators across thirty-six TTPs · 3668 unique IOCs · 117 clusters · 1104 concentrated C2 IOCs · 11 APT clusters active this week · fragmentation-versus-concentration threat brief
4

Weekly Threat Advisory: 50 Concurrent Ransomware Operators + 5 Dominant C2 Cluster + 11 APT Clusters (Aug 17-23, 2026)

// WEEKLY THREAT ADVISORY · TLP:CLEAR · REF TA-2026-034 · AUG 17 → AUG 23 · 2026 Fifty Concurrent Ransomware...
The TaHiTI Finalize Doctrine · CISO-grade threat hunting playbook · 90% of programs skip Finalize · dark HUD cover · emerald + navy · three phase-chips Initialize Hunt Finalize with Finalize highlighted as compounding phase · pressure test 69584 named IOCs 50 ransomware ops 83 URL adversaries 36 ransomware TTPs
6

The TaHiTI Finalize Doctrine · Why 90% of Threat Hunting Programs Never Compound (and the 5-Deliverable Playbook That Fixes It)

// TaHiTI DOCTRINE · THE FINALIZE PHASE · TLP:CLEAR The TaHiTI Finalize Doctrine — Why 90% of Threat Hunting Programs...
AIaaS · Attack Infrastructure as a Service · CISO-grade threat manifesto · dark HUD cover · 44 threat actors deliberately share 1 cloud-hosted IP address · a market with 2,097 sellers · 480,897 units of inventory · zero compliance frameworks that cover it · 7 laws of AIaaS chips at bottom
6

The AIaaS Doctrine · Attack Infrastructure as a Service · What 1.86 Million Cloud-Hosted IOCs Tell Every CISO

// THE AIaaS DOCTRINE · A CISO-GRADE THREAT MANIFESTO · TLP:CLEAR Attack Infrastructure as a Service: The Market Your CISO...
HackForLab Weekly Threat Advisory · Aug 10-16 2026 · Dark HUD cover · 906 drive-by domains this week · 2.5x WoW surge · 3,269 IOCs · 118 clusters · 9+ APT clusters concurrent · dashboard-style aggressive threat brief
15

Weekly Threat Advisory: Drive-By Doubles + Phishing-Framework Surge + DPRK APT Triple-Track (Aug 10-16, 2026)

● CTI SITREP 026·33 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-033 · August 10 – 16, 2026 The...
Weekly Threat Advisory
41

Weekly Threat Advisory: Drive-By Domain Surge + 9 Concurrent Ransomware Operators (Aug 3-9, 2026)

● CTI SITREP 026·32 · INTEL BRIEFING · TLP:CLEAR · BRIEFING REF: TA-2026-032 · August 3 – 9, 2026 Drive-by...

Cyber Threat Attacks / Hunting

HACKFORALB successfully completed threat hunting for following attack…

DNS Reconnaissance, Domain Generation Algorithm (DGA), Robotic Pattern Detection, DNS Shadowing , Fast Flux DNS , Beaconing , Phishing , APT , Lateral Movement , Browser Compromised , DNS Amplification , DNS Tunneling , Skeleton key Malware , Advance Persistent Threats, Low and Slow attacks , DoS, Watering Hole Attack Detection, Weh Shell , DNS Water Torch Attack , Intrusion Detection, Cookie visibility and theft, User login Session hijacking, Broken Trust, Pass the Hash, Session fixation, Honey Token account suspicious activities, Data Snooping / Data aggregation, Cross Channel Data Egress, Banking fraud detection, Chopper Web shell

Cyber Deception




  • Facebook
  • LinkedIN
  • Twitter
  • Google+

FOLLOW US

  • Facebook
  • LinkedIN
  • Twitter
  • Google+

CYBER THREAT CATEGORIES

  • Cyber Threat (59)
  • Data Recovery (3)
  • Digital Forensics (16)
  • General (14)
  • Linux Server Investigation (1)
  • Linux Training (1)
  • Packet Forensics and Analytics (8)
  • ProDiscover (4)
  • Threat Intelligence (43)

Top Cyber Security Articles

  • Network Threat Hunting with Outbound Traffic
    Network Threat Hunting with Outbound Traffic
  • Network Vulnerability and Attacks by Layer
    Network Vulnerability and Attacks by Layer
  • How to use ProDiscover
    How to use ProDiscover
  • Digital Forensic Checklist
    Digital Forensic Checklist
  • Types of System Software
    Types of System Software

Threat Hunting Scenarios




Copyright HACKFORLAB

Design by ThemesDNA.com