Skip to main content

ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Solutionschevron right
  • Industrieschevron right
  • Platformchevron right
  • Resourceschevron right
  • Customerschevron right
  • Companychevron right
lock Icon

Anatomy of an Attack

post image

Cl0p Ransomware Group and the PTC Windchill Campaign

September 22, 2026

Explore how Cl0p targeted PTC Windchill with a custom web shell for data theft, and how ExtraHop RevealX detects C2 and exfiltration across encrypted sessions.

cover image for Detecting the Behavior of Medusa Ransomware Operations
Detecting the Behavior of Medusa Ransomware Operations

August 31, 2026

Medusa ransomware operators follow a predictable "exfiltrate first, encrypt second" pattern. Learn how security teams can detect these behavioral trails on the network even when endpoint defenses are impaired.

cover image for Iranian-Affiliated Actors Target U.S. Critical Infrastructure Through PLCs
Iranian-Affiliated Actors Target U.S. Critical Infrastructure Through PLCs

August 10, 2026

Explore the anatomy of Iranian-linked cyberattacks targeting U.S. critical infrastructure. Learn how to detect and stop unauthorized PLC manipulation using ExtraHop RevealX network detection and response.

cover image for VECT 2.0 Ransomware
VECT 2.0 Ransomware

July 21, 2026

VECT 2.0 is a data wiper, not ransomware. Discover how this destructive malware irreversibly deletes files and learn critical network-based strategies to defend against it.

cover image for UNC6692 and the SNOW Malware Ecosystem
UNC6692 and the SNOW Malware Ecosystem

July 7, 2026

UNC6692 uses Microsoft Teams and email-bombing to deploy the modular SNOW malware ecosystem, stealthily bypassing common defenses to compromise domain controllers and exfiltrate data.

cover image for VIPERTUNNEL
VIPERTUNNEL

June 30, 2026

Examine how VIPERTUNNEL uses Python execution, file-type masquerading, and SOCKS5 tunneling to support ransomware-linked intrusions, and how ExtraHop RevealX helps detect the activity.

cover image for Inside Interlock Ransomware Operations
Inside Interlock Ransomware Operations

June 16, 2026

Examine how the Interlock ransomware group leverages living off the land techniques and cloud exfiltration, and how ExtraHop RevealX detects the intrusion.

cover image for The DINDOOR Backdoor
The DINDOOR Backdoor

May 12, 2026

Iranian APT MuddyWater (Seedworm) is targeting organizations with a new, undocumented backdoor called DINDOOR. Discover how this campaign exploits the Deno runtime and Rclone for cloud exfiltration to bypass EDR, and learn how network detection and response (NDR) can help provide the visibility needed to stop these stealthy threats.

cover image for The Copy Fail: Linux Kernel Local Privilege Escalation
The Copy Fail: Linux Kernel Local Privilege Escalation

May 4, 2026

Uncover the "Copy Fail" logic flaw (CVE-2026-31431) that enables instant root access on nearly all major Linux distributions. Learn how this vulnerability bypasses file integrity monitoring and why network-based behavioral analysis is critical for securing containerized and cloud environments.

cover image for The MIMICRAT CLICKFIX Campaign
The MIMICRAT CLICKFIX Campaign

April 28, 2026

Expose how the MIMICRAT campaign weaponizes compromised financial sites and ClickFix lures to deploy fileless malware. See how ExtraHop RevealX provides the network-level ground truth to detect telemetry suppression and stealthy C2 patterns that bypass EDR.

Explore Topics

post image

Why Network Detections Need an Identity Layer

October 1, 2026

Integrating real-time identity logs into network telemetry allows agentic SOC platforms to automate threat triage, isolate blast radius, and resolve stolen-token attacks.

Agentic SOCIdentity
post image

Feeding the Monster: The New Cybersecurity Threat Hiding in Your Data Lakes

September 30, 2026

Discover how indirect prompt injection attacks weaponize enterprise data lakes to hijack autonomous AI agents, and why real-time network telemetry is critical to stopping machine-speed exploits.

Data Lakes Indirect Prompt Injection AI SecurityNetwork Detection and Response
post image

NVIDIA and ExtraHop Bring Independent Security to Autonomous Agents

September 29, 2026

NVIDIA introduced an open agent security framework on Monday, naming ExtraHop as a collaborator working to secure autonomous AI agents.

AI AgentsAI SecurityAI Governance
post image

The FBI Breach and the Search for a Starting Point

September 28, 2026

Investigators still can't confirm how the FBI's data breach began, exposing a common challenge in tracing attacks across both internal and vendor connection points.

FederalNetwork VisibilityData Breaches
post image

Machine-Speed Cyberattacks Demand Autonomous Remediation

September 24, 2026

AI now reads patches and builds exploits within minutes. Security operations need autonomous remediation that isolates endpoints and kills sessions the instant behavior crosses a threshold.

Autonomous RemediationAgentic SOCThreat DetectionAI-Driven Threats
post image

Anatomy of an Attack

Cl0p Ransomware Group and the PTC Windchill Campaign

September 22, 2026

Explore how Cl0p targeted PTC Windchill with a custom web shell for data theft, and how ExtraHop RevealX detects C2 and exfiltration across encrypted sessions.

Threat DetectionNetwork Detection and ResponseRevealXAnatomy of an Attack

Experience RevealX NDR for Yourself

Schedule a demo