Day 2️⃣ of #100DaysofYARA: Detecting #ExMatter with the help of PE module
🔗 https://github.com/colincowie/100DaysOfYara_2023/blob/main/January/002/002.md
What does a targeted attack look like? This one begins with #BlackCat finding a weak link to infiltrate the network, pivoting using #LOLBins then using #ExMatter for data exfiltration. #Ransomware https://www.netskope.com/blog/blackcat-ransomware-tactics-and-techniques-from-a-targeted-attack
#blackcat #lolbins #ExMatter #ransomware