CINXE.COM
Cisco Talos Incident Response || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence
<!DOCTYPE html> <html> <head> <meta charset="utf-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <script type="text/javascript">window.NREUM||(NREUM={});NREUM.info={"beacon":"bam.nr-data.net","errorBeacon":"bam.nr-data.net","licenseKey":"NRJS-2cca8a1e043b4e8b396","applicationID":"590339741","transactionName":"cglWRxdZDg5dFEkIW1IPXFYLQj0QXRUWDltCAxdaC1IHGg==","queueTime":1,"applicationTime":793,"agent":""}</script> <script type="text/javascript">(window.NREUM||(NREUM={})).init={ajax:{deny_list:["bam.nr-data.net"]}};(window.NREUM||(NREUM={})).loader_config={licenseKey:"NRJS-2cca8a1e043b4e8b396",applicationID:"590339741"};;/*! For license information please see nr-loader-rum-1.281.0.min.js.LICENSE.txt */ (()=>{var e,t,r={122:(e,t,r)=>{"use strict";r.d(t,{a:()=>i});var n=r(944);function i(e,t){try{if(!e||"object"!=typeof e)return(0,n.R)(3);if(!t||"object"!=typeof t)return(0,n.R)(4);const r=Object.create(Object.getPrototypeOf(t),Object.getOwnPropertyDescriptors(t)),o=0===Object.keys(r).length?e:r;for(let a in o)if(void 0!==e[a])try{if(null===e[a]){r[a]=null;continue}Array.isArray(e[a])&&Array.isArray(t[a])?r[a]=Array.from(new Set([...e[a],...t[a]])):"object"==typeof e[a]&&"object"==typeof t[a]?r[a]=i(e[a],t[a]):r[a]=e[a]}catch(e){(0,n.R)(1,e)}return r}catch(e){(0,n.R)(2,e)}}},555:(e,t,r)=>{"use strict";r.d(t,{Vp:()=>c,fn:()=>s,x1:()=>u});var n=r(384),i=r(122);const o={beacon:n.NT.beacon,errorBeacon:n.NT.errorBeacon,licenseKey:void 0,applicationID:void 0,sa:void 0,queueTime:void 0,applicationTime:void 0,ttGuid:void 0,user:void 0,account:void 0,product:void 0,extra:void 0,jsAttributes:{},userAttributes:void 0,atts:void 0,transactionName:void 0,tNamePlain:void 0},a={};function s(e){try{const t=c(e);return!!t.licenseKey&&!!t.errorBeacon&&!!t.applicationID}catch(e){return!1}}function c(e){if(!e)throw new Error("All info objects require an agent identifier!");if(!a[e])throw new Error("Info for ".concat(e," was never set"));return a[e]}function u(e,t){if(!e)throw new Error("All info objects require an agent identifier!");a[e]=(0,i.a)(t,o);const r=(0,n.nY)(e);r&&(r.info=a[e])}},217:(e,t,r)=>{"use strict";r.d(t,{D0:()=>h,gD:()=>b,xN:()=>v});r(860).K7.genericEvents;const n="experimental.marks",i="experimental.measures",o="experimental.resources";var a=r(993);const s=e=>{if(!e||"string"!=typeof e)return!1;try{document.createDocumentFragment().querySelector(e)}catch{return!1}return!0};var c=r(614),u=r(944),l=r(384),d=r(122);const f="[data-nr-mask]",g=()=>{const e={feature_flags:[],experimental:{marks:!1,measures:!1,resources:!1},mask_selector:"*",block_selector:"[data-nr-block]",mask_input_options:{color:!1,date:!1,"datetime-local":!1,email:!1,month:!1,number:!1,range:!1,search:!1,tel:!1,text:!1,time:!1,url:!1,week:!1,textarea:!1,select:!1,password:!0}};return{ajax:{deny_list:void 0,block_internal:!0,enabled:!0,autoStart:!0},distributed_tracing:{enabled:void 0,exclude_newrelic_header:void 0,cors_use_newrelic_header:void 0,cors_use_tracecontext_headers:void 0,allowed_origins:void 0},get feature_flags(){return e.feature_flags},set feature_flags(t){e.feature_flags=t},generic_events:{enabled:!0,autoStart:!0},harvest:{interval:30},jserrors:{enabled:!0,autoStart:!0},logging:{enabled:!0,autoStart:!0,level:a.p_.INFO},metrics:{enabled:!0,autoStart:!0},obfuscate:void 0,page_action:{enabled:!0},page_view_event:{enabled:!0,autoStart:!0},page_view_timing:{enabled:!0,autoStart:!0},performance:{get capture_marks(){return e.feature_flags.includes(n)||e.experimental.marks},set capture_marks(t){e.experimental.marks=t},get capture_measures(){return e.feature_flags.includes(i)||e.experimental.measures},set capture_measures(t){e.experimental.measures=t},capture_detail:!0,resources:{get enabled(){return e.feature_flags.includes(o)||e.experimental.resources},set enabled(t){e.experimental.resources=t},asset_types:[],first_party_domains:[],ignore_newrelic:!0}},privacy:{cookies_enabled:!0},proxy:{assets:void 0,beacon:void 0},session:{expiresMs:c.wk,inactiveMs:c.BB},session_replay:{autoStart:!0,enabled:!1,preload:!1,sampling_rate:10,error_sampling_rate:100,collect_fonts:!1,inline_images:!1,fix_stylesheets:!0,mask_all_inputs:!0,get mask_text_selector(){return e.mask_selector},set mask_text_selector(t){s(t)?e.mask_selector="".concat(t,",").concat(f):""===t||null===t?e.mask_selector=f:(0,u.R)(5,t)},get block_class(){return"nr-block"},get ignore_class(){return"nr-ignore"},get mask_text_class(){return"nr-mask"},get block_selector(){return e.block_selector},set block_selector(t){s(t)?e.block_selector+=",".concat(t):""!==t&&(0,u.R)(6,t)},get mask_input_options(){return e.mask_input_options},set mask_input_options(t){t&&"object"==typeof t?e.mask_input_options={...t,password:!0}:(0,u.R)(7,t)}},session_trace:{enabled:!0,autoStart:!0},soft_navigations:{enabled:!0,autoStart:!0},spa:{enabled:!0,autoStart:!0},ssl:void 0,user_actions:{enabled:!0,elementAttributes:["id","className","tagName","type"]}}},p={},m="All configuration objects require an agent identifier!";function h(e){if(!e)throw new Error(m);if(!p[e])throw new Error("Configuration for ".concat(e," was never set"));return p[e]}function v(e,t){if(!e)throw new Error(m);p[e]=(0,d.a)(t,g());const r=(0,l.nY)(e);r&&(r.init=p[e])}function b(e,t){if(!e)throw new Error(m);var r=h(e);if(r){for(var n=t.split("."),i=0;i<n.length-1;i++)if("object"!=typeof(r=r[n[i]]))return;r=r[n[n.length-1]]}return r}},371:(e,t,r)=>{"use strict";r.d(t,{V:()=>f,f:()=>d});var n=r(122),i=r(384),o=r(154),a=r(324);let s=0;const c={buildEnv:a.F3,distMethod:a.Xs,version:a.xv,originTime:o.WN},u={customTransaction:void 0,disabled:!1,isolatedBacklog:!1,loaderType:void 0,maxBytes:3e4,onerror:void 0,ptid:void 0,releaseIds:{},appMetadata:{},session:void 0,denyList:void 0,timeKeeper:void 0,obfuscator:void 0,harvester:void 0},l={};function d(e){if(!e)throw new Error("All runtime objects require an agent identifier!");if(!l[e])throw new Error("Runtime for ".concat(e," was never set"));return l[e]}function f(e,t){if(!e)throw new Error("All runtime objects require an agent identifier!");l[e]={...(0,n.a)(t,u),...c},Object.hasOwnProperty.call(l[e],"harvestCount")||Object.defineProperty(l[e],"harvestCount",{get:()=>++s});const r=(0,i.nY)(e);r&&(r.runtime=l[e])}},324:(e,t,r)=>{"use strict";r.d(t,{F3:()=>i,Xs:()=>o,xv:()=>n});const n="1.281.0",i="PROD",o="CDN"},154:(e,t,r)=>{"use strict";r.d(t,{OF:()=>c,RI:()=>i,WN:()=>l,bv:()=>o,gm:()=>a,mw:()=>s,sb:()=>u});var n=r(863);const i="undefined"!=typeof window&&!!window.document,o="undefined"!=typeof WorkerGlobalScope&&("undefined"!=typeof self&&self instanceof WorkerGlobalScope&&self.navigator instanceof WorkerNavigator||"undefined"!=typeof globalThis&&globalThis instanceof WorkerGlobalScope&&globalThis.navigator instanceof WorkerNavigator),a=i?window:"undefined"!=typeof WorkerGlobalScope&&("undefined"!=typeof self&&self instanceof WorkerGlobalScope&&self||"undefined"!=typeof globalThis&&globalThis instanceof WorkerGlobalScope&&globalThis),s=Boolean("hidden"===a?.document?.visibilityState),c=/iPad|iPhone|iPod/.test(a.navigator?.userAgent),u=c&&"undefined"==typeof SharedWorker,l=((()=>{const e=a.navigator?.userAgent?.match(/Firefox[/\s](\d+\.