Insights · Tag

#India

3 posts tagged India.

Adversary emulation 27 May 2026

Inside a 90-day red team op against a tier-1 Indian airport operator

A redacted case study mapping a 13-week journey from an external foothold to full Active Directory compromise. Discover how the operator adapted tactics on the fly and what forensic artifacts survived a rigorous CERT-In post-incident review.

By Cyberange Adaptive Red Team

DFIR 14 May 2024

Anatomy of a ransomware breach: from one exposed RDP port to domain-wide encryption in 72 hours

A sanitized DFIR debrief of a ransomware intrusion at a large Indian manufacturer. We reconstruct the timeline from a misconfigured firewall rule and a brute-forced RDP login through Mimikatz, AV removal, PsExec lateral movement, and full-estate encryption — and the anti-forensics that nearly erased the trail.

By Cyberange DFIR Team

DFIR 26 May 2026

The CERT-In six-hour window: what your DFIR runbook needs to say

CERT-In Direction 70B (April 2022) requires reporting of certain cyber incidents within six hours of detection. A practical breakdown of what the clock actually measures, what your runbook needs to include, and where most organisations get the timeline wrong.

By Cyberange DFIR Consulting