Skip to main content

ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Solutionschevron right
  • Industrieschevron right
  • Platformchevron right
  • Resourceschevron right
  • Customerschevron right
  • Companychevron right

THREAT INSIGHTS

featured

2025 Global Threat Landscape Report

The threat landscape is evolving at an unprecedented pace. Timely intelligence regarding attack surfaces, threat actors, ransomware trends, and more empowers your enterprise to make faster, smarter security decisions.

Read the Report
lock Icon

Anatomy of an Attack

post image

TerminalFix: When a Workstation Becomes a Network Pivot

October 1, 2026

Learn how the TerminalFix ClickFix variant turns compromised workstations into network pivots via PowerShell, steganography, and reverse C2 tunnels, and how ExtraHop RevealX detects it.

cover image for Cl0p Ransomware Group and the PTC Windchill Campaign
Cl0p Ransomware Group and the PTC Windchill Campaign

September 22, 2026

Explore how Cl0p targeted PTC Windchill with a custom web shell for data theft, and how ExtraHop RevealX detects C2 and exfiltration across encrypted sessions.

cover image for Detecting the Behavior of Medusa Ransomware Operations
Detecting the Behavior of Medusa Ransomware Operations

August 31, 2026

Medusa ransomware operators follow a predictable "exfiltrate first, encrypt second" pattern. Learn how security teams can detect these behavioral trails on the network even when endpoint defenses are impaired.

cover image for Iranian-Affiliated Actors Target U.S. Critical Infrastructure Through PLCs
Iranian-Affiliated Actors Target U.S. Critical Infrastructure Through PLCs

August 10, 2026

Explore the anatomy of Iranian-linked cyberattacks targeting U.S. critical infrastructure. Learn how to detect and stop unauthorized PLC manipulation using ExtraHop RevealX network detection and response.

cover image for VECT 2.0 Ransomware
VECT 2.0 Ransomware

July 21, 2026

VECT 2.0 is a data wiper, not ransomware. Discover how this destructive malware irreversibly deletes files and learn critical network-based strategies to defend against it.

cover image for UNC6692 and the SNOW Malware Ecosystem
UNC6692 and the SNOW Malware Ecosystem

July 7, 2026

UNC6692 uses Microsoft Teams and email-bombing to deploy the modular SNOW malware ecosystem, stealthily bypassing common defenses to compromise domain controllers and exfiltrate data.

cover image for VIPERTUNNEL
VIPERTUNNEL

June 30, 2026

Examine how VIPERTUNNEL uses Python execution, file-type masquerading, and SOCKS5 tunneling to support ransomware-linked intrusions, and how ExtraHop RevealX helps detect the activity.

cover image for Inside Interlock Ransomware Operations
Inside Interlock Ransomware Operations

June 16, 2026

Examine how the Interlock ransomware group leverages living off the land techniques and cloud exfiltration, and how ExtraHop RevealX detects the intrusion.

cover image for The DINDOOR Backdoor
The DINDOOR Backdoor

May 12, 2026

Iranian APT MuddyWater (Seedworm) is targeting organizations with a new, undocumented backdoor called DINDOOR. Discover how this campaign exploits the Deno runtime and Rclone for cloud exfiltration to bypass EDR, and learn how network detection and response (NDR) can help provide the visibility needed to stop these stealthy threats.

cover image for The Copy Fail: Linux Kernel Local Privilege Escalation
The Copy Fail: Linux Kernel Local Privilege Escalation

May 4, 2026

Uncover the "Copy Fail" logic flaw (CVE-2026-31431) that enables instant root access on nearly all major Linux distributions. Learn how this vulnerability bypasses file integrity monitoring and why network-based behavioral analysis is critical for securing containerized and cloud environments.

Featured Resources

Video preview
play button

Calculating Your Security Blast Radius - From Potential to Actual Impact

Video preview
play button

Uncovering Hidden Threats: The Power of Network Data

Video preview
play button

Detect Ransomware with Network Detection and Response (NDR) - The Attack Kill Chain Explained