\d+)/);Array.isArray(e)&&e.length>=2&&e[1]})(),Date.now()-(0,n.t)())},687:(e,t,r)=>{"use strict";r.d(t,{Ak:()=>c,Ze:()=>d,x3:()=>u});var n=r(836),i=r(606),o=r(860),a=r(646);const s={};function c(e,t){const r={staged:!1,priority:o.P3[t]||0};l(e),s[e].get(t)||s[e].set(t,r)}function u(e,t){e&&s[e]&&(s[e].get(t)&&s[e].delete(t),g(e,t,!1),s[e].size&&f(e))}function l(e){if(!e)throw new Error("agentIdentifier required");s[e]||(s[e]=new Map)}function d(e="",t="feature",r=!1){if(l(e),!e||!s[e].get(t)||r)return g(e,t);s[e].get(t).staged=!0,f(e)}function f(e){const t=Array.from(s[e]);t.every((([e,t])=>t.staged))&&(t.sort(((e,t)=>e[1].priority-t[1].priority)),t.forEach((([t])=>{s[e].delete(t),g(e,t)})))}function g(e,t,r=!0){const o=e?n.ee.get(e):n.ee,s=i.i.handlers;if(!o.aborted&&o.backlog&&s){if(r){const e=o.backlog[t],r=s[t];if(r){for(let t=0;e&&t<e.length;++t)p(e[t],r);Object.entries(r).forEach((([e,t])=>{Object.values(t||{}).forEach((t=>{t[0]?.on&&t[0]?.context()instanceof a.y&&t[0].on(e,t[1])}))}))}}o.isolatedBacklog||delete s[t],o.backlog[t]=null,o.emit("drain-"+t,[])}}function p(e,t){var r=e[1];Object.values(t[r]||{}).forEach((t=>{var r=e[0];if(t[0]===r){var n=t[1],i=e[3],o=e[2];n.apply(i,o)}}))}},836:(e,t,r)=>{"use strict";r.d(t,{P:()=>c,ee:()=>u});var n=r(384),i=r(990),o=r(371),a=r(646),s=r(607);const c="nr@context:".concat(s.W),u=function e(t,r){var n={},s={},l={},d=!1;try{d=16===r.length&&(0,o.f)(r).isolatedBacklog}catch(e){}var f={on:p,addEventListener:p,removeEventListener:function(e,t){var r=n[e];if(!r)return;for(var i=0;i<r.length;i++)r[i]===t&&r.splice(i,1)},emit:function(e,r,n,i,o){!1!==o&&(o=!0);if(u.aborted&&!i)return;t&&o&&t.emit(e,r,n);for(var a=g(n),c=m(e),l=c.length,d=0;d<l;d++)c[d].apply(a,r);var p=v()[s[e]];p&&p.push([f,e,r,a]);return a},get:h,listeners:m,context:g,buffer:function(e,t){const r=v();if(t=t||"feature",f.aborted)return;Object.entries(e||{}).forEach((([e,n])=>{s[n]=t,t in r||(r[t]=[])}))},abort:function(){f._aborted=!0,Object.keys(f.backlog).forEach((e=>{delete f.backlog[e]}))},isBuffering:function(e){return!!v()[s[e]]},debugId:r,backlog:d?{}:t&&"object"==typeof t.backlog?t.backlog:{},isolatedBacklog:d};return Object.defineProperty(f,"aborted",{get:()=>{let e=f._aborted||!1;return e||(t&&(e=t.aborted),e)}}),f;function g(e){return e&&e instanceof a.y?e:e?(0,i.I)(e,c,(()=>new a.y(c))):new a.y(c)}function p(e,t){n[e]=m(e).concat(t)}function m(e){return n[e]||[]}function h(t){return l[t]=l[t]||e(f,t)}function v(){return f.backlog}}(void 0,"globalEE"),l=(0,n.Zm)();l.ee||(l.ee=u)},646:(e,t,r)=>{"use strict";r.d(t,{y:()=>n});class n{constructor(e){this.contextId=e}}},908:(e,t,r)=>{"use strict";r.d(t,{d:()=>n,p:()=>i});var n=r(836).ee.get("handle");function i(e,t,r,i,o){o?(o.buffer([e],i),o.emit(e,t,r)):(n.buffer([e],i),n.emit(e,t,r))}},606:(e,t,r)=>{"use strict";r.d(t,{i:()=>o});var n=r(908);o.on=a;var i=o.handlers={};function o(e,t,r,o){a(o||n.d,i,e,t,r)}function a(e,t,r,i,o){o||(o="feature"),e||(e=n.d);var a=t[o]=t[o]||{};(a[r]=a[r]||[]).push([e,i])}},878:(e,t,r)=>{"use strict";function n(e,t){return{capture:e,passive:!1,signal:t}}function i(e,t,r=!1,i){window.addEventListener(e,t,n(r,i))}function o(e,t,r=!1,i){document.addEventListener(e,t,n(r,i))}r.d(t,{DD:()=>o,jT:()=>n,sp:()=>i})},607:(e,t,r)=>{"use strict";r.d(t,{W:()=>n});const n=(0,r(566).bz)()},566:(e,t,r)=>{"use strict";r.d(t,{LA:()=>s,bz:()=>a});var n=r(154);const i="xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx";function o(e,t){return e?15&e[t]:16*Math.random()|0}function a(){const e=n.gm?.crypto||n.gm?.msCrypto;let t,r=0;return e&&e.getRandomValues&&(t=e.getRandomValues(new Uint8Array(30))),i.split("").map((e=>"x"===e?o(t,r++).toString(16):"y"===e?(3&o()|8).toString(16):e)).join("")}function s(e){const t=n.gm?.crypto||n.gm?.msCrypto;let r,i=0;t&&t.getRandomValues&&(r=t.getRandomValues(new Uint8Array(e)));const a=[];for(var s=0;s<e;s++)a.push(o(r,i++).toString(16));return a.join("")}},614:(e,t,r)=>{"use strict";r.d(t,{BB:()=>a,H3:()=>n,g:()=>u,iL:()=>c,tS:()=>s,uh:()=>i,wk:()=>o});const n="NRBA",i="SESSION",o=144e5,a=18e5,s={STARTED:"session-started",PAUSE:"session-pause",RESET:"session-reset",RESUME:"session-resume",UPDATE:"session-update"},c={SAME_TAB:"same-tab",CROSS_TAB:"cross-tab"},u={OFF:0,FULL:1,ERROR:2}},863:(e,t,r)=>{"use strict";function n(){return Math.floor(performance.now())}r.d(t,{t:()=>n})},944:(e,t,r)=>{"use strict";function n(e,t){"function"==typeof console.debug&&console.debug("New Relic Warning: https://github.com/newrelic/newrelic-browser-agent/blob/main/docs/warning-codes.md#".concat(e),t)}r.d(t,{R:()=>n})},284:(e,t,r)=>{"use strict";r.d(t,{t:()=>c,B:()=>s});var n=r(836),i=r(154);const o="newrelic";const a=new Set,s={};function c(e,t){const r=n.ee.get(t);s[t]??={},e&&"object"==typeof e&&(a.has(t)||(r.emit("rumresp",[e]),s[t]=e,a.add(t),function(e={}){try{i.gm.dispatchEvent(new CustomEvent(o,{detail:e}))}catch(e){}}({loaded:!0})))}},990:(e,t,r)=>{"use strict";r.d(t,{I:()=>i});var n=Object.prototype.hasOwnProperty;function i(e,t,r){if(n.call(e,t))return e[t];var i=r();if(Object.defineProperty&&Object.keys)try{return Object.defineProperty(e,t,{value:i,writable:!0,enumerable:!1}),i}catch(e){}return e[t]=i,i}},389:(e,t,r)=>{"use strict";function n(e,t=500,r={}){const n=r?.leading||!1;let i;return(...r)=>{n&&void 0===i&&(e.apply(this,r),i=setTimeout((()=>{i=clearTimeout(i)}),t)),n||(clearTimeout(i),i=setTimeout((()=>{e.apply(this,r)}),t))}}function i(e){let t=!1;return(...r)=>{t||(t=!0,e.apply(this,r))}}r.d(t,{J:()=>i,s:()=>n})},289:(e,t,r)=>{"use strict";r.d(t,{GG:()=>o,sB:()=>a});var n=r(878);function i(){return"undefined"==typeof document||"complete"===document.readyState}function o(e,t){if(i())return e();(0,n.sp)("load",e,t)}function a(e){if(i())return e();(0,n.DD)("DOMContentLoaded",e)}},384:(e,t,r)=>{"use strict";r.d(t,{NT:()=>o,US:()=>l,Zm:()=>a,bQ:()=>c,dV:()=>s,nY:()=>u,pV:()=>d});var n=r(154),i=r(863);const o={beacon:"bam.nr-data.net",errorBeacon:"bam.nr-data.net"};function a(){return n.gm.NREUM||(n.gm.NREUM={}),void 0===n.gm.newrelic&&(n.gm.newrelic=n.gm.NREUM),n.gm.NREUM}function s(){let e=a();return e.o||(e.o={ST:n.gm.setTimeout,SI:n.gm.setImmediate,CT:n.gm.clearTimeout,XHR:n.gm.XMLHttpRequest,REQ:n.gm.Request,EV:n.gm.Event,PR:n.gm.Promise,MO:n.gm.MutationObserver,FETCH:n.gm.fetch,WS:n.gm.WebSocket}),e}function c(e,t){let r=a();r.initializedAgents??={},t.initializedAt={ms:(0,i.t)(),date:new Date},r.initializedAgents[e]=t}function u(e){let t=a();return t.initializedAgents?.[e]}function l(e,t){a()[e]=t}function d(){return function(){let e=a();const t=e.info||{};e.info={beacon:o.beacon,errorBeacon:o.errorBeacon,...t}}(),function(){let e=a();const t=e.init||{};e.init={...t}}(),s(),function(){let e=a();const t=e.loader_config||{};e.loader_config={...t}}(),a()}},843:(e,t,r)=>{"use strict";r.d(t,{u:()=>i});var n=r(878);function i(e,t=!1,r,i){(0,n.DD)("visibilitychange",(function(){if(t)return void("hidden"===document.visibilityState&&e());e(document.visibilityState)}),r,i)}},434:(e,t,r)=>{"use strict";r.d(t,{Jt:()=>o,YM:()=>c});var n=r(836),i=r(607);const o="nr@original:".concat(i.W);var a=Object.prototype.hasOwnProperty,s=!1;function c(e,t){return e||(e=n.ee),r.inPlace=function(e,t,n,i,o){n||(n="");const a="-"===n.charAt(0);for(let s=0;s<t.length;s++){const c=t[s],u=e[c];l(u)||(e[c]=r(u,a?c+n:n,i,c,o))}},r.flag=o,r;function r(t,r,n,s,c){return l(t)?t:(r||(r=""),nrWrapper[o]=t,function(e,t,r){if(Object.defineProperty&&Object.keys)try{return Object.keys(e).forEach((function(r){Object.defineProperty(t,r,{get:function(){return e[r]},set:function(t){return e[r]=t,t}})})),t}catch(e){u([e],r)}for(var n in e)a.call(e,n)&&(t[n]=e[n])}(t,nrWrapper,e),nrWrapper);function nrWrapper(){var o,a,l,d;try{a=this,o=[...arguments],l="function"==typeof n?n(o,a):n||{}}catch(t){u([t,"",[o,a,s],l],e)}i(r+"start",[o,a,s],l,c);try{return d=t.apply(a,o)}catch(e){throw i(r+"err",[o,a,e],l,c),e}finally{i(r+"end",[o,a,d],l,c)}}}function i(r,n,i,o){if(!s||t){var a=s;s=!0;try{e.emit(r,n,i,t,o)}catch(t){u([t,r,n,i],e)}s=a}}}function u(e,t){t||(t=n.ee);try{t.emit("internal-error",e)}catch(e){}}function l(e){return!