Talk With an Expert

When the Threat Group Doesn’t Leave: Incident Response Under Fire

When the Threat Group Doesn’t Leave: Incident Response Under Fire (PDF, 0.66MB)Last updated: 28 Sep, 2025
Presented by:
Eran Laloof
Eran Laloof

What happens when you face one of the most aggressive, capable, and determined threat group - while they’re still active in the network? This session presents a real-world cyber extortion case where investigators battled a live adversary within a complex environment. Attendees will explore the threat group’s TTPs, a detailed attack timeline, critical containment and forensic challenges, and key incident management dilemmas. Beyond a war story, this deep-dive provides actionable lessons for IR professionals, threat hunters, SOC analysts, and incident managers, offering guidance on avoiding costly mistakes when responding to live, ongoing attacks.

SANS DFIR Europe Prague 2025