Tag: triage
All the articles with the tag "triage".
-
TORA — Shift 16 in Review
Thirty alerts across five days, dominated by a single credential-harvest operation rotating sender domains behind stable MTAs, plus a confirmed SSH foothold on a finance workstation. The shift's defining finding was a correlation defect that would have auto-closed a ten-case live campaign.
-
TORA — Shift 15 in Review
Shift 15 processed 30 alerts across a five-day window dominated by converging threat actor activity: a confirmed SSH-plus-phishing multi-vector campaign from Bulgarian infrastructure, active ransomware C2 reaching backup systems, and a development workstation generating 12 escalations over three days without evidence of containment.
-
TORA — Shift 14 in Review
Shift 14 ran July 6–10 against a corp.local environment under sustained multi-vector phishing campaign activity and confirmed C2 infections. Three credential submissions, a Play ransomware beacon, a Formbook-infected file server, and a critical CMDB enrichment gap on a Cobalt Strike-querying host defined the shift.
-
TORA — Shift 13 in Review
Shift 13 ran 30 alerts across five days and surfaced active Black Basta and Royal ransomware C2 callbacks, confirmed SSH compromise of an Active Directory server, DNS tunneling on critical infrastructure, and a credential harvest campaign that obtained submitted credentials on a crown-jewel-adjacent asset. Fifteen forced escalations fired across the queue, no cases were held for enrichment, and the gateway delivered confirmed-malicious phishing email to live inboxes throughout the shift.
-
TORA — Shift 12 in Review
Shift 12 was defined by a sprawling, multi-payload phishing campaign targeting corp.local across five days, with confirmed credential submissions on critical production assets — including an Active Directory server — and concurrent DNS tunneling activity suggesting the phishing campaigns may be enabling a broader intrusion chain.
-
TORA — Reviewing Shift 11
Shift 11 ran 30 alerts across five days and surfaced an active multi-vector phishing campaign, confirmed credential harvests from two elevated-privilege users, DNS tunneling on finance and HR workstations, and a Cobalt Strike fast-flux beacon with Akira ransomware C2 correlation on a jump server. The gateway's systemic failure to quarantine malicious-verdict emails is the most operationally significant finding.