(e&&"function"==typeof e&&e.apply&&!e[o])}},993:(e,t,r)=>{"use strict";r.d(t,{ET:()=>o,p_:()=>i});var n=r(860);const i={ERROR:"ERROR",WARN:"WARN",INFO:"INFO",DEBUG:"DEBUG",TRACE:"TRACE"},o="log";n.K7.logging},969:(e,t,r)=>{"use strict";r.d(t,{TZ:()=>n,XG:()=>s,rs:()=>i,xV:()=>a,z_:()=>o});const n=r(860).K7.metrics,i="sm",o="cm",a="storeSupportabilityMetrics",s="storeEventMetrics"},630:(e,t,r)=>{"use strict";r.d(t,{T:()=>n});const n=r(860).K7.pageViewEvent},782:(e,t,r)=>{"use strict";r.d(t,{T:()=>n});const n=r(860).K7.pageViewTiming},344:(e,t,r)=>{"use strict";r.d(t,{G4:()=>i});var n=r(614);r(860).K7.sessionReplay;const i={RECORD:"recordReplay",PAUSE:"pauseReplay",REPLAY_RUNNING:"replayRunning",ERROR_DURING_REPLAY:"errorDuringReplay"};n.g.ERROR,n.g.FULL,n.g.OFF},234:(e,t,r)=>{"use strict";r.d(t,{W:()=>o});var n=r(836),i=r(687);class o{constructor(e,t){this.agentIdentifier=e,this.ee=n.ee.get(e),this.featureName=t,this.blocked=!1}deregisterDrain(){(0,i.x3)(this.agentIdentifier,this.featureName)}}},603:(e,t,r)=>{"use strict";r.d(t,{j:()=>K});var n=r(860),i=r(555),o=r(371),a=r(908),s=r(836),c=r(687),u=r(289),l=r(154),d=r(944),f=r(969),g=r(384),p=r(344);const m=["setErrorHandler","finished","addToTrace","addRelease","recordCustomEvent","addPageAction","setCurrentRouteName","setPageViewName","setCustomAttribute","interaction","noticeError","setUserId","setApplicationVersion","start",p.G4.RECORD,p.G4.PAUSE,"log","wrapLogger"],h=["setErrorHandler","finished","addToTrace","addRelease"];var v=r(863),b=r(614),y=r(993);var w=r(646),A=r(434);const R=new Map;function _(e,t,r,n){if("object"!=typeof t||!t||"string"!=typeof r||!r||"function"!=typeof t[r])return(0,d.R)(29);const i=function(e){return(e||s.ee).get("logger")}(e),o=(0,A.YM)(i),a=new w.y(s.P);a.level=n.level,a.customAttributes=n.customAttributes;const c=t[r]?.[A.Jt]||t[r];return R.set(c,a),o.inPlace(t,[r],"wrap-logger-",(()=>R.get(c))),i}function E(){const e=(0,g.pV)();m.forEach((t=>{e[t]=(...r)=>function(t,...r){let n=[];return Object.values(e.initializedAgents).forEach((e=>{e&&e.api?e.exposed&&e.api[t]&&n.push(e.api[t](...r)):(0,d.R)(38,t)})),n.length>1?n:n[0]}(t,...r)}))}const x={};function N(e,t,g=!1){t||(0,c.Ak)(e,"api");const m={};var w=s.ee.get(e),A=w.get("tracer");x[e]=b.g.OFF,w.on(p.G4.REPLAY_RUNNING,(t=>{x[e]=t}));var R="api-",E=R+"ixn-";function N(t,r,n,o){const a=(0,i.Vp)(e);return null===r?delete a.jsAttributes[t]:(0,i.x1)(e,{...a,jsAttributes:{...a.jsAttributes,[t]:r}}),j(R,n,!0,o||null===r?"session":void 0)(t,r)}function k(){}m.log=function(e,{customAttributes:t={},level:r=y.p_.INFO}={}){(0,a.p)(f.xV,["API/log/called"],void 0,n.K7.metrics,w),function(e,t,r={},i=y.p_.INFO){(0,a.p)(f.xV,["API/logging/".concat(i.toLowerCase(),"/called")],void 0,n.K7.metrics,e),(0,a.p)(y.ET,[(0,v.t)(),t,r,i],void 0,n.K7.logging,e)}(w,e,t,r)},m.wrapLogger=(e,t,{customAttributes:r={},level:i=y.p_.INFO}={})=>{(0,a.p)(f.xV,["API/wrapLogger/called"],void 0,n.K7.metrics,w),_(w,e,t,{customAttributes:r,level:i})},h.forEach((e=>{m[e]=j(R,e,!0,"api")})),m.addPageAction=j(R,"addPageAction",!0,n.K7.genericEvents),m.recordCustomEvent=j(R,"recordCustomEvent",!0,n.K7.genericEvents),m.setPageViewName=function(t,r){if("string"==typeof t)return"/"!==t.charAt(0)&&(t="/"+t),(0,o.f)(e).customTransaction=(r||"http://custom.transaction")+t,j(R,"setPageViewName",!0)()},m.setCustomAttribute=function(e,t,r=!1){if("string"==typeof e){if(["string","number","boolean"].includes(typeof t)||null===t)return N(e,t,"setCustomAttribute",r);(0,d.R)(40,typeof t)}else(0,d.R)(39,typeof e)},m.setUserId=function(e){if("string"==typeof e||null===e)return N("enduser.id",e,"setUserId",!0);(0,d.R)(41,typeof e)},m.setApplicationVersion=function(e){if("string"==typeof e||null===e)return N("application.version",e,"setApplicationVersion",!1);(0,d.R)(42,typeof e)},m.start=()=>{try{(0,a.p)(f.xV,["API/start/called"],void 0,n.K7.metrics,w),w.emit("manual-start-all")}catch(e){(0,d.R)(23,e)}},m[p.G4.RECORD]=function(){(0,a.p)(f.xV,["API/recordReplay/called"],void 0,n.K7.metrics,w),(0,a.p)(p.G4.RECORD,[],void 0,n.K7.sessionReplay,w)},m[p.G4.PAUSE]=function(){(0,a.p)(f.xV,["API/pauseReplay/called"],void 0,n.K7.metrics,w),(0,a.p)(p.G4.PAUSE,[],void 0,n.K7.sessionReplay,w)},m.interaction=function(e){return(new k).get("object"==typeof e?e:{})};const T=k.prototype={createTracer:function(e,t){var r={},i=this,o="function"==typeof t;return(0,a.p)(f.xV,["API/createTracer/called"],void 0,n.K7.metrics,w),g||(0,a.p)(E+"tracer",[(0,v.t)(),e,r],i,n.K7.spa,w),function(){if(A.emit((o?"":"no-")+"fn-start",[(0,v.t)(),i,o],r),o)try{return t.apply(this,arguments)}catch(e){const t="string"==typeof e?new Error(e):e;throw A.emit("fn-err",[arguments,this,t],r),t}finally{A.emit("fn-end",[(0,v.t)()],r)}}}};function j(e,t,r,i){return function(){return(0,a.p)(f.xV,["API/"+t+"/called"],void 0,n.K7.metrics,w),i&&(0,a.p)(e+t,[r?(0,v.t)():performance.now(),...arguments],r?null:this,i,w),r?void 0:this}}function I(){r.e(296).then(r.bind(r,778)).then((({setAPI:t})=>{t(e),(0,c.Ze)(e,"api")})).catch((e=>{(0,d.R)(27,e),w.abort()}))}return["actionText","setName","setAttribute","save","ignore","onEnd","getContext","end","get"].forEach((e=>{T[e]=j(E,e,void 0,g?n.K7.softNav:n.K7.spa)})),m.setCurrentRouteName=g?j(E,"routeName",void 0,n.K7.softNav):j(R,"routeName",!0,n.K7.spa),m.noticeError=function(t,r){"string"==typeof t&&(t=new Error(t)),(0,a.p)(f.xV,["API/noticeError/called"],void 0,n.K7.metrics,w),(0,a.p)("err",[t,(0,v.t)(),!1,r,!!x[e]],void 0,n.K7.jserrors,w)},l.RI?(0,u.GG)((()=>I()),!0):I(),m}var k=r(217),T=r(122);const j={accountID:void 0,trustKey:void 0,agentID:void 0,licenseKey:void 0,applicationID:void 0,xpid:void 0},I={};var S=r(284);const O=e=>{const t=e.startsWith("http");e+="/",r.p=t?e:"https://"+e};let P=!1;function K(e,t={},r,n){let{init:a,info:c,loader_config:u,runtime:d={},exposed:f=!0}=t;d.loaderType=r;const p=(0,g.pV)();c||(a=p.init,c=p.info,u=p.loader_config),(0,k.xN)(e.agentIdentifier,a||{}),function(e,t){if(!e)throw new Error("All loader-config objects require an agent identifier!");I[e]=(0,T.a)(t,j);const r=(0,g.nY)(e);r&&(r.loader_config=I[e])}(e.agentIdentifier,u||{}),c.jsAttributes??={},l.bv&&(c.jsAttributes.isWorker=!0),(0,i.x1)(e.agentIdentifier,c);const m=(0,k.D0)(e.agentIdentifier),h=[c.beacon,c.errorBeacon];P||(m.proxy.assets&&(O(m.proxy.assets),h.push(m.proxy.assets)),m.proxy.beacon&&h.push(m.proxy.beacon),E(),(0,g.US)("activatedFeatures",S.B),e.runSoftNavOverSpa&&=!0===m.soft_navigations.enabled&&m.feature_flags.includes("soft_nav")),d.denyList=[...m.ajax.deny_list||[],...m.ajax.block_internal?h:[]],d.ptid=e.agentIdentifier,(0,o.V)(e.agentIdentifier,d),e.ee=s.ee.get(e.agentIdentifier),void 0===e.api&&(e.api=N(e.agentIdentifier,n,e.runSoftNavOverSpa)),void 0===e.exposed&&(e.exposed=f),P=!0}},374:(e,t,r)=>{r.nc=(()=>{try{return document?.currentScript?.nonce}catch(e){}return""})()},860:(e,t,r)=>{"use strict";r.d(t,{$J:()=>u,K7:()=>s,P3:()=>c,XX:()=>i,qY:()=>n,v4:()=>a});const n="events",i="jserrors",o="browser/blobs",a="rum",s={ajax:"ajax",genericEvents:"generic_events",jserrors:i,logging:"logging",metrics:"metrics",pageAction:"page_action",pageViewEvent:"page_view_event",pageViewTiming:"page_view_timing",sessionReplay:"session_replay",sessionTrace:"session_trace",softNav:"soft_navigations",spa:"spa"},c={[s.pageViewEvent]:1,[s.pageViewTiming]:2,[s.metrics]:3,[s.jserrors]:4,[s.spa]:5,[s.ajax]:6,[s.sessionTrace]:7,[s.softNav]:8,[s.sessionReplay]:9,[s.logging]:10,[s.genericEvents]:11},u={[s.pageViewEvent]:a,[s.pageViewTiming]:n,[s.ajax]:n,[s.spa]:n,[s.softNav]:n,[s.metrics]:i,[s.jserrors]:i,[s.sessionTrace]:o,[s.sessionReplay]:o,[s.logging]:"browser/logs",[s.genericEvents]:"ins"}}},n={};function i(e){var t=n[e];if(void 0!