Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.Β
How does water holing attack work?
- Β The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
π‘ Free Threat Hunting Playbooks CISOs Love to Reuse π‘
Proactive threat hunting is key for detecting attacks before they escalate, but building playbooks from scratch is time-consuming. Luckily, several free resources provide tested playbooks CISOs can adapt immediately.
Here are the top free threat hunting playbooks:
1οΈβ£ MITRE ATT&CK Playbooks β Prebuilt hunting workflows mapped to TTPs.
π https://attack.mitre.org/resources/
2οΈβ£ SANS Institute Hunt Playbooks β Free guides for Windows, Linux, and cloud environments.
π https://www.sans.org/white-papers/
3οΈβ£ Elastic Security Labs Playbooks β Open-source examples for SIEM-based hunting.
π https://www.elastic.co/security-labs
4οΈβ£ Microsoft Security Response Center (MSRC) Playbooks β Step-by-step threat investigation templates.
π https://www.microsoft.com/en-us/msrc
5οΈβ£ SOC Prime Threat Hunting Library β Free community-contributed queries and use cases.
π https://socprime.com/community
6οΈβ£ Red Canary Threat Detection Playbooks β Guides for endpoint and network threat hunting.
π https://redcanary.com/resources/
7οΈβ£ Aumint.io Sample Playbooks β Our curated templates for simulating social engineering and insider attack scenarios.
π https://aumint.io/resources
β‘ Using these free playbooks, CISOs can standardize threat hunts, reduce response time, and increase detection confidence.
At AUMINT.io, we complement technical hunting with real-world simulations targeting human vulnerabilities, ensuring your SOC detects both technical and behavioral threats.
π Ready to see how your SOC handles advanced threats and employee-targeted attacks? Book a free demo
#ThreatHunting #CISO #CyberSecurity #SOC #AUMINT