

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Tracking a Chinese Influence Campaign, DRAGONBRIDGE
Mandiant uncovers DRAGONBRIDGE, a Chinese influence campaign targeting the US with false narratives to create division and discredit democracy. Despite poor execution and minimal engagement, the campaign spreads misinformation, including blaming the US for the Nord Stream explosions and dissuading voters in the midterm elections.
Threat Actor Stores Malware Commands in IIS Logs
Symantec researchers reveal the Cranefly hacking group’s use of IIS logs to hide malware commands. Using Trojan.Geppei, the group disguises commands as web requests, initiating activities like installing backdoors, executing OS commands, and disabling IIS logging for long-term intelligence collection.
CISA's #StopRansomware Reports on Daixin Team
CISA's #StopRansomware advisory spotlights the Daixin Team, a cybercrime group targeting the healthcare sector. Using phishing, stolen credentials, and public-facing applications, the group encrypts healthcare servers and exfiltrates sensitive data for ransom.
Cuba Ransomware Critical Networks in Ukraine
CERT-UA warns of Cuba ransomware targeting critical networks in Ukraine, using phishing emails to distribute ROMCOM RAT. The attacks, tracked by BlackBerry and linked to Tropical Scorpius, target critical infrastructure, military, food & beverage, and manufacturing sectors.
The Rapid Growth of Raspberry Robin Malware
Microsoft's Security Threat Intelligence team reveals the rapid growth of Raspberry Robin malware, which is now used to deploy Cl0p ransomware and popular malware loaders. Affecting thousands of devices, Raspberry Robin utilizes USB infections, malicious ads, and phishing for initial access, and employs LOLBins for execution.
Analysis of a LV Ransomware Attack Against a Jordan-based Company
Trend Micro analyzes an LV ransomware attack on a Jordan-based company, revealing the attackers exploited ProxyLogon and ProxyShell vulnerabilities, used PowerShell scripts, and employed RDP for data exfiltration. The attack targeted multiple industries including manufacturing, technology, and financial services.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)