Recursos/SentinelOne Vs. BlackCat Ransomware – Kill and Quarantine
diciembre 29, 2021
SentinelOne Vs. BlackCat Ransomware – Kill and Quarantine
⚔️ See how SentinelOne kills and quarantines BlackCat Ransomware. BlackCat (aka AlphaVM, AlphaV) is a newly established RaaS (Ransomware as a Service) with payloads written in Rust. Current data indicates primary delivery of BlackCat is via 3rd party framework/toolset (aka Cobalt Strike) or via exposed (and vulnerable) applications.
BlackCat currently supports both Windows and Linux operating systems. Samples analyzed (to date ) require an “access token” to be supplied as a parameter upon execution. This is similar to threats like Egregor, and is often used as an anti-analysis tactic. In addition, BlackCat (on Windows) will attempt to Delete VSS (Volume Shadow Copies), as well as enumerate local/accessible drives to affect eligible files. Extensions on encrypted files can vary across samples. Infected users are instructed to connect to the attackers’ payment/support portal (via TOR).
#blackcat #cybersecurity #RaaS #ransomware #endpointsecurity #endpointprotection #XDR
SentinelOne Vs. BlackCat Ransomware – Kill and Quarantine
Recursos relacionados
Resource
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
View Asset
Resource
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
View Asset
Resource
LABScon24 Replay | A Walking Red Flag (With Yellow Stars) | Cary & Benincasa
China's cybersecurity competition ecosystem has grown significantly since 2017, with over 150 unique events and more than 400 total competitions.…
View Asset
Resource
LABScon24 Replay | Kryptina RaaS: From Unsellable Cast-off to Enterprise Ransomware | Jim Walter
Kryptina RaaS, originally a free giveaway, has evolved into a tool for large ransomware groups targeting Linux and cloud environments.…
View Asset
Disfrute de la plataforma de ciberseguridad más avanzada del mundo
Descubra cómo nuestra plataforma de ciberseguridad inteligente y autónoma protege a su empresa, ahora y en el futuro.