
Mark Parsons
Mark Parsons is a threat hunter for Sophos Managed Detection and Response. He specializes in threat hunting, digital forensics, and incident response. Previous notable achievements include identifying multi-month nation state intrusions; working with multiple states’ cybersecurity programs before, during, and after the 2020 election cycle to improve their detection and response capabilities; finding rarely seen (second reporter) bugs in Microsoft Azure/CAP logs; and identifying multiple initial access brokers prior to their targets’ being compromised by second actors.
コンテンツ提供 Mark Parsons

Threat Research
.lnk
DLL サイドローディング
特集
GOLD BLADE
RedLoader
Sophos X-Ops
webdav
サイバー犯罪
脅威の調査
犯罪集団「GOLD BLADE」、リモート DLL サイドローディング攻撃で RedLoader を展開
July 29, 2025

Security Operations
Threat Research
Black Basta
特集
Fin7
Java マルウェア
Microsoft Office 365
Python マルウェア
Quick Assist
STAC5143
stac5777
Teams
セキュリティ運用
リモートマシンの管理
正規サービスの悪用
脅威リサーチ
Sophos MDR、「メール爆弾」と「ビッシング」を使用した 2 つのランサムウェアキャンペーンを追跡
January 21, 2025

Security Operations
Threat Research
CloudFlare
特集
FlowerStorm
legitimate service abuse
PaaS (サービスとしてのフィッシング)
Phishing
phishing-as-a-service
Rockstar
Rockstar2FA
Sophos MDR
セキュリティの運用
フィッシング
正規サービスの悪用
脅威の調査
フィッシングプラットフォーム「Rockstar 2FA」が停止し、「FlowerStorm」が台頭
December 19, 2024

Security Operations
human-led threat hunting
Microsoft SQL Server
Mimic ランサムウェア
Sophos X-Ops
セキュリティオペレーション
人間主導の脅威ハンティング
Sophos MDR、インドの組織に対する Mimic ランサムウェア攻撃を追跡
August 7, 2024

Threat Research
BackdoorDiplomacy
china
EAGERBEE
Earth Longzhi
特集
RUDEBIRD
Sophos X-Ops
state actors
TA428
threat research
threat-hunting
Worok
中国
国家的攻撃グループ
脅威ハンティング
脅威リサーチ
クリムゾンパレス作戦 (Operation Crimson Palace):脅威ハンティングによって明らかになった、東南アジア政府を標的とする中国による国家支援型攻撃
June 5, 2024