The DFIR Report (@TheDFIRReport )

The DFIR Report

Bio real intrusions by real attackers, the truth behind the intrusion
Tweets 23
Followers 587
Following 18
Account created 03-04-2020 01:33:43
ID 1245886895458078722

Twitter Web App : Short write-up on a threat actor using AdFind for recon in the honeypot.

thedfirreport.com/2020/05/08/adf…

Maze, FIN6 and Trickbot have been seen using AdFind for recon.

Maze - fireeye.com/blog/threat-re…
FIN6 - fireeye.com/blog/threat-re…
Trickbot - cybereason.com/blog/dropping-…