

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Hacked Sites Spreads Fake "Capitulation" News
On March 3rd, 2022, the Ukrainian State Service of Special Communication and Information Protection (SSSCIP) identified hacked government sites spreading fake news about Ukraine's surrender to Russia. The SSSCIP actively shares updates and warnings about these compromised sites on Twitter, emphasizing that the surrender claims are false.
Anonymous Attacks Russian Government Sites
On March 15th, 2022, the Anonymous group launched DDoS attacks taking down multiple Russian government sites, including FSB and the Stock Exchange. The attacks caused a seven-hour outage, with some sites remaining inaccessible.
DoubleZero Wiper
On March 22, 2022, Symantec reported on the DoubleZero wiper, written in .NET and designed to obfuscate code and zero out critical system files and registry keys. This latest addition joins other wipers like WhisperGate, HermeticWiper, IsaacWiper, and CaddyWiper.
Anonymous Hacker Group Potentially Hacks Nestlé
On March 22nd, 2022, Anonymous claimed to have hacked 10GB of data from Nestlé due to their continued operations in Russia. Nestlé denies the hack, stating the data was accidentally released in February. The company has since limited its offerings in Russia.
Okta Shares Investigation Update - 2022-03-24
Okta's investigation into the Lapsus$ breach reveals it originated from a Sitel support engineer's workstation accessed via RDP. The engineer's "SuperUser" privileges were limited to basic support duties. The breach, detected on January 20, 2022, was contained within an hour. Okta has provided a detailed incident timeline.
Okta Updates ~2.5% Customers Impacted From Breach
Okta's Chief Security Officer, David Bradbury, reports that 366 customers, roughly 2.5% of all Okta customers, were impacted by the January 2022 breach. The exposed data may have been viewed or acted upon. Customers were notified about potential security threats, including API token creation and suspicious sign-ins.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)