==t)return t.exports;var o=n[e]={exports:{}};return r[e](o,o.exports,i),o.exports}i.m=r,i.d=(e,t)=>{for(var r in t)i.o(t,r)&&!i.o(e,r)&&Object.defineProperty(e,r,{enumerable:!0,get:t[r]})},i.f={},i.e=e=>Promise.all(Object.keys(i.f).reduce(((t,r)=>(i.f[r](e,t),t)),[])),i.u=e=>"nr-rum-1.281.0.min.js",i.o=(e,t)=>Object.prototype.hasOwnProperty.call(e,t),e={},t="NRBA-1.281.0.PROD:",i.l=(r,n,o,a)=>{if(e[r])e[r].push(n);else{var s,c;if(void 0!==o)for(var u=document.getElementsByTagName("script"),l=0;l<u.length;l++){var d=u[l];if(d.getAttribute("src")==r||d.getAttribute("data-webpack")==t+o){s=d;break}}if(!s){c=!0;var f={296:"sha512-zqOtfbjYsGTkQScey1O8Hh9fA1+m2RFxLpfv7BWqqTivgQ6iM13v6QJ4d5xykyDwx1GoMFmngC4SKpFn6VciYg=="};(s=document.createElement("script")).charset="utf-8",s.timeout=120,i.nc&&s.setAttribute("nonce",i.nc),s.setAttribute("data-webpack",t+o),s.src=r,0!==s.src.indexOf(window.location.origin+"/")&&(s.crossOrigin="anonymous"),f[a]&&(s.integrity=f[a])}e[r]=[n];var g=(t,n)=>{s.onerror=s.onload=null,clearTimeout(p);var i=e[r];if(delete e[r],s.parentNode&&s.parentNode.removeChild(s),i&&i.forEach((e=>e(n))),t)return t(n)},p=setTimeout(g.bind(null,void 0,{type:"timeout",target:s}),12e4);s.onerror=g.bind(null,s.onerror),s.onload=g.bind(null,s.onload),c&&document.head.appendChild(s)}},i.r=e=>{"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})},i.p="https://js-agent.newrelic.com/",(()=>{var e={374:0,840:0};i.f.j=(t,r)=>{var n=i.o(e,t)?e[t]:void 0;if(0!==n)if(n)r.push(n[2]);else{var o=new Promise(((r,i)=>n=e[t]=[r,i]));r.push(n[2]=o);var a=i.p+i.u(t),s=new Error;i.l(a,(r=>{if(i.o(e,t)&&(0!==(n=e[t])&&(e[t]=void 0),n)){var o=r&&("load"===r.type?"missing":r.type),a=r&&r.target&&r.target.src;s.message="Loading chunk "+t+" failed.\n("+o+": "+a+")",s.name="ChunkLoadError",s.type=o,s.request=a,n[1](s)}}),"chunk-"+t,t)}};var t=(t,r)=>{var n,o,[a,s,c]=r,u=0;if(a.some((t=>0!==e[t]))){for(n in s)i.o(s,n)&&(i.m[n]=s[n]);if(c)c(i)}for(t&&t(r);u<a.length;u++)o=a[u],i.o(e,o)&&e[o]&&e[o][0](),e[o]=0},r=self["webpackChunk:NRBA-1.281.0.PROD"]=self["webpackChunk:NRBA-1.281.0.PROD"]||[];r.forEach(t.bind(null,0)),r.push=t.bind(null,r.push.bind(r))})(),(()=>{"use strict";i(374);var e=i(944),t=i(344),r=i(566);class n{agentIdentifier;constructor(){this.agentIdentifier=(0,r.LA)(16)}#e(t,...r){if("function"==typeof this.api?.[t])return this.api[t](...r);(0,e.R)(35,t)}addPageAction(e,t){return this.#e("addPageAction",e,t)}recordCustomEvent(e,t){return this.#e("recordCustomEvent",e,t)}setPageViewName(e,t){return this.#e("setPageViewName",e,t)}setCustomAttribute(e,t,r){return this.#e("setCustomAttribute",e,t,r)}noticeError(e,t){return this.#e("noticeError",e,t)}setUserId(e){return this.#e("setUserId",e)}setApplicationVersion(e){return this.#e("setApplicationVersion",e)}setErrorHandler(e){return this.#e("setErrorHandler",e)}addRelease(e,t){return this.#e("addRelease",e,t)}log(e,t){return this.#e("log",e,t)}}class o extends n{#e(t,...r){if("function"==typeof this.api?.[t])return this.api[t](...r);(0,e.R)(35,t)}start(){return this.#e("start")}finished(e){return this.#e("finished",e)}recordReplay(){return this.#e(t.G4.RECORD)}pauseReplay(){return this.#e(t.G4.PAUSE)}addToTrace(e){return this.#e("addToTrace",e)}setCurrentRouteName(e){return this.#e("setCurrentRouteName",e)}interaction(){return this.#e("interaction")}wrapLogger(e,t,r){return this.#e("wrapLogger",e,t,r)}}var a=i(860),s=i(217);const c=Object.values(a.K7);function u(e){const t={};return c.forEach((r=>{t[r]=function(e,t){return!0===(0,s.gD)(t,"".concat(e,".enabled"))}(r,e)})),t}var l=i(603);var d=i(687),f=i(234),g=i(289),p=i(154),m=i(384);const h=e=>p.RI&&!0===(0,s.gD)(e,"privacy.cookies_enabled");function v(e){return!!(0,m.dV)().o.MO&&h(e)&&!0===(0,s.gD)(e,"session_trace.enabled")}var b=i(389);class y extends f.W{constructor(e,t,r=!0){super(e.agentIdentifier,t),this.auto=r,this.abortHandler=void 0,this.featAggregate=void 0,this.onAggregateImported=void 0,!1===e.init[this.featureName].autoStart&&(this.auto=!1),this.auto?(0,d.Ak)(e.agentIdentifier,t):this.ee.on("manual-start-all",(0,b.J)((()=>{(0,d.Ak)(e.agentIdentifier,this.featureName),this.auto=!0,this.importAggregator(e)})))}importAggregator(t,r={}){if(this.featAggregate||!this.auto)return;let n;this.onAggregateImported=new Promise((e=>{n=e}));const o=async()=>{let o;try{if(h(this.agentIdentifier)){const{setupAgentSession:e}=await i.e(296).then(i.bind(i,861));o=e(t)}}catch(t){(0,e.R)(20,t),this.ee.emit("internal-error",[t]),this.featureName===a.K7.sessionReplay&&this.abortHandler?.()}try{if(!this.#t(this.featureName,o))return(0,d.Ze)(this.agentIdentifier,this.featureName),void n(!1);const{lazyFeatureLoader:e}=await i.e(296).then(i.bind(i,103)),{Aggregate:a}=await e(this.featureName,"aggregate");this.featAggregate=new a(t,r),t.runtime.harvester.initializedAggregates.push(this.featAggregate),n(!0)}catch(t){(0,e.R)(34,t),this.abortHandler?.(),(0,d.Ze)(this.agentIdentifier,this.featureName,!0),n(!1),this.ee&&this.ee.abort()}};p.RI?(0,g.GG)((()=>o()),!0):o()}#t(e,t){switch(e){case a.K7.sessionReplay:return v(this.agentIdentifier)&&!!t;case a.K7.sessionTrace:return!!t;default:return!0}}}var w=i(630);class A extends y{static featureName=w.T;constructor(e,t=!0){super(e,w.T,t),this.importAggregator(e)}}var R=i(908),_=i(843),E=i(878),x=i(782),N=i(863);class k extends y{static featureName=x.T;constructor(e,t=!0){super(e,x.T,t),p.RI&&((0,_.u)((()=>(0,R.p)("docHidden",[(0,N.t)()],void 0,x.T,this.ee)),!0),(0,E.sp)("pagehide",(()=>(0,R.p)("winPagehide",[(0,N.t)()],void 0,x.T,this.ee))),this.importAggregator(e))}}var T=i(969);class j extends y{static featureName=T.TZ;constructor(e,t=!0){super(e,T.TZ,t),this.importAggregator(e)}}new class extends o{constructor(t){super(),p.gm?(this.features={},(0,m.bQ)(this.agentIdentifier,this),this.desiredFeatures=new Set(t.features||[]),this.desiredFeatures.add(A),this.runSoftNavOverSpa=[...this.desiredFeatures].some((e=>e.featureName===a.K7.softNav)),(0,l.j)(this,t,t.loaderType||"agent"),this.run()):(0,e.R)(21)}get config(){return{info:this.info,init:this.init,loader_config:this.loader_config,runtime:this.runtime}}run(){try{const t=u(this.agentIdentifier),r=[...this.desiredFeatures];r.sort(((e,t)=>a.P3[e.featureName]-a.P3[t.featureName])),r.forEach((r=>{if(!t[r.featureName]&&r.featureName!==a.K7.pageViewEvent)return;if(this.runSoftNavOverSpa&&r.featureName===a.K7.spa)return;if(!this.runSoftNavOverSpa&&r.featureName===a.K7.softNav)return;const n=function(e){switch(e){case a.K7.ajax:return[a.K7.jserrors];case a.K7.sessionTrace:return[a.K7.ajax,a.K7.pageViewEvent];case a.K7.sessionReplay:return[a.K7.sessionTrace];case a.K7.pageViewTiming:return[a.K7.pageViewEvent];default:return[]}}(r.featureName).filter((e=>!