My recent ransomware reports are all depressingly similar. PLEASE look to the security/patch level of edge firewall/VPN devices, send their logs to an external host for long-term storage, and make sure you have network-layer logs that show attempts to compromise these devices.

Jul 29, 2021 · 7:21 PM UTC

1
28
4
115
Replying to @hal_pomeranz
Send them to @MeetHumio we ❤️logs and integrate with @SOC_Prime
2