ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Solutionschevron right
  • Industrieschevron right
  • Platformchevron right
  • Resourceschevron right
  • Customerschevron right
  • Companychevron right
lock Icon

Anatomy of an Attack

post image

Cl0p Ransomware Group and the PTC Windchill Campaign

September 22, 2026

Explore how Cl0p targeted PTC Windchill with a custom web shell for data theft, and how ExtraHop RevealX detects C2 and exfiltration across encrypted sessions.

cover image for Detecting the Behavior of Medusa Ransomware Operations
Detecting the Behavior of Medusa Ransomware Operations

August 31, 2026

Medusa ransomware operators follow a predictable "exfiltrate first, encrypt second" pattern. Learn how security teams can detect these behavioral trails on the network even when endpoint defenses are impaired.

cover image for Iranian-Affiliated Actors Target U.S. Critical Infrastructure Through PLCs
Iranian-Affiliated Actors Target U.S. Critical Infrastructure Through PLCs

August 10, 2026

Explore the anatomy of Iranian-linked cyberattacks targeting U.S. critical infrastructure. Learn how to detect and stop unauthorized PLC manipulation using ExtraHop RevealX network detection and response.

cover image for VECT 2.0 Ransomware
VECT 2.0 Ransomware

July 21, 2026

VECT 2.0 is a data wiper, not ransomware. Discover how this destructive malware irreversibly deletes files and learn critical network-based strategies to defend against it.

cover image for UNC6692 and the SNOW Malware Ecosystem
UNC6692 and the SNOW Malware Ecosystem

July 7, 2026

UNC6692 uses Microsoft Teams and email-bombing to deploy the modular SNOW malware ecosystem, stealthily bypassing common defenses to compromise domain controllers and exfiltrate data.

cover image for VIPERTUNNEL
VIPERTUNNEL

June 30, 2026

Examine how VIPERTUNNEL uses Python execution, file-type masquerading, and SOCKS5 tunneling to support ransomware-linked intrusions, and how ExtraHop RevealX helps detect the activity.

cover image for Inside Interlock Ransomware Operations
Inside Interlock Ransomware Operations

June 16, 2026

Examine how the Interlock ransomware group leverages living off the land techniques and cloud exfiltration, and how ExtraHop RevealX detects the intrusion.

cover image for The DINDOOR Backdoor
The DINDOOR Backdoor

May 12, 2026

Iranian APT MuddyWater (Seedworm) is targeting organizations with a new, undocumented backdoor called DINDOOR. Discover how this campaign exploits the Deno runtime and Rclone for cloud exfiltration to bypass EDR, and learn how network detection and response (NDR) can help provide the visibility needed to stop these stealthy threats.

cover image for The Copy Fail: Linux Kernel Local Privilege Escalation
The Copy Fail: Linux Kernel Local Privilege Escalation

May 4, 2026

Uncover the "Copy Fail" logic flaw (CVE-2026-31431) that enables instant root access on nearly all major Linux distributions. Learn how this vulnerability bypasses file integrity monitoring and why network-based behavioral analysis is critical for securing containerized and cloud environments.

cover image for The MIMICRAT CLICKFIX Campaign
The MIMICRAT CLICKFIX Campaign

April 28, 2026

Expose how the MIMICRAT campaign weaponizes compromised financial sites and ClickFix lures to deploy fileless malware. See how ExtraHop RevealX provides the network-level ground truth to detect telemetry suppression and stealthy C2 patterns that bypass EDR.

Explore Topics

post image

Anatomy of an Attack

Cl0p Ransomware Group and the PTC Windchill Campaign

September 22, 2026

Explore how Cl0p targeted PTC Windchill with a custom web shell for data theft, and how ExtraHop RevealX detects C2 and exfiltration across encrypted sessions.

Threat DetectionNetwork Detection and ResponseRevealXAnatomy of an Attack
post image

Would an AI Slowdown Buy Defenders Enough Time?

September 16, 2026

AI leaders are calling for a policy pause on frontier development, but the real risk to enterprises isn't on a policy timeline — it's machine-speed threats, internal and external, happening now.

Agentic AIMachine-speed DefenseAI GovernanceNDR
post image

How Open-Weight Models Are Reshaping the Cyber Threat Landscape

September 16, 2026

Threat actors are using self-hosted open-weight AI models to automate stealth campaigns. Learn why static logs fail to detect unmonitored AI and how open network context restores visibility.

AI SecurityOpen Weight Models
post image

Threading the Needle: Detecting AD CS Abuse Through Decryption

September 15, 2026

Discover how network decryption reveals hidden Active Directory Certificate Services (AD CS) attacks, empowering security teams to identify malicious activity within encrypted traffic.

Network Detection and ResponseNDRThreat IntelligenceSecurity OperationsCloud Security
post image

When AI Agents Go Rogue, the Network Is Your Last Line of Defense

September 15, 2026

AI agents sabotage each other when given conflicting goals, revoking credentials and killing processes. Network visibility closes the gap other security tools miss.

AI AgentsNDRAgentic SOCAgentic Security
post image

3 SOC Tasks AI Agents Are Taking Over and What Security Teams Can’t See

September 10, 2026

AI agents are absorbing SOC triage, detection, and containment. See why authorized behavior isn't verified behavior, and what closes the gap.

Agentic SOCAI AgentsThreat DetectionNetwork Visibility

Experience RevealX NDR for Yourself

Schedule a demo