(e in this.features)));n.length>0&&(0,e.R)(36,{targetFeature:r.featureName,missingDependencies:n}),this.features[r.featureName]=new r(this)}))}catch(t){(0,e.R)(22,t);for(const e in this.features)this.features[e].abortHandler?.();const r=(0,m.Zm)();delete r.initializedAgents[this.agentIdentifier]?.api,delete r.initializedAgents[this.agentIdentifier]?.features,delete this.sharedAggregator;return r.ee.get(this.agentIdentifier).abort(),!1}}}({features:[A,k,j],loaderType:"lite"})})()})();</script> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="canonical" href=""/> <title> Cisco Talos Incident Response || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence </title> <meta name="description" content=""/> <meta name="keywords" content=""/> <link rel="stylesheet" href="/assets/application-2843e2a8a50264a14de049cfa32e7596f58df6139a3d38af2f684513d6d77e00.css" media="all" /> <script src="/assets/application-66d7d8c030f9a67406fb3b4e215ddf77401ec8b10aa30b8f5bc250468229ea36.js"></script> <link rel="icon" type="image/x-icon" href="/assets/favicons/favicon-01f90f6b94ec4cceb73079603f6ae4329ac68a00d055125fd7e998b2ce4d5556.ico" /> <meta name="csrf-param" content="authenticity_token" /> <meta name="csrf-token" content="OMwXNstXIO5hEeRGFwxD0b71RhvdRS4dwyHdLRVXAW5UTt8OQFMED3G9dLJ77AwsA7a+NWC5Q9pZEA3LZErwdg==" /> <script> //<![CDATA[ window.gmk = "AIzaSyBw2Flbv4O6-cA6f_zAGMP7Lw5KXDGmSjI"; //]]> </script> <script> (function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){ (i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o), m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m) })(window,document,'script','https://www.google-analytics.com/analytics.js','ga'); ga('create', 'UA-63204287-3', 'auto'); ga('send', 'pageview'); </script> <link href='https://fonts.googleapis.com/css?family=Roboto:100,300,400,500,700' rel='stylesheet' type='text/css'> <link href="https://fonts.googleapis.com/css2?family=Exo+2:wght@100;300;400;500;700&display=swap" rel="stylesheet"> </head> <body> <nav id='nav'> <div id='top-nav-bar'> <ul class='top-nav-links-wrapper'> <li><a class="login-button" href="/users/auth/saml">Cisco Login</a></li> </ul> </div> <div id='navigation'> <div class='navigation-logos-wrapper'> <div id='talos-logo-wrapper'> <a class="page-link" href="/"><svg xmlns="http://www.w3.org/2000/svg" id="cisco_talos_logo" viewBox="0 0 617.37 213.1"> <defs> <style> .cisco-fill{fill:#8e8c8c;} .talos-fill{fill:#056eb6;} </style> </defs> <g id="Layer_1-2"> <path class="cisco-fill" d="m92.7,1.73c-.3-.08-4.85-1.29-9.7-1.32-9.18-.06-14.75,4.86-14.8,12.24-.04,6.54,4.56,9.83,10.1,11.62.62.21,1.52.5,2.12.7,2.47.79,4.43,1.96,4.42,3.96-.02,2.24-2.31,3.67-7.26,3.64-4.36-.03-8.52-1.3-9.4-1.53l-.06,9.09c.49.11,5.44,1.12,10.75,1.15,7.63.05,16.37-3.22,16.44-13.14.03-4.81-2.88-9.26-9.34-11.36l-2.74-.89c-1.64-.53-4.56-1.39-4.54-3.79.01-1.9,2.19-3.22,6.19-3.19,3.45.02,7.63,1.21,7.78,1.26l.06-8.43h0Zm84.08,19.77c-.04,5.75-4.47,10.36-10.38,10.32-5.91-.04-10.27-4.72-10.23-10.46.04-5.73,4.46-10.35,10.37-10.31,5.91.04,10.28,4.72,10.24,10.45h0ZM166.6.99c-12.14-.08-20.92,9.02-20.99,20.3-.08,11.3,8.57,20.51,20.71,20.59,12.14.08,20.93-9.01,21.01-20.31.08-11.28-8.58-20.5-20.73-20.58h0ZM31.25,1.48C30.31,1.19,26.86.03,22.17,0,10.04-.08,1.08,8.5,1,20.29c-.09,12.72,9.69,20.52,20.89,20.59,4.45.03,7.85-1,9.1-1.34l.07-10.6c-.43.23-3.7,2.07-8.39,2.04-6.64-.05-10.89-4.75-10.85-10.62.04-6.05,4.54-10.5,10.99-10.46,4.77.03,7.96,1.95,8.36,2.17l.07-10.6h0Zm104,.71c-.94-.28-4.4-1.44-9.07-1.48-12.14-.08-21.1,8.5-21.18,20.29-.09,12.72,9.7,20.52,20.9,20.59,4.43.03,7.84-1,9.09-1.34l.07-10.6c-.44.23-3.71,2.07-8.4,2.04-6.63-.05-10.88-4.75-10.84-10.62.04-6.05,4.54-10.5,10.98-10.46,4.77.03,7.96,1.95,8.37,2.17l.07-10.6h0ZM54.64,40.41l-9.96-.07.27-39.49,9.96.07-.27,39.49h0Z"></path> <path class="talos-fill" d="m478.12,96.94l-9.97,9.97c2.89,1,5.17,3.28,6.17,6.17l9.97-9.97c-1.92-2.19-3.98-4.25-6.17-6.17Z"></path> <path class="talos-fill" d="m395.44,179.63l-9.97,9.97c1.92,2.19,3.98,4.25,6.17,6.17l9.97-9.97c-2.89-1-5.17-3.28-6.17-6.17Z"></path> <path class="talos-fill" d="m394.88,173.11v-56.76c0-5.52,4.48-10,10-10h56.76l12.59-12.59c-10.97-8.22-24.59-13.09-39.35-13.09-36.27,0-65.68,29.41-65.68,65.68,0,14.76,4.87,28.38,13.09,39.35l12.59-12.59Z"></path> <path class="talos-fill" d="m487.47,107l-12.59,12.59v56.76c0,5.52-4.48,10-10,10h-56.76l-12.59,12.59c10.97,8.22,24.59,13.09,39.35,13.09,36.27,0,65.68-29.41,65.68-65.68,0-14.76-4.87-28.38-13.09-39.35Z"></path> <path class="talos-fill" d="m104.85,102.56c9.61-.91,19.25-8.76,19.25-22.53H0c0,14.66,10.94,22.61,21.13,22.62h0s23.56,0,23.95,0c3.3.03,5.95,2.7,5.94,6,0,2.93,0,84.04,0,84.04,0,5.62,1.67,10.06,5.1,13.57,2.83,2.9,6.48,4.83,11.15,5.9,1.03.24,5.78.95,5.78.95v-104.44c0-3.29,2.65-5.97,5.94-6,0,0,23.94,0,23.96,0h0c.62,0,1.25-.03,1.88-.09,0,0,0,0,0,0Z"></path> <path class="talos-fill" d="m245.87,105.39c0-15.3-10.17-25.4-24.27-25.4h-78.77c0,14.7,10.98,22.67,21.2,22.67.32.02,35.71,0,49.93-.01,5.53,0,10.01,4.47,10.01,10l-.1,63.58c0,7.73-6.26,14-13.99,14h-48.41c-6.64-.04-10.84-2.78-12.46-8.81-1.3-4.85-.84-7.98,1.4-13.35,2.81-6.7,7.17-11.07,13.33-13.34,2.97-1.1,6.18-1.17,9.49-1.16,11.26.05,44.71,0,44.71,0v-22.3s-34.44.01-48.57,0c-6.93,0-13.3,1.84-18.95,5.48-9.71,6.26-16.94,15.06-21.48,27.03-2.92,7.69-3.49,14.4-1.76,24.29,1.01,5.74,3.07,10.31,6.32,13.97,5.57,6.29,12.98,9.7,22.03,10.14,1.9.09,53.47.08,55.72.08,1.74,0,3.45-.11,5.09-.33,5.23-.69,9.71-2.74,13.35-5.59,3.64,2.85,8.12,4.9,13.35,5.59,1.63.22,2.91.34,2.91.34,0,0-.07-105.76-.07-106.91Z"></path> <path class="talos-fill" d="m375.22,212.3h0c0-7.39-2.78-13.08-6.83-16.92,0,0,0,0,0,0-.12-.12-.26-.24-.4-.36-3.73-3.35-8.47-5.18-13.12-5.38-.03,0-.05-.01-.05-.01l-58.33-.03c-3.31,0-6-2.69-6-6v-81.95c0-5.16-2.01-9.89-4.98-13.35-3.82-4.56-9.8-7.77-17.75-7.77h0v111.78c0,11.05,8.95,20,20,20h87.46Z"></path> <path class="talos-fill" d="m617.3,161.26c-.02-4.33-.79-7.97-2.37-11.12-4.77-9.53-13.41-14.96-24.32-15.31-1.74-.06-42.2-.23-43.68-.23-4.96-.18-8.65-3.99-8.75-8.86l1.13-13c.51-5.53,5.4-10.01,10.92-10,10.26.01,45.34.04,45.68.01,10.15,0,21.04-7.87,21.19-22.38.02-.11-67.89-.3-67.89-.3-1.74,0-3.46.11-5.12.33-14.58,1.91-24.4,14.06-26.57,25.07-.39,1.97-2.27,24.41-2.35,25.36-.38,4.33.06,7.97,1.35,11.12,3.9,9.53,12.04,14.96,22.92,15.31.06,0,.13,0,.21,0,1.04.11,2.1.17,3.18.18.87.01,27.15.02,42.01.03,5.52,0,9.99,4.48,9.99,10v11.88c0,5.53-4.48,10.01-10.01,10-12.25-.01-59.26-.05-59.8-.01-10.22,0-21.2,7.98-21.2,22.69,0,0,81.13-.01,84.09-.01,1.74,0,3.45-.11,5.09-.33,14.41-1.91,23.11-14.06,24.27-25.07.21-1.97.03-24.41.03-25.36Z"></path> </g> </svg> </a></div> </div> <div class='navigation-links-wrapper'> <ul class='main-nav-list'> <li class='nav-item'> <div class='primary-link-wrapper'> <a class="primary_nav_link" href="/reputation"><div class='mobile-nav-icon'><!-- Generator: Adobe Illustrator 24.