TI Mindmap HUB
Threat Intelligence Report

They Got In Through SonicWall. Then They Tried to Kill Every Security Tool

๐Ÿ“… February 5, 2026 ๐Ÿ“ฐ www.huntress.com ๐Ÿ” 0 CVE(s) referenced

Threat actors exploited SonicWall SSLVPN credentials to breach a network and deploy a sophisticated EDR killer using a legitimate but revoked forensic driver, illustrating how attackers are increasingly abusing trusted signed drivers to disable security tools and pave the way for ransomware.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle