As cited
Copy frozen at (site build).
threat intel
Velociraptor Misuse, Pt. II: The Eye of the Storm
Huntress has identified an increase in threat actors misusing Velociraptor, an open-source digital forensics and incident response tool, in attacks that exploit WSUS (Windows Server Update Services) and VS Code tunnels. The trend suggests adversaries are leveraging legitimate security tools to evade detection during post-compromise activities.
Why it matters: Security teams and defenders need to monitor for Velociraptor abuse in their environments, especially in conjunction with WSUS and development tool exploitation, as this represents a shift in attacker tradecraft toward living-off-the-land techniques.
- Source published
- First seen by Cybersecurity Tracker