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) --><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0px" y="0px" viewBox="0 0 20 20" height="20px" width="20px" style="enable-background:new 0 0 20 20;" xml:space="preserve"> <style type="text/css"> .white{fill:#FFFFFF;} </style> <g> <path class="white" d="M19.5,9.5h-1.1c-0.3-4.2-3.6-7.6-7.8-7.8V0.5C10.5,0.2,10.3,0,10,0l0,0C9.7,0,9.5,0.2,9.5,0.5l0,0v1.1 C5.3,1.9,1.9,5.3,1.6,9.5H0.5C0.2,9.5,0,9.7,0,10s0.2,0.5,0.5,0.5l0,0h1.1c0.3,4.2,3.6,7.6,7.8,7.8v1.1c0,0.3,0.2,0.5,0.5,0.5l0,0 c0.3,0,0.5-0.2,0.5-0.5l0,0v-1.1c4.2-0.3,7.6-3.6,7.8-7.8h1.1c0.3,0,0.5-0.2,0.5-0.5C20,9.7,19.8,9.5,19.5,9.5 M16.6,10.5h0.7 c-0.3,3.6-3.2,6.5-6.8,6.8v-0.8c0-0.3-0.2-0.5-0.5-0.5l0,0c-0.3,0-0.5,0.2-0.5,0.5v0.8C5.8,17,3,14.2,2.7,10.5h0.8 C3.8,10.5,4,10.3,4,10S3.8,9.5,3.5,9.5l0,0H2.7C3,5.8,5.8,3,9.5,2.7v0.8C9.5,3.7,9.7,4,10,4l0,0c0.3,0,0.5-0.2,0.5-0.5V2.7 C14.2,3,17,5.8,17.3,9.5h-0.7c-0.3,0-0.5,0.2-0.5,0.5C16.1,10.3,16.3,10.5,16.6,10.5L16.6,10.5"></path> <circle class="white" cx="10" cy="10" r="3.2"></circle> </g> </svg> </div> <span class='top-nav-link-text'> Intelligence Center </span> </a></div> <input class='sub-nav-trigger' id='intelligence-sub-trigger' type='checkbox'> <label class='sub-nav-trigger-label' for='intelligence-sub-trigger'> <svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="48.167px" height="47.75px" viewBox="0 0 48.167 47.75"> <circle opacity="0.4" fill="none" stroke="#FFFFFF" stroke-miterlimit="10" cx="24.083" cy="23.875" r="22"></circle> <g> <circle fill="#FFFFFF" cx="24.083" cy="16.068" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="23.875" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="31.682" r="2.496"></circle> </g> </svg> </label> <ul class='sub-nav sub-nav-single-list'> <li class='desktop-hide'> <a class="mobile_nav_link" href="/reputation"><h1>Intelligence Center</h1> </a></li> <li class='desktop-hide'> <label class='subnav-back-button' for='intelligence-sub-trigger'>BACK</label> </li> <li><a class="secondary_nav_link" href="/reputation_center">Intelligence Search</a></li> <li><a class="secondary_nav_link" href="/reputation_center/email_rep">Email & Spam Trends</a></li> </ul> <div class='desktop-hide subnav-overlay'><!-- Generator: Adobe Illustrator 24.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) --><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0px" y="0px" viewBox="0 0 20 20" height="20px" width="20px" style="enable-background:new 0 0 20 20;" xml:space="preserve"> <style type="text/css"> .white{fill:#FFFFFF;} </style> <g> <path class="white" d="M19.5,9.5h-1.1c-0.3-4.2-3.6-7.6-7.8-7.8V0.5C10.5,0.2,10.3,0,10,0l0,0C9.7,0,9.5,0.2,9.5,0.5l0,0v1.1 C5.3,1.9,1.9,5.3,1.6,9.5H0.5C0.2,9.5,0,9.7,0,10s0.2,0.5,0.5,0.5l0,0h1.1c0.3,4.2,3.6,7.6,7.8,7.8v1.1c0,0.3,0.2,0.5,0.5,0.5l0,0 c0.3,0,0.5-0.2,0.5-0.5l0,0v-1.1c4.2-0.3,7.6-3.6,7.8-7.8h1.1c0.3,0,0.5-0.2,0.5-0.5C20,9.7,19.8,9.5,19.5,9.5 M16.6,10.5h0.7 c-0.3,3.6-3.2,6.5-6.8,6.8v-0.8c0-0.3-0.2-0.5-0.5-0.5l0,0c-0.3,0-0.5,0.2-0.5,0.5v0.8C5.8,17,3,14.2,2.7,10.5h0.8 C3.8,10.5,4,10.3,4,10S3.8,9.5,3.5,9.5l0,0H2.7C3,5.8,5.8,3,9.5,2.7v0.8C9.5,3.7,9.7,4,10,4l0,0c0.3,0,0.5-0.2,0.5-0.5V2.7 C14.2,3,17,5.8,17.3,9.5h-0.7c-0.3,0-0.5,0.2-0.5,0.5C16.1,10.3,16.3,10.5,16.6,10.5L16.6,10.5"></path> <circle class="white" cx="10" cy="10" r="3.2"></circle> </g> </svg> </div> </li> <li class='nav-item'> <div class='primary-link-wrapper'> <a class="primary_nav_link" href="/vulnerability_info"><div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="26px" height="20px" viewBox="0 0 26 20"> <g id="vuln-icon" class="nav-icon"> <path fill="#FFFFFF" d="M24.256,18.49L13.872,0.503C13.692,0.192,13.36,0,13,0c-0.359,0-0.692,0.192-0.872,0.503L1.744,18.49 c-0.18,0.312-0.18,0.695,0,1.006C1.924,19.809,2.257,20,2.616,20h20.769c0.359,0,0.691-0.191,0.871-0.504 C24.436,19.186,24.436,18.803,24.256,18.49 M14.268,18.215h-2.533v-1.85h2.533V18.215z M14.268,15.441h-2.533L10.89,6.515h4.222 L14.268,15.441z"></path> </g> </svg> </div> <span class='top-nav-link-text'> Vulnerability Research </span> </a></div> <input class='sub-nav-trigger' id='vuln-sub-trigger' type='checkbox'> <label class='sub-nav-trigger-label' for='vuln-sub-trigger'> <div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="48.167px" height="47.75px" viewBox="0 0 48.167 47.75"> <circle opacity="0.4" fill="none" stroke="#FFFFFF" stroke-miterlimit="10" cx="24.083" cy="23.875" r="22"></circle> <g> <circle fill="#FFFFFF" cx="24.083" cy="16.068" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="23.875" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="31.682" r="2.496"></circle> </g> </svg> </div> </label> <ul class='sub-nav sub-nav-single-list'> <li class='desktop-hide'> <a href="/vulnerability_info"><h1>Vulnerability Research</h1> </a></li> <li class='desktop-hide'> <label class='subnav-back-button' for='vuln-sub-trigger'>BACK</label> </li> <li><a class="vulnerabilty-info-nav-link" href="/vulnerability_reports">Vulnerability Reports</a></li> <li><a class="vulnerabilty-info-nav-link" href="/ms_advisories">Microsoft Advisories</a></li> </ul> <div class='desktop-hide subnav-overlay'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="26px" height="20px" viewBox="0 0 26 20"> <g id="vuln-icon" class="nav-icon"> <path fill="#FFFFFF" d="M24.256,18.49L13.872,0.503C13.692,0.192,13.36,0,13,0c-0.359,0-0.692,0.192-0.872,0.503L1.744,18.49 c-0.18,0.312-0.18,0.695,0,1.006C1.924,19.809,2.257,20,2.616,20h20.769c0.359,0,0.691-0.191,0.871-0.504 C24.436,19.186,24.436,18.803,24.256,18.49 M14.268,18.215h-2.533v-1.85h2.533V18.215z M14.268,15.441h-2.533L10.89,6.515h4.222 L14.268,15.441z"></path> </g> </svg> </div> </li> <li class='nav-item'> <div class='primary-link-wrapper'> <a class="primary_nav_link" href="/incident_response"><div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" width="111.588" height="148.311" viewBox="0 0 111.588 148.311"> <path d="M1.181,128.446v15.7a4.167,4.167,0,0,0,4.167,4.167h100.9a4.167,4.167,0,0,0,4.167-4.167v-15.7a4.167,4.167,0,0,0-4.167-4.167H5.348a4.167,4.167,0,0,0-4.167,4.166M55.8,63.109a3.277,3.277,0,1,1,0,6.553c-10.344,0-20.755,8.578-20.755,18.57a3.277,3.277,0,1,1-6.554,0C28.489,73.947,41.93,63.109,55.8,63.109Zm0-12.016c-21.787,0-39.325,17.81-39.325,39.937v26.7H95.122V91.03c0-22.128-17.537-39.937-39.324-39.937m52.365-38.3a3.291,3.291,0,0,0-2.254,1.024L88.432,31.294a3.283,3.283,0,0,0,4.642,4.644l17.478-17.479a3.278,3.278,0,0,0-2.389-5.666m-105.138,0a3.276,3.276,0,0,0-1.98,5.666L18.522,35.938a3.283,3.283,0,0,0,4.643-4.644L5.687,13.817A3.255,3.255,0,0,0,3.025,12.793ZM55.389.026a3.276,3.276,0,0,0-2.867,3.345V19.642a3.277,3.277,0,1,0,6.554,0V3.371A3.283,3.283,0,0,0,55.389.026Z" fill="#fff"></path> </svg> </div> <span class='top-nav-link-text'> Incident Response </span> </a></div> <input class='sub-nav-trigger' id='ir-sub-trigger' type='checkbox'> <label class='sub-nav-trigger-label' for='ir-sub-trigger'> <div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="48.167px" height="47.75px" viewBox="0 0 48.167 47.75"> <circle opacity="0.4" fill="none" stroke="#FFFFFF" stroke-miterlimit="10" cx="24.083" cy="23.875" r="22"></circle> <g> <circle fill="#FFFFFF" cx="24.083" cy="16.068" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="23.875" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="31.682" r="2.496"></circle> </g> </svg> </div> </label> <ul class='sub-nav sub-nav-single-list'> <li class='desktop-hide'> <a href="/incident_response"><h1>Incident Response</h1> </a></li> <li class='desktop-hide'> <label class='subnav-back-button' for='ir-sub-trigger'>BACK</label> </li> <li><a class="secondary_nav_link" href="/incident_response/services#reactive-services">Reactive Services</a></li> <li><a class="secondary_nav_link" href="/incident_response/services#proactive-services">Proactive Services</a></li> <li> <a href='' id='emergency_report_modal'>Emergency Support</a> </li> </ul> <div class='desktop-hide subnav-overlay'><svg xmlns="http://www.w3.org/2000/svg" width="111.588" height="148.311" viewBox="0 0 111.588 148.311"> <path d="M1.181,128.446v15.7a4.167,4.167,0,0,0,4.167,4.167h100.9a4.167,4.167,0,0,0,4.167-4.167v-15.7a4.167,4.167,0,0,0-4.167-4.167H5.348a4.167,4.167,0,0,0-4.167,4.166M55.8,63.109a3.277,3.277,0,1,1,0,6.553c-10.344,0-20.755,8.578-20.755,18.57a3.277,3.277,0,1,1-6.554,0C28.489,73.947,41.93,63.109,55.8,63.109Zm0-12.016c-21.787,0-39.325,17.81-39.325,39.937v26.7H95.122V91.03c0-22.128-17.537-39.937-39.324-39.937m52.365-38.3a3.291,3.291,0,0,0-2.254,1.024L88.432,31.294a3.283,3.283,0,0,0,4.642,4.644l17.478-17.479a3.278,3.278,0,0,0-2.389-5.666m-105.138,0a3.276,3.276,0,0,0-1.98,5.666L18.522,35.938a3.283,3.283,0,0,0,4.643-4.644L5.687,13.817A3.255,3.255,0,0,0,3.025,12.793ZM55.389.026a3.276,3.276,0,0,0-2.867,3.345V19.642a3.277,3.277,0,1,0,6.554,0V3.371A3.283,3.283,0,0,0,55.389.026Z" fill="#fff"></path> </svg> </div> </li> <li class='nav-item'> <a class="primary_nav_link" href="https://blog.talosintelligence.com"><div class='mobile-nav-icon'><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"> <!