Threat hunts for Ivanti
5 hunts covering Ivanti, each with a hypothesis, the queries that test it and what the hunt cannot see.
5 hunts
-
critical Part 3 of 3Research by The DFIR Report
Akira Ransomware Exfiltration and Impact
An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by The DFIR Report
Bumblebee Persistence and AD Credential Harvesting
An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by The DFIR Report
Bumblebee Delivery and C2 Establishment
An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 2Research by Sekoia
ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration
An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-64446 -
high Part 1 of 2Research by The DFIR Report
Bumblebee Delivery and Persistence
An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · exfiltration