ยท 2 days agoยท SANS Internet Storm
Analyzing Akira Ransomware Kill Chain Using Perimeter and Endpoint Logs
Most Akira write-ups focus on the ransom note or the encryption routine. By the time those show up the interesting forensic work is over. The questions that matter to defenders sit earlier. How did they get in. When did they get domain admin. What did they touch before the binary fired. Those answer
#ransomware#cybersecurity#forensics#malware-analysis