-- Generator: Adobe Illustrator 16.0.0, SVG Export Plug-In . SVG Version: 6.00 Build 0) --><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0px" y="0px" width="260px" height="296.5px" viewBox="0 0 260 296.5" enable-background="new 0 0 260 296.5" xml:space="preserve"> <path fill="#FFFFFF" d="M243.586,42.404h-14.448c-0.943-4.513-3.143-8.813-6.616-12.33L201.793,9.098 c-4.7-4.757-10.972-7.377-17.66-7.377c-6.578,0-12.777,2.547-17.457,7.173l-33.875,33.511H17.586c-6.6,0-12,5.399-12,12V226.28 c0,6.6,5.4,12,12,12H153.83l84.21,56.278l-27.448-56.278h32.994c6.6,0,12-5.4,12-12V54.404 C255.586,47.804,250.186,42.404,243.586,42.404z M214.662,48.045c-0.01,0.2-0.021,0.399-0.044,0.599 c-0.008,0.069-0.021,0.139-0.031,0.207c-0.046,0.345-0.113,0.688-0.196,1.026c-0.034,0.137-0.063,0.273-0.103,0.408 c-0.039,0.135-0.087,0.267-0.133,0.399c-0.051,0.151-0.102,0.302-0.16,0.45c-0.049,0.126-0.105,0.249-0.16,0.373 c-0.068,0.153-0.139,0.307-0.216,0.457c-0.059,0.116-0.12,0.23-0.184,0.345c-0.088,0.157-0.181,0.312-0.278,0.465 c-0.065,0.104-0.13,0.206-0.2,0.308c-0.115,0.168-0.239,0.33-0.366,0.492c-0.064,0.081-0.124,0.165-0.19,0.244 c-0.199,0.238-0.409,0.472-0.635,0.694L82.458,182.308l-47.932,12.871l13.427-47.74L177.223,19.561 c1.917-1.895,4.414-2.84,6.911-2.84c2.534,0,5.068,0.975,6.99,2.92l20.726,20.974c0.545,0.552,1.002,1.156,1.39,1.79 c0.574,0.938,0.975,1.951,1.206,2.993c0.004,0.021,0.01,0.04,0.014,0.06c0.049,0.226,0.086,0.453,0.119,0.682 c0.008,0.06,0.017,0.118,0.024,0.178c0.026,0.211,0.045,0.424,0.058,0.636c0.004,0.077,0.007,0.153,0.009,0.23 c0.007,0.203,0.011,0.407,0.005,0.61C214.673,47.877,214.666,47.961,214.662,48.045z"></path> </svg> </div> <span class='top-nav-link-text'>Blog</span> </a></li> <li class='nav-item active'> <a class="primary_nav_link" href="https://support.talosintelligence.com"><div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" width="26px" height="20px" viewBox="0 0 123.17 159.292"> <path d="M61.59,0,0,17.069v85.32c0,23.472,61.59,56.9,61.59,56.9s61.58-36.288,61.58-56.9V17.069Zm-.433,149.746C38.314,136.662,8.128,114.3,8.128,102.389V23.239l53.029-14.7Z" fill="#fff"></path> </svg> </div> <span class='top-nav-link-text'>Support</span> </a></li> </ul> <ul class='secondary-nav-list'> <div class='more-desktop-link'> <div class='more-link-wrapper'> <span class='more-nav-link'> <div class='desktop-nav-icon more-menu-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" width="22px" height="16px" viewBox="0 0 22 16"> <g id="menu-icon"> <path fill="#FFFFFF" d="M20.5,3h-19C0.672,3,0,2.329,0,1.5S0.672,0,1.5,0h19C21.328,0,22,0.671,22,1.5S21.328,3,20.5,3z"></path> <path fill="#FFFFFF" d="M20.5,9.5h-19C0.672,9.5,0,8.828,0,8c0-0.829,0.672-1.5,1.5-1.5h19C21.328,6.5,22,7.171,22,8 C22,8.828,21.328,9.5,20.5,9.5z"></path> <path fill="#FFFFFF" d="M20.5,16h-19C0.672,16,0,15.328,0,14.5S0.672,13,1.5,13h19c0.828,0,1.5,0.672,1.5,1.5S21.328,16,20.5,16z"></path> </g> </svg> </div> <span class='top-nav-link-text top-nav-more-text'> More </span> </span> </div> </div> <li class='nav-item more-text-link'> <div class='more-link-wrapper more-link-wrapper-mobile'> <span class='more-nav-link'> <div class='mobile-nav-icon'><!-- Generator: Adobe Illustrator 24.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) --><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0px" y="0px" viewBox="0 0 20 20" style="enable-background:new 0 0 20 20;" width="25px" height="25px" xml:space="preserve"> <style type="text/css"> .white{fill:#FFFFFF;} </style> <path class="white" d="M19.4,17.1c0,0.1-0.1,0-0.2,0c0,0-1.3-0.9-2-1.4c-0.2-0.1-0.5-0.1-0.6,0.1c-0.3,0.3-0.6,0.8-0.9,1.3 c-0.1,0.2-0.1,0.5,0.1,0.6l2,1.5c0.1,0,0,0.1,0.1,0.2c0,0.1,0,0.1-0.1,0.2c-1.2,0.5-2.6,0.2-3.5-0.7c-0.8-0.9-1-2-0.7-3.1L4.5,6.5 c-1,0.3-2.3,0-3-0.9c-0.8-0.9-1.1-1.7-1-2.7c0-0.1,0-0.1,0.1-0.2c0.1,0,0.2,0.1,0.2,0.1l2,1.5C3,4.4,3.3,4.5,3.4,4.2 c0,0,0.5-0.8,0.9-1.3c0.1-0.2,0.1-0.5-0.1-0.6L2.3,0.9c-0.1,0,0-0.1-0.1-0.3c0-0.1,0-0.1,0.1-0.2C3.5-0.1,5,0.2,5.8,1.1 c0.8,0.9,1,2,0.7,3.1l9.1,9.3c1-0.3,2.3,0,3,0.9c0.7,0.7,0.9,1.5,0.9,2.5C19.5,16.9,19.5,17,19.4,17.1z"></path> </svg> </div> <span class='top-nav-link-text top-nav-more-text'> Security Resources </span> </span> </div> <input class='sub-nav-trigger' id='security-resources-sub-trigger' type='checkbox'> <label class='sub-nav-trigger-label' for='security-resources-sub-trigger'> <div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="48.167px" height="47.75px" viewBox="0 0 48.167 47.75"> <circle opacity="0.4" fill="none" stroke="#FFFFFF" stroke-miterlimit="10" cx="24.083" cy="23.875" r="22"></circle> <g> <circle fill="#FFFFFF" cx="24.083" cy="16.068" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="23.875" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="31.682" r="2.496"></circle> </g> </svg> </div> </label> <div class='sub-nav sub-nav-multiple-list sub-nav-multiple-list-left'> <div class='sub-nav-multiple-wrapper'> <div class='sub-nav-list-top-of-mobile-wrapper'> <h1 class='sub-nav-list-header sub-nav-list-top-of-mobile'>Security Resources</h1> <ul class='sub-nav-list'> <li class='desktop-hide'> <label class='subnav-back-button' for='security-resources-sub-trigger'>BACK</label> </li> </ul> </div> <div class='sub-nav-list-item-wrapper'> <span class='sub-nav-desktop-header uppercase'>Security Resources</span> <ul class='sub-nav-list'> <li> <a href="/software"><span>Open Source Security Tools</span> </a></li> <li> <a href="/categories"><span>Intelligence Categories Reference</span> </a></li> <li> <a href="/secure-endpoint-naming"><span>Secure Endpoint Naming Reference</span> </a></li> </ul> </div> </div> </div> <div class='desktop-hide subnav-overlay'><!-- Generator: Adobe Illustrator 24.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) --><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0px" y="0px" viewBox="0 0 20 20" style="enable-background:new 0 0 20 20;" width="25px" height="25px" xml:space="preserve"> <style type="text/css"> .white{fill:#FFFFFF;} </style> <path class="white" d="M19.4,17.1c0,0.1-0.1,0-0.2,0c0,0-1.3-0.9-2-1.4c-0.2-0.1-0.5-0.1-0.6,0.1c-0.3,0.3-0.6,0.8-0.9,1.3 c-0.1,0.2-0.1,0.5,0.1,0.6l2,1.5c0.1,0,0,0.1,0.1,0.2c0,0.1,0,0.1-0.1,0.2c-1.2,0.5-2.6,0.2-3.5-0.7c-0.8-0.9-1-2-0.7-3.1L4.5,6.5 c-1,0.3-2.3,0-3-0.9c-0.8-0.9-1.1-1.7-1-2.7c0-0.1,0-0.1,0.1-0.2c0.1,0,0.2,0.1,0.2,0.1l2,1.5C3,4.4,3.3,4.5,3.4,4.2 c0,0,0.5-0.8,0.9-1.3c0.1-0.2,0.1-0.5-0.1-0.6L2.3,0.9c-0.1,0,0-0.1-0.1-0.3c0-0.1,0-0.1,0.1-0.2C3.5-0.1,5,0.2,5.8,1.1 c0.8,0.9,1,2,0.7,3.1l9.1,9.3c1-0.3,2.3,0,3,0.9c0.7,0.7,0.9,1.5,0.9,2.5C19.5,16.9,19.5,17,19.4,17.1z"></path> </svg> </div> </li> <li class='nav-item'> <div class='more-link-wrapper more-link-wrapper-mobile'> <span class='more-nav-link'> <div class='mobile-nav-icon'><!