<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Incident Response on Martin&#39;s Blog</title>
		<link>https://mac.sploit.dk/tags/incident-response/</link>
		<description>Recent content in Incident Response on Martin&#39;s Blog</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Wed, 09 Sep 2026 08:30:00 +0200</lastBuildDate>
		
			<atom:link href="https://mac.sploit.dk/tags/incident-response/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Pronico TTP Overlap: Standard Playbook or Uncommon Composition?</title>
				<link>https://mac.sploit.dk/blog/pronico-ttp-overlap-standard-playbook/</link>
				<pubDate>Wed, 09 Sep 2026 08:30:00 +0200</pubDate>
				<guid>https://mac.sploit.dk/blog/pronico-ttp-overlap-standard-playbook/</guid>
				<description>&lt;p&gt;The &lt;a href=&#34;https://mac.sploit.dk/blog/guacamaya-pronico-ttps/&#34;&gt;main analysis of Guacamaya&amp;rsquo;s 2021–22 Pronico intrusion&lt;/a&gt; maps 67 Enterprise ATT&amp;amp;CK techniques from the operators&amp;rsquo; own screen recording. This follow-up asks a narrower question: how much of that behavior was standard enterprise intrusion procedure, and which combinations were less common?&lt;/p&gt;&#xA;&lt;p&gt;Two earlier bodies of material make useful comparisons: Phineas Fisher&amp;rsquo;s 2017 &lt;a href=&#34;https://packetstormsecurity.com/files/142321/HackBack-A-DIY-Guide.html&#34;&gt;&lt;em&gt;Hack Back — A DIY Guide&lt;/em&gt;&lt;/a&gt;, about the Hacking Team intrusion, and the &lt;a href=&#34;https://github.com/ForbiddenProgrammer/conti-pentester-guide-leak&#34;&gt;pentesting manuals archived as material supplied to Conti affiliates&lt;/a&gt;. The comparison here is about procedures, not actor identity.&lt;/p&gt;</description>
			</item>
			<item>
				<title>When the Intruders Publish Their Screen Recording: Guacamaya&#39;s Pronico TTPs</title>
				<link>https://mac.sploit.dk/blog/guacamaya-pronico-ttps/</link>
				<pubDate>Tue, 08 Sep 2026 20:00:00 +0200</pubDate>
				<guid>https://mac.sploit.dk/blog/guacamaya-pronico-ttps/</guid>
				<description>&lt;p&gt;We do not often get to see how an intrusion was actually worked.&lt;/p&gt;&#xA;&lt;p&gt;Most public reports begin after the fact. They give us a timeline assembled from logs, a list of malware, and perhaps a clean attack-flow diagram. What disappears is the operator: the wrong commands, improvised workarounds, changes of plan, concern about being detected, and the response when defenders begin closing doors.&lt;/p&gt;&#xA;&lt;p&gt;This case is different. On 6 March 2022, Guacamaya published a 2 hour 23 minute screen recording of its intrusion into Compañía Guatemalteca de Níquel (CGN) and Compañía Procesadora de Níquel de Izabal (Pronico), the mining and processing companies then behind Guatemala&amp;rsquo;s Fenix nickel project. The visible timeline begins on 7 April 2021 and reaches February 2022, although Guacamaya describes the active operation as lasting six months.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
