Recursos/SentinelOne VS Play Ransomware – Prevention
diciembre 7, 2022
SentinelOne VS Play Ransomware – Prevention
Play Ransomware is a new type of malware seen starting in June 2022. The name “play” comes from the extension added to files once they have become encrypted by this ransomware family (i e., .play). This group usually initializes its activities with attack vectorization through vulnerabilities discovered in either FortiOS or other devices. Once inside a targeted environment, the group attempts to mask their activity and remain stealthy. For example, they rely heavily on the use of LOLBins. The group also uses commodity tools such as Anydesk, Netscan, and Advanced IP Scanner. The payloads are often spread through AD environments via GPO.
Play ransomware is one of several ransomware families using “intermittent encryption.” This is a method of partially encrypting specifically-sized chunks of data within files. This can assist in the evasion of ‘legacy’ malware detection systems.
Singularity Complete ofrece capacidades líderes en el mercado de protección de cargas de trabajo en la nube y endpoints impulsadas…
Leer ahora
Resource
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
View Asset
Resource
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
View Asset
Resource
LABScon24 Replay | A Walking Red Flag (With Yellow Stars) | Cary & Benincasa
China's cybersecurity competition ecosystem has grown significantly since 2017, with over 150 unique events and more than 400 total competitions.…
View Asset
Disfrute de la plataforma de ciberseguridad más avanzada del mundo
Descubra cómo nuestra plataforma de ciberseguridad inteligente y autónoma protege a su empresa, ahora y en el futuro.