Skip to main content

ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Solutionschevron right
  • Industrieschevron right
  • Platformchevron right
  • Resourceschevron right
  • Customerschevron right
  • Companychevron right

Arrow pointing leftBlog

Angela Wilson

Senior Cyber Threat Intelligence Analyst

Angela Wilson is a Senior Cyber Threat Intelligence Analyst with over a decade of experience in the cybersecurity industry. She focuses on transforming complex threat data into strategic intelligence that enhances organizational resilience and informs proactive defense.

Posts by this author

Anatomy of an Attack:

TerminalFix: When a Workstation Becomes a Network Pivot

October 1, 2026

Learn how the TerminalFix ClickFix variant turns compromised workstations into network pivots via PowerShell, steganography, and reverse C2 tunnels, and how ExtraHop RevealX detects it.

Anatomy of an AttackThreat DetectionNDRNetwork Detection and ResponseIncident ResponseActive Directory AttacksCommand and ControlMalware

Anatomy of an Attack

Cl0p Ransomware Group and the PTC Windchill Campaign

September 22, 2026

Explore how Cl0p targeted PTC Windchill with a custom web shell for data theft, and how ExtraHop RevealX detects C2 and exfiltration across encrypted sessions.

Threat DetectionNetwork Detection and ResponseRevealXAnatomy of an Attack

Threading the Needle: Detecting AD CS Abuse Through Decryption

September 15, 2026

Discover how network decryption reveals hidden Active Directory Certificate Services (AD CS) attacks, empowering security teams to identify malicious activity within encrypted traffic.

Network Detection and ResponseNDRThreat IntelligenceSecurity OperationsCloud Security

Anatomy of an Attack

Detecting the Behavior of Medusa Ransomware Operations

August 31, 2026

Medusa ransomware operators follow a predictable "exfiltrate first, encrypt second" pattern. Learn how security teams can detect these behavioral trails on the network even when endpoint defenses are impaired.

Threat IntelligenceRevealXNetwork Detection and ResponseNetwork SecurityLateral MovementThreat HuntingNetwork Detection and ResponseAnatomy of an Attack

Threading the Needle: Detecting AD CS Abuse Through Decryption

August 14, 2026

Discover how network decryption reveals hidden Active Directory Certificate Services (AD CS) attacks, empowering security teams to identify malicious activity within encrypted traffic.

Network Detection and ResponseNDRThreat IntelligenceSecurity OperationsCloud Security

Anatomy of an Attack

Iranian-Affiliated Actors Target U.S. Critical Infrastructure Through PLCs

August 10, 2026

Explore the anatomy of Iranian-linked cyberattacks targeting U.S. critical infrastructure. Learn how to detect and stop unauthorized PLC manipulation using ExtraHop RevealX network detection and response.

Anatomy of an AttackCyberAv3ngersNetwork Detection and Response

Anatomy of an Attack:

VECT 2.0 Ransomware

July 21, 2026

VECT 2.0 is a data wiper, not ransomware. Discover how this destructive malware irreversibly deletes files and learn critical network-based strategies to defend against it.

CybersecurityAnatomy of an AttackMalwareRansomwareThreat IntelligenceLateral MovementMITRE ATT&CKNetwork Detection and ResponseNDRRevealX

Anatomy of an Attack

UNC6692 and the SNOW Malware Ecosystem

July 7, 2026

UNC6692 uses Microsoft Teams and email-bombing to deploy the modular SNOW malware ecosystem, stealthily bypassing common defenses to compromise domain controllers and exfiltrate data.

Anatomy of an AttackMalwareThreat IntelligenceNetwork Detection and ResponseLateral MovementCloud SecurityMITRE ATT&CKUNC6692SNOW MalwareSocial Engineering

Anatomy of an Attack

The Copy Fail: Linux Kernel Local Privilege Escalation

May 4, 2026

Uncover the "Copy Fail" logic flaw (CVE-2026-31431) that enables instant root access on nearly all major Linux distributions. Learn how this vulnerability bypasses file integrity monitoring and why network-based behavioral analysis is critical for securing containerized and cloud environments.

Cloud SecurityCybersecurityNetwork Detection and ResponseNDRThreat IntelligenceAnatomy of an Attack

The 84% Blind Spot: Why Attackers Love Your 'Trusted' Admin Tools

April 28, 2026

The m odern enterprise security perimeter has morphed into a complex fabric of identity-centric access and administrative protocols. The most significant risk …

Network Detection and ResponseNetwork VisibilityThreat Hunting

The Digital Front of Iranian Cyber Offensive Response

March 9, 2026

Analyze how Iranian threat actors like APT42 and MuddyWater are integrating Generative AI and memory-safe languages into their 2026 cyber offensive. This guide examines the "triple-threat" model of espionage and destructive hacktivism, detailing how ExtraHop RevealX uses protocol fluency and decryption to detect sophisticated backdoors like TAMECAT and CHAR.

NDRSecurity ThreatsRevealX

Exploiting the OpenClaw Agentic Loop

February 16, 2026

Analyze the security risks of the OpenClaw agentic framework and the CVE-2026-25253 "1-click" RCE vulnerability. Discover how autonomous AI assistants create a 24/7 attack surface for credential theft and how network detection and response (NDR) identifies these emerging agentic threats in real time.

AIIdentityMalwareDetections

Experience RevealX NDR for Yourself

Schedule a demo