Recent DFIR reporting detailed how investigators can reconstruct attacker activity from Windows and Unix artifacts while avoiding common misreads of legitimate security tooling. Securelist published deep analyses of UserAssist and AmCache, showing how shell32.dll updates GUI execution records, how session statistics and undocumented bytes can reveal usage patterns, and why AmCache can identify executables, drivers, shortcuts, and installed applications even after deletion, despite limits such as SHA-1 hashing only the first 31,457,280 bytes of large files. Separate research showed that Zsh session files can preserve command evidence even when .zsh_history is deleted, and that binaries wrapped with shc or AutoIT often remain recoverable or observable through runtime artifacts rather than being truly opaque.
Incident write-ups and field notes also showed how attackers and defenders alike can complicate investigations. Analysts documented a typosquatted npm package, peritter, that dropped OneDrive.exe into Startup and stole Chrome credentials; an intrusion in which phishing, Slack installation, RDP access, and Google Drive traffic were tied to document staging and exfiltration; and broader cases in Brazilian educational institutions involving ransomware, valid-account abuse, AnyDesk, PsExec, and insider-planted malware. Other reports warned that legitimate tools and platform features can masquerade as threats or hide them: NSSM was used to run payloads such as ngrok as Windows services, Azure Batch was abused for cryptomining, RMM cleanup scripts attempted to conceal remote access software, and Microsoft Defender for Endpoint activity including device discovery and Defender XDR deception accounts generated telemetry that could be mistaken for attacker reconnaissance or privileged account misuse unless investigators validated the underlying configuration and scripts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
In a controlled Windows 10 lab, Hayabusa analysis of Security.evtx identified Sliver implant activity along with attacker commands including whoami /all and net.exe user creation for persistence. The article also reports Windows Defender detected the delivered implant GASTRIC_EPOXY.exe as Trojan:Win32/Gracing.I during the simulation.
Analysis showed the package's obfuscated index.js copied dataset.db into the user's Startup folder as OneDrive.exe for persistence and execution. MFT and Prefetch artifacts placed the malicious execution shortly after installation.
MFT analysis indicated the peritter package was downloaded or installed on the system. Package metadata identified the author as s1rx-dev, and analysis later showed the package contained an obfuscated index.js and a malicious payload in dataset.db.
Chrome history showed the user visited the npmjs.com page for the package peritter, a likely typosquat of prettier. This browsing event preceded installation of the malicious package on the compromised host.
The analyzed incident-response dataset covered attacks against Brazilian educational institutions from January 2025 through June 2026. It included ransomware, suspicious endpoint activity, privilege escalation, and insider threats, with DragonForce and LockBit 3 appearing prominently.
Windows Defender MPLog entries recorded four Project Venus-related documents being placed in Jane's Downloads folder during the attacker-linked RDP session. The files were Energy Storage.txt, Research.txt, Solar Panel Tech.txt, and Wind Turbine Design.txt, indicating staging or exfiltration activity.
Magnet AXIOM RDP artifacts showed an incoming RDP connection from 104.203.174.169 to Jane Andrada's workstation. The write-up tied this session to the attacker activity that followed the phishing compromise.
Jane Andrada received and opened a malicious email masquerading as IT Support, as shown by Chrome web history and Chrome Web Visits artifacts. This phishing event preceded the attacker-controlled remote access and suspected data theft.
Artifacts showed Slack was installed on Jane Andrada's machine despite the organization primarily using Microsoft Teams. The installation became part of the reconstructed intrusion timeline tied to later attacker activity.
An example .session file in Zsh contained a restored-session timestamp corresponding to Thu May 16 2024 09:47:05 UTC. The article highlighted this as useful forensic evidence for narrowing when commands were executed, even if .zsh_history is deleted.
Decoded Microsoft Defender for Endpoint Device discovery parameters included an ExpirationDateTime of 2024-04-19T01:26:02.1473403Z for the scan job. The investigation concluded the observed port-scan-like behavior was legitimate Defender discovery rather than attacker reconnaissance.
Metadata from the analyzed Docker image showed the ubtssl/webappx image used in the Azure Batch cryptomining setup was created on 2024-01-03T06:31:11.0826861Z. The image later ran a Python HTTP server and the xm cryptocurrency miner with configured pool and wallet parameters.
One of the Brazilian educational-institution case studies involved an insider planting a Python keylogger on a system that used shared accounts. The article presented this as part of the broader pattern of insider threats observed in the dataset.
Another case in the Brazilian education-sector dataset involved attackers using a compromised user account to install AnyDesk and deploy DragonForce ransomware. Investigators identified the DragonForce sample through Prefetch and Amcache.hve artifacts and matched the SHA-1 of 1.EXE to a DragonForce variant.
In one case from the Brazilian education-sector dataset, attackers used a leaked valid account to deploy a custom LockBit variant, disabled defenses with a batch script, enabled RDP, and used PsExec for lateral movement. Internal systems including file servers and databases storing student profiles were encrypted, and investigators found no evidence of data exfiltration.
A PowerShell cleaner script downloaded from an open directory was found to hide AteraAgent and Splashtop Streamer by setting uninstall entries' SystemComponent value, deleting Start Menu folders, and renaming a Splashtop firewall rule to resemble a benign Windows rule. Testing confirmed it removed Splashtop from Apps & features while leaving other forensic artifacts behind.
A SANS ISC diary explained how the Atuin shell history tool stores command history in a SQLite database and identified key forensic artifacts including history.db, WAL/SHM files, encryption keys, session tokens, and configuration files. The write-up also noted soft-deleted records, sync-related cross-host history, and logging gaps investigators must account for.
An attacker who had obtained access to an Azure administrator account created a new resource group and the Azure Batch account websecv1, then sought a quota increase so compute pools could be launched for mining activity. The attacker later created a Linux Ubuntu pool that used a Start Task to download and run a script that installed Docker and launched the ubtssl/webappx container running the xm miner.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcexakep.ru
Open sourceisc.sans.edu
Open sourcetrojan-killer.net
Open sourcedfir.ch
Open sourcedfir.ch
Open sourcedfir.ch
Open sourcedfir.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.