ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

Arrow pointing leftBlog

Michael Zuckerman

Product Marketing Team

Michael Zuckerman is a seasoned B2B product marketing and marketing strategy consultant. Zuckerman’s domain experience in cybersecurity over the past 10 years includes DNS security, threat intelligence, threat intelligence platforms (TIP), container security, mobile device security, moving target defense, sandbox, deception technology, cloud access security brokers (CASB), SASE, data loss prevention (DLP), user and entity behavior analytics (UEBA), Network detection and response (NDR), and encryption.

Posts by this author

Anatomy of an Attack

Inside Interlock Ransomware Operations

June 16, 2026

Examine how the Interlock ransomware group leverages living off the land techniques and cloud exfiltration, and how ExtraHop RevealX detects the intrusion.

Anatomy of an AttackRansomwareThreat IntelligenceNetwork Detection and ResponseAnatomy of an AttackLateral MovementCloud Security

Anatomy of an Attack

The DINDOOR Backdoor

May 12, 2026

Iranian APT MuddyWater (Seedworm) is targeting organizations with a new, undocumented backdoor called DINDOOR. Discover how this campaign exploits the Deno runtime and Rclone for cloud exfiltration to bypass EDR, and learn how network detection and response (NDR) can help provide the visibility needed to stop these stealthy threats.

RevealXNDRNetwork Detection and ResponseThreat HuntingNetwork SecurityAnatomy of an Attack

Anatomy of an Attack

The MIMICRAT CLICKFIX Campaign

April 28, 2026

Expose how the MIMICRAT campaign weaponizes compromised financial sites and ClickFix lures to deploy fileless malware. See how ExtraHop RevealX provides the network-level ground truth to detect telemetry suppression and stealthy C2 patterns that bypass EDR.

Anatomy of an AttackNetwork DetectionNDRRevealXThreat Hunting

Anatomy of an Attack

The Chrysalis Backdoor and the Notepad++ Supply Chain Hijack

April 6, 2026

Unmask the Chrysalis backdoor and the sophisticated Notepad++ supply chain hijack orchestrated by Lotus Blossom. Learn how these state-sponsored attackers bypass traditional defenses and why network-level visibility is the ultimate key to stopping them.

Anatomy of an Attack

Anatomy of an Attack:

CHAOS in a BLACKSUIT—Triple Extortion Ransomware

March 11, 2026

Discover how the Chaos threat group utilizes triple extortion to pressure victims. See how ExtraHop RevealX provides the decryption and network visibility required to expose these stealthy attackers before data is leaked.

Anatomy of an AttackNDRThreat DetectionRevealXLateral MovementRansomware

Anatomy of an Attack

From the Wire to the Data Center: Unmasking UNC5221 and the BRICKSTORM Backdoor

February 20, 2026

Discover how UNC5221 exploits vCenter and ADFS. See how ExtraHop RevealX decrypts authentication protocols to expose the threat actors.

Anatomy of an AttackNetwork Security

Anatomy of the Attack

DarkSpectre

February 4, 2026

Defend your supply chain against DarkSpectre’s evolving browser-based threats. This deep dive covers operational pillars like "The Zoom Stealer," MITRE ATT&CK TTPs, and actionable remediation strategies using allow-lists and network-centric security.

Network SecurityAnatomy of an Attack

Anatomy of an Attack

Anatomy of an Attack: European Cyber Threat Landscape: December 2025

January 14, 2026

Explore how specialized cyber operations in December 2025 weaponized BitLocker and used traffic mimicry to target critical infrastructure in Romania, France, and the UK. Learn how ExtraHop RevealX detects these "Living off the Land" tactics and supply chain breaches.

Anatomy of an Attack

Anatomy of an Attack:

SHADOW-VOID-042 Campaign Uses Deceptive Update Lures in Targeted Global Espionage

January 8, 2026

Stop the SHADOW-VOID-042 espionage campaign. See how this Void Rabisu-linked threat uses deceptive lures and zero-days. Learn how ExtraHop decodes 90+ protocols @ 100 Gbps to catch it.

Network SecurityAnatomy of an AttackDetections

Defeating Akira Ransomware: Full CISA Advisory Breakdown with ExtraHop NDR and MITRE ATT&CK

December 8, 2025

ExtraHop’s guide to the CISA AA24-109A advisory on the Akira ransomware group. See full MITRE ATT&CK TTPs, how Akira targets critical infrastructure, and how ExtraHop NDR defeats evasion and detects attacks in real-time, even within encrypted traffic.

Anatomy of an AttackRansomwareSecurity

Anatomy of an Attack

Anthropic AI Attack: How NDR Detects GTG-1002 Cyber Espionage

November 24, 2025

The GTG-1002 Campaign: Anthropic Reveals the First AI-Orchestrated Cyber Espionage Attack

SecurityThreat DetectionAnatomy of an Attack

Anatomy of the Attack

Healthcare Ransomware Defense: How NDR Stops Attacks Like Tufts & Eurofins

November 13, 2025

Deconstruct the Tufts Medicine & Eurofins ransomware attacks. Learn how NDR detects the advanced TTPs and lateral movement that perimeter security misses.

HealthcareRansomwareAnatomy of an Attack

Flax Typhoon's ArcGIS Backdoor: Why EDR Failed and How NDR Finds the Webshell

October 30, 2025

Anatomy of an Attack: Flax Typhoon’s ArcGIS Backdoor & NDR Detection

Threat HuntingCybersecurityZero TrustAnatomy of an Attack

Experience RevealX NDR for Yourself

Schedule a demo