INSIGHTS & ANALYSIS
Cybersecurity Investigations,
Digital Forensics & Response.
Analysis and practical guidance from Cyber Centaurs on digital forensics, incident response, cyber investigations, threat activity, security testing, and the technical issues that shape consequential decisions.

LATEST ARTICLE
Detecting ClickFix Malvertising in Enterprise Environments
Detection strategies and threat-hunting guidance for identifying ClickFix malvertising activity, including PowerShell execution, persistence, credential access, certificate manipulation, and suspicious behaviors.
Read Article →LATEST INSIGHTS
Recent Analysis.
A denser index of recent Cyber Centaurs analysis, field notes, and practical guidance for security, legal, and executive teams.

Deconstructing the ClickFix Infection Chain Part 2 – Loader Obfuscation and Stealth Persistence
Part 2 of the ClickFix series deconstructs loader obfuscation, UAC bypass, DPAPI-protected payloads, scheduled-task persistence, and stealth activity.
Read Article →
Unmasking the ClickFix Malvertising Infection Chain part1
Part 1 of the ClickFix series examines the initial malvertising lure, user-driven Win+R execution, and why this social engineering technique continues to work.
Read Article →
When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read Article →
Infiltration into the INC Ransomware Group’s Infrastructure
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read Article →
RedNovember’s Tactics and Tradecraft
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read Article →
Threat Actors’ Obsession with Veeam Backups
Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…
Read Article →
Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read Article →
Guarding Against Midnight Blizzard’s New RDP Tactics
As cyber threat actors continually refine their techniques, state-sponsored groups are pushing boundaries to infiltrate even the most secure networks. Among these groups, Midnight Blizzard—also known as APT29 or Cozy…
Read Article →
The Truth About Deleted Data and Modern Technology
Modern SSDs, encryption, secure deletion, and mobile-device architecture have changed what forensic investigators can recover after data is deleted—and where alternative evidence may still exist.
Read Article →
Unmasking North Korean IT Infiltration
The evolution of remote work has created new avenues for business growth but also introduced significant cyber risks. As of 2024, around 22.8% of U.S. employees work remotely at least…
Read Article →
Mastering Metadata for Legal Professionals
In the legal world, where the smallest detail can tip the balance of a case, metadata serves as a hidden but powerful ally. Beyond the visible content of a document…
Read Article →
Defense Strategies for Living Off the Land (LOTL) Attacks
With the third article in our series on Living Off the Land (LOTL) attacks, we dive deeper into defense strategies that organizations can implement to safeguard their infrastructure from these…
Read Article →INCIDENT RESPONSE
Incident Response
Analysis and guidance on ransomware, business email compromise, cloud compromise, data breaches, response strategy, and cyber incident investigations.

Essential Metrics for Effective Incident Response Strategies
In today’s complex digital landscape, cybersecurity is a critical concern for corporate IT leaders, including Chief Information Security Officers (CISOs), Chief Information Officers (CIOs), and IT Directors. With the frequency…
Read →
Navigating Data Breach Disclosures
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
Understanding Cyber Threat Intelligence
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
The Resurgence of USB-based Cyberattacks
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →DIGITAL FORENSICS
Digital Forensics
Articles on computer and mobile forensics, digital evidence, forensic methodology, insider investigations, data movement, and investigative analysis.

The Truth About Deleted Data and Modern Technology
Modern SSDs, encryption, secure deletion, and mobile-device architecture have changed what forensic investigators can recover after data is deleted—and where alternative evidence may still exist.
Read →
Mastering Metadata for Legal Professionals
In the legal world, where the smallest detail can tip the balance of a case, metadata serves as a hidden but powerful ally. Beyond the visible content of a document…
Read →
Video Forensics in Criminal Defense
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
Legal Frameworks and Compliance – A Guide for Legal Practitioners
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →THREAT HUNTING
Threat Hunting
Research and practical guidance on suspicious activity, attacker behavior, detection logic, persistence, credential misuse, and proactive threat investigation.

Detecting ClickFix Malvertising in Enterprise Environments
Detection strategies and threat-hunting guidance for identifying ClickFix malvertising activity, including PowerShell execution, persistence, credential access, certificate manipulation, and suspicious behaviors.
Read →
Deconstructing the ClickFix Infection Chain Part 2 – Loader Obfuscation and Stealth Persistence
Part 2 of the ClickFix series deconstructs loader obfuscation, UAC bypass, DPAPI-protected payloads, scheduled-task persistence, and stealth activity.
Read →
Unmasking the ClickFix Malvertising Infection Chain part1
Part 1 of the ClickFix series examines the initial malvertising lure, user-driven Win+R execution, and why this social engineering technique continues to work.
Read →
Defense Strategies for Living Off the Land (LOTL) Attacks
With the third article in our series on Living Off the Land (LOTL) attacks, we dive deeper into defense strategies that organizations can implement to safeguard their infrastructure from these…
Read →PENETRATION TESTING
Penetration Testing
Technical guidance on penetration testing, attack paths, Active Directory, network security, offensive-security methodology, and remediation validation.

Supply Chain Attacks in Healthcare Are a Growing Cybersecurity Threat
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
BlackBasta Ransomware – Threat Analysis and Indicators of Compromise
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
Understanding Remote Access Trojans (RATs)
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
Using Penetration Testing to Stop a New Stealth Breed of Ransomware Attacks
Ransomware is arguably one of the most insidious and damaging forms of malware. Cybercriminals are continually exploiting newer methods to circumvent strategies by enterprises to thwart ransomware attacks. A recent…
Read →THREAT ACTOR ANALYSIS
Threat Actor Analysis
Research on threat groups, campaigns, tactics, techniques, procedures, malware, infrastructure, and observed adversary behavior.

When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
Infiltration into the INC Ransomware Group’s Infrastructure
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
RedNovember’s Tactics and Tradecraft
[vc_row type=”in_container” full_screen_row_position=”middle” column_margin=”default” column_direction=”default” column_direction_tablet=”default” column_direction_phone=”default” scene_position=”center” text_color=&
Read →
Threat Actors’ Obsession with Veeam Backups
Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…
Read →NEED ASSISTANCE?
Start With a
Confidential Conversation.
If an article relates to an active incident, forensic matter, or security concern affecting your organization, contact Cyber Centaurs to discuss the circumstances directly.
CONTACT CYBER CENTAURS →