Category: incident response

Providing Solutions

Rapid Response: The Ngrok Incident Guide

Ngrok is a legitimate remote-access tool. It is regularly abused by attackers, who use its capabilities and reputation to maneuver while bypassing network protections. This incident guide shows Security Operations Centers (SOCs) and response teams how to detect and respond to the suspicious presence or use of ngrok on the network.

Secrets of a security analyst: Investigating an incident

Tips to help you investigate incidents from experienced security analysts.

Secrets of a security analyst: Starting a threat hunt

Learn the basics of starting a threat hunt with tips and tricks from experienced security analysts.

Hindsight #7: Prepare for the worst

This article is  part of a series that aims to educate cyber security professionals on the lessons learned by breach victims. Each lesson will include simple recommendations, many of which do not require organizations to purchase any tools.