

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
LastPass: New Details Emerge from Second Security Breach of 2022
LastPass disclosed a secondary breach in 2022, where attackers accessed AWS cloud storage from August to October. Data exfiltrated included partially encrypted password vaults and customer information. Attackers targeted a DevOps engineer to gain access. LastPass has since enhanced its security measures.
'Blind Eagle' Sets Sights on Latin American Organizations
Blind Eagle, a South American cyber espionage group, targets financial, government, and healthcare organizations in Colombia and Ecuador. Using phishing emails and RATs, they aim for information theft and espionage. Protect your organization from this emerging threat.
Evasive LockBit Campaign
The latest LockBit ransomware campaign, observed in December 2022 and January 2023, uses advanced evasion techniques to bypass AV and EDR solutions. Employing social engineering and sophisticated scripting, this campaign poses a serious threat to global industries.
Tax Season Brings News Tax-themed Phishing Campaigns
Tax-themed phishing campaigns are increasing during tax season, distributing GuLoader malware and remote access trojans like Remcos. Malicious attachments masquerade as tax-related documents to deceive victims. Stay vigilant and protect against these attacks.
#StopRansomware Headlines Royal Ransomware
The FBI and CISA report on Royal ransomware activities since September 2022. Targeting critical infrastructure, education, and healthcare sectors, Royal ransomware uses phishing, RDP, and valid accounts to gain access and execute double extortion tactics, encrypting and exfiltrating data.
Russian Influence Campaigns Losing Steam on Meta Platforms
Meta reports a decline in Russian influence campaigns on Facebook and Instagram. The shift from sophisticated tactics to spam-like behavior has resulted in lower engagement, as new security measures thwart nefarious accounts.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)