DFIR Labs - Subscription Plans
π¨ New: DFIR Labs Pro Tier is here!
π― Smarter investigations with:
β’ π§ AI Timeline Builder (w/ IOCs + notes)
β’ β±οΈ More lab time + extension credits
β’ π Analytics dashboard w/ tailored insights
π Dive in: dfirlabs.thedfirreport.com/subscription...
23.07.2025 13:13 β π 3 π 1 π¬ 0 π 1
KongTuke FileFix Leads to New Interlock RAT Variant
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware groupβs remote access trojan (RAT). This new malware,β¦
π¨ New Interlock RAT variant spotted!
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware groupβs remote access trojan (RAT).
π thedfirreport.com/2025/07/14/k...
#DFIR #KongTuke #InterlockRAT #FileFix
14.07.2025 11:36 β π 2 π 1 π¬ 0 π 1
DFIR Labs - Digital Forensics Challenge - Enterprise Edition
π’DFIR Labs Enterprise Forensics Challengeπ’
πΉ When: Aug 30, 2025 (14:00-18:00 UTC)
πΉ SIEM: Azure Log Analytics, Elastic, or Splunk
πΉ Teams: 2-3 analysts
πΉ Prizes: Top team wins! π
Limited spots available.
Register Now: dfirlabs.thedfirreport.com/dfirchalleng...
25.06.2025 12:27 β π 2 π 1 π¬ 0 π 0
A New DFIR Lab is out: The Hive Ransomware Fail π
A domain is under siege, can you trace the threat actor's steps? Sharpen your triage and lateral movement skills in this hands-on investigation.
β‘οΈDifficulty: Easy
1/2
27.06.2025 14:37 β π 4 π 1 π¬ 1 π 0
Microsoft Forms
π We're Hiring: Senior Security Analyst
We're looking for a full-time Senior Security Analyst with a passion for dissecting intrusions and translating technical findings into actionable insights.
Check out the full job description and apply here π forms.office.com/r/87y8wAp3gA
26.06.2025 12:28 β π 1 π 2 π¬ 0 π 0
DFIR Labs - Digital Forensics Challenge - Enterprise Edition
π’DFIR Labs Enterprise Forensics Challengeπ’
πΉ When: Aug 30, 2025 (14:00-18:00 UTC)
πΉ SIEM: Azure Log Analytics, Elastic, or Splunk
πΉ Teams: 2-3 analysts
πΉ Prizes: Top team wins! π
Limited spots available.
Register Now: dfirlabs.thedfirreport.com/dfirchalleng...
25.06.2025 12:27 β π 2 π 1 π¬ 0 π 0
DFIR Labs - Subscription Plans
We built these plans to make high-quality DFIR training accessible to everyone.
Ready to dive in? Check out all the details and sign up today! π
π dfirlabs.thedfirreport.com/subscription...
5/5
23.06.2025 14:22 β π 0 π 0 π¬ 0 π 0
For Teams:
Need to level up your whole crew? Our Enterprise plans are packed with features like bulk tokens, detailed usage reporting, 7-day lab access, and priority support. Everything your team needs to sharpen their skills together!
4/5
23.06.2025 14:22 β π 0 π 0 π¬ 1 π 0
You'll get 1 token monthly, 2-day lab access, quiz retries, and rollover β all designed for continuous growth, not just one-time learning.
3/5
23.06.2025 14:22 β π 0 π 0 π¬ 1 π 0
For Individuals:
Ready to get hands-on with real-world intrusion labs? Our Individual plan is just $14.99/month for a limited time during launch week! Lock in this amazing discounted rate for as long as you're a member.
2/5
23.06.2025 14:22 β π 0 π 0 π¬ 1 π 0
π Huge News from DFIR Labs: Subscriptions are Here! π
We're thrilled to announce that subscriptions are officially LIVE and weβre proud of what this means for the DFIR community π
1/5
23.06.2025 14:22 β π 1 π 0 π¬ 1 π 1
DFIR Discussions: Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
Reports Β· Episode
πNew DFIR Discussions Episodeπ
πAvailable on Spotify, Apple, & YouTube!
ποΈ We dive into our latest public report with Randy Pargman, Jake Ouellette, Kostas T., and Mangatas Tondang. Check it out and let us know what you think!
open.spotify.com/episode/1SKP...
16.06.2025 12:48 β π 1 π 0 π¬ 0 π 1
βοΈRegistration for the DFIR Labs Enterprise CTF is now LIVE! βοΈ
Assemble your elite SOC/IR team (up to 3 members) for a 4-hour competition to prove you're the best in the industry.
