Ressourcen/SentinelOne Vs. BlackCat Ransomware – Kill and Quarantine
Dezember 29, 2021
SentinelOne Vs. BlackCat Ransomware – Kill and Quarantine
⚔️ See how SentinelOne kills and quarantines BlackCat Ransomware. BlackCat (aka AlphaVM, AlphaV) is a newly established RaaS (Ransomware as a Service) with payloads written in Rust. Current data indicates primary delivery of BlackCat is via 3rd party framework/toolset (aka Cobalt Strike) or via exposed (and vulnerable) applications.
BlackCat currently supports both Windows and Linux operating systems. Samples analyzed (to date ) require an “access token” to be supplied as a parameter upon execution. This is similar to threats like Egregor, and is often used as an anti-analysis tactic. In addition, BlackCat (on Windows) will attempt to Delete VSS (Volume Shadow Copies), as well as enumerate local/accessible drives to affect eligible files. Extensions on encrypted files can vary across samples. Infected users are instructed to connect to the attackers’ payment/support portal (via TOR).
#blackcat #cybersecurity #RaaS #ransomware #endpointsecurity #endpointprotection #XDR
SentinelOne Vs. BlackCat Ransomware – Kill and Quarantine
Weiterführende Ressourcen
Resource
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
View Asset
Resource
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
View Asset
Resource
LABScon24 Replay | A Walking Red Flag (With Yellow Stars) | Cary & Benincasa
China's cybersecurity competition ecosystem has grown significantly since 2017, with over 150 unique events and more than 400 total competitions.…
View Asset
Resource
LABScon24 Replay | Kryptina RaaS: From Unsellable Cast-off to Enterprise Ransomware | Jim Walter
Kryptina RaaS, originally a free giveaway, has evolved into a tool for large ransomware groups targeting Linux and cloud environments.…
View Asset
Erleben Sie die weltweit fortschrittlichste Cybersecurity Plattform in Aktion
Erfahren Sie, wie unsere intelligente, autonome Cybersecurity Plattform Ihr Unternehmen heute und morgen schützt.