Win prizes, bragging rights, and glory! π
Register now! πhttps://form.jotform.com/251605321344245
10.06.2025 18:37 β π 1 π 0 π¬ 0 π 0
ποΈ New Podcast Episode Dropping Soon!
We dive into our latest public report with Randy Pargman, Jake Ouellette, Kostas T., and Mangatas Tondang.
Stay tuned for deep insights, behind-the-scenes analysis, and expert commentary from the front lines of DFIR. π
10.06.2025 12:06 β π 2 π 1 π¬ 1 π 0
Huge thanks to everyone who participated, helped organize, and supported this event. We hope you had as much fun as we did β and we can't wait to see you at the next one!
And nowβ¦ the lab that powered the whole event is live and available π₯
08.06.2025 12:34 β π 0 π 0 π¬ 1 π 0
π¨ That CTF finale was wild. Only 300 points between 1st and 3rd β it stayed neck-and-neck till the very last minute.
Big congrats to our winners!
π₯ @Friffnz β 5100 pts
π₯ snail β 4840 pts
π₯ forynsics β 4800 pts
08.06.2025 12:34 β π 0 π 0 π¬ 1 π 0
π¨ CTF is starting soon!π¨
Don't Miss the DFIR Labs CTF - Registration Still Open!
β‘οΈWhen: Today, June 7th | 16:30β20:30 UTC
β‘οΈβ‘οΈRegister: dfirlabs.thedfirreport.com/ctf
07.06.2025 12:29 β π 0 π 0 π¬ 0 π 0
/1
π¨ πππ
π€π’ππ€π¬ π¨ππ π’π§ π₯ππ¬π¬ ππ‘ππ§ 48π‘ - ππ§π ππ‘π’π¬ π¨π§πβπ¬ ππ’π .
One of the most involved cases weβve ever made available to the public.
Youβll be diving into an intrusion that hit 18 hosts, including:
β‘οΈ Domain Controllers
β‘οΈ Backup Servers
β‘οΈ Hypervisors
β‘οΈ RDP Servers (Guess the initial access gonna be? π)
05.06.2025 17:07 β π 0 π 2 π¬ 1 π 0
Contact Us
PGP Key
β‘οΈ The above is from a recent Private Threat Brief: "Interlock-Linked Threat Actor Gains Access via Fake Teams ClickFix Lure"
β‘οΈβ‘οΈInterested in receiving reports like this one? Contact us for a demo or pricing - thedfirreport.com/contact/
3/3
05.06.2025 12:39 β π 0 π 0 π¬ 0 π 0
The malware in this case took 15 minutes to establish a successful connection to an online endpoint at hxxp://bristol-weed-martin-know[.]trycloudflare[.]com/init1234."
2/3
05.06.2025 12:39 β π 0 π 0 π¬ 1 π 0
"The remote endpoints it attempted to contact included several TryCloudflare domains as well as direct IP addresses.
The logic would rotate through the various servers until an online host was found.
1/3
#dfir #CyberSecurity #cyberthreatintelligence #cti #interlock #ransomware
05.06.2025 12:39 β π 0 π 0 π¬ 1 π 0
π― THIS SATURDAY: DFIR Labs CTF π―
β° June 7 | 1630β2030 UTC
π Register Now β dfirlabs.thedfirreport.com/ctf
π DFIR Labs CTF is back!
π₯ Only $9.99 to join
π₯ Choose Elastic or Splunk
π₯ Access a brand-new, unreleased case
π₯ Top 5 get invited to join The DFIR Report team!
04.06.2025 12:04 β π 0 π 1 π¬ 0 π 1
We had a blast speaking at the Ransomware Summit! π€π₯
Huge thanks to everyone involved!
π₯ Missed our keynote? No worries β you can catch the full session here:
π www.youtube.com/live/nhB-xkm...
02.06.2025 13:22 β π 2 π 0 π¬ 0 π 0
π₯ DFIR Labs is Evolving! Have You Seen What's New? π₯
Big things are happening at DFIR Labs! We've been hard at work implementing a wave of exciting changes and improvements, all designed to enhance your experience!
β‘οΈ Check it out now! dfirlabs.thedfirreport.com
22.05.2025 18:44 β π 3 π 2 π¬ 0 π 0
Interested in receiving private reports similar to this report? Contact us for pricing - thedfirreport.com/contact/
4/4
22.05.2025 12:52 β π 0 π 0 π¬ 0 π 0