-- Generator: Adobe Illustrator 24.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) --><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0px" y="0px" viewBox="0 0 20 20" width="25px" height="25px" style="enable-background:new 0 0 20 20;" xml:space="preserve"> <style type="text/css"> .sticoncomment{fill-rule:evenodd;clip-rule:evenodd;fill:#FFFFFF;} </style> <path class="sticoncomment" d="M13.6,7.1H6.4c-0.3,0-0.6-0.3-0.6-0.6c0-0.3,0.3-0.6,0.6-0.6l7.2,0c0.3,0,0.6,0.3,0.6,0.6 C14.2,6.8,13.9,7.1,13.6,7.1L13.6,7.1z M13.6,9.4H6.4c-0.3,0-0.6-0.3-0.6-0.6s0.3-0.6,0.6-0.6l7.2,0c0.3,0,0.6,0.3,0.6,0.6 C14.2,9.2,13.9,9.4,13.6,9.4L13.6,9.4z M11.5,11.7H6.4c-0.3,0-0.6-0.3-0.6-0.6c0-0.3,0.3-0.6,0.6-0.6h5.1c0.3,0,0.6,0.3,0.6,0.6 C12.1,11.5,11.8,11.7,11.5,11.7z M15.8,3H4.2C3.5,3,3,3.5,3,4.2V17l2.8-2.3h10c0.6,0,1.2-0.5,1.2-1.2V4.2C17,3.5,16.5,3,15.8,3 L15.8,3z"></path> </svg> </div> <span class='top-nav-link-text top-nav-more-text'> Media </span> </span> </div> <input class='sub-nav-trigger' id='media-sub-trigger' type='checkbox'> <label class='sub-nav-trigger-label' for='media-sub-trigger'> <div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="48.167px" height="47.75px" viewBox="0 0 48.167 47.75"> <circle opacity="0.4" fill="none" stroke="#FFFFFF" stroke-miterlimit="10" cx="24.083" cy="23.875" r="22"></circle> <g> <circle fill="#FFFFFF" cx="24.083" cy="16.068" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="23.875" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="31.682" r="2.496"></circle> </g> </svg> </div> </label> <div class='sub-nav sub-nav-multiple-list sub-nav-multiple-list-middle'> <div class='sub-nav-multiple-wrapper'> <div class='sub-nav-list-top-of-mobile-wrapper'> <h1 class='sub-nav-list-header sub-nav-list-top-of-mobile'>Media</h1> <ul class='sub-nav-list'> <li class='desktop-hide'> <label class='subnav-back-button' for='media-sub-trigger'>BACK</label> </li> </ul> </div> <div class='sub-nav-list-item-wrapper'> <span class='sub-nav-desktop-header uppercase'>Media</span> <ul class='sub-nav-list'> <li> <a href="https://blog.talosintelligence.com"><span>Talos Intelligence Blog</span> </a></li> <li> <a href="https://blog.talosintelligence.com/category/threat-source-newsletter/"><span>Threat Source Newsletter</span> </a></li> <li> <a href="/podcasts/shows/beers_with_talos"><span>Beers with Talos Podcast</span> </a></li> <li> <a href="/podcasts/shows/talos_takes"><span>Talos Takes Podcast</span> </a></li> <li> <a target="_blank" href="https://www.youtube.com/channel/UCPZ1DtzQkStYBSG3GTNoyfg/featured"><span>Talos Videos</span> </a></li> </ul> </div> </div> </div> <div class='desktop-hide subnav-overlay'><!-- Generator: Adobe Illustrator 24.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) --><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" id="Layer_1" x="0px" y="0px" viewBox="0 0 20 20" width="25px" height="25px" style="enable-background:new 0 0 20 20;" xml:space="preserve"> <style type="text/css"> .sticoncomment{fill-rule:evenodd;clip-rule:evenodd;fill:#FFFFFF;} </style> <path class="sticoncomment" d="M13.6,7.1H6.4c-0.3,0-0.6-0.3-0.6-0.6c0-0.3,0.3-0.6,0.6-0.6l7.2,0c0.3,0,0.6,0.3,0.6,0.6 C14.2,6.8,13.9,7.1,13.6,7.1L13.6,7.1z M13.6,9.4H6.4c-0.3,0-0.6-0.3-0.6-0.6s0.3-0.6,0.6-0.6l7.2,0c0.3,0,0.6,0.3,0.6,0.6 C14.2,9.2,13.9,9.4,13.6,9.4L13.6,9.4z M11.5,11.7H6.4c-0.3,0-0.6-0.3-0.6-0.6c0-0.3,0.3-0.6,0.6-0.6h5.1c0.3,0,0.6,0.3,0.6,0.6 C12.1,11.5,11.8,11.7,11.5,11.7z M15.8,3H4.2C3.5,3,3,3.5,3,4.2V17l2.8-2.3h10c0.6,0,1.2-0.5,1.2-1.2V4.2C17,3.5,16.5,3,15.8,3 L15.8,3z"></path> </svg> </div> </li> <li class='nav-item'> <div class='more-link-wrapper more-link-wrapper-mobile'> <span class='more-nav-link'> <div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="25px" height="25px" viewBox="0 0 55 55"> <g> <g class="mobile-nav-home"> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M45.201,12.343c0.378,0.48,0.758,0.925,1.096,1.401 c2.975,4.207,4.543,8.876,4.494,14.044c-0.05,5.452-1.643,10.386-5.186,14.593c-3.484,4.133-7.929,6.73-13.182,7.895 c-6.313,1.398-12.216,0.275-17.695-3.131c-0.441-0.273-0.847-0.6-1.266-0.904c-0.11-0.078-0.208-0.174-0.337-0.287 c0.127-0.141,0.246-0.27,0.366-0.398c0.887-0.949,1.765-1.904,2.663-2.844c0.114-0.119,0.321-0.217,0.485-0.217 c3.658-0.006,7.318,0,10.975,0.008c3.458,0.006,6.913,0.02,10.369,0.02c0.957,0,1.871-0.193,2.62-0.844 c0.797-0.693,1.157-1.596,1.157-2.643c0.001-7.533,0.003-15.067-0.005-22.601c-0.002-0.309,0.088-0.524,0.3-0.743 C43.098,14.598,44.127,13.49,45.201,12.343"></path> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M41.402,8.822c-0.99,1.027-1.994,2.021-2.935,3.072 c-0.312,0.35-0.616,0.416-1.036,0.415c-6.98-0.009-13.957-0.007-20.938-0.007c-2.039,0-3.561,1.514-3.561,3.557 c0,6.504,0.002,13.008,0.006,19.512c0.002,0.973,0.011,1.943,0.004,2.914c0,0.133-0.04,0.301-0.127,0.393 c-1.069,1.162-2.15,2.314-3.229,3.469c-0.021,0.023-0.052,0.039-0.109,0.08c-0.159-0.188-0.323-0.369-0.471-0.562 c-2.535-3.348-4.119-7.102-4.605-11.268c-0.61-5.229,0.194-10.229,2.835-14.839c2.669-4.664,6.655-7.805,11.618-9.75 c3.205-1.257,6.533-1.852,9.977-1.621c4.478,0.298,8.553,1.754,12.227,4.325c0.101,0.072,0.197,0.151,0.291,0.229 C41.364,8.755,41.374,8.778,41.402,8.822"></path> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M39.799,12.47c0.873-0.911,1.749-1.829,2.676-2.797 c0.605,0.564,1.195,1.112,1.816,1.691c-0.941,0.985-1.817,1.903-2.703,2.83c-0.276-0.339-0.511-0.688-0.807-0.975 C40.492,12.941,40.145,12.728,39.799,12.47"></path> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M10.35,43.279c0.969-1.016,1.885-1.977,2.76-2.893 c0.213,0.369,0.376,0.762,0.639,1.072c0.265,0.312,0.627,0.539,0.98,0.832c-0.853,0.891-1.713,1.791-2.624,2.746 C11.513,44.445,10.939,43.869,10.35,43.279"></path> </g> </g> </svg> </div> <span class='top-nav-link-text top-nav-more-text'> Company </span> </span> </div> <input class='sub-nav-trigger' id='company-sub-trigger' type='checkbox'> <label class='sub-nav-trigger-label' for='company-sub-trigger'> <div class='mobile-nav-icon'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="48.167px" height="47.75px" viewBox="0 0 48.167 47.75"> <circle opacity="0.4" fill="none" stroke="#FFFFFF" stroke-miterlimit="10" cx="24.083" cy="23.875" r="22"></circle> <g> <circle fill="#FFFFFF" cx="24.083" cy="16.068" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="23.875" r="2.496"></circle> <circle fill="#FFFFFF" cx="24.083" cy="31.682" r="2.496"></circle> </g> </svg> </div> </label> <div class='sub-nav sub-nav-multiple-list sub-nav-multiple-list-right'> <div class='sub-nav-multiple-wrapper'> <div class='sub-nav-list-top-of-mobile-wrapper'> <h1 class='sub-nav-list-header sub-nav-list-top-of-mobile'>Company</h1> <ul class='sub-nav-list'> <li class='desktop-hide'> <label class='subnav-back-button' for='company-sub-trigger'>BACK</label> </li> </ul> </div> <div class='sub-nav-list-item-wrapper'> <span class='sub-nav-desktop-header uppercase'>Company</span> <ul class='sub-nav-list'> <li> <a href="/about"><span>About Talos</span> </a></li> <li> <a href="/careers"><span>Careers</span> </a></li> </ul> </div> </div> </div> <div class='desktop-hide subnav-overlay'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="25px" height="25px" viewBox="0 0 55 55"> <g> <g class="mobile-nav-home"> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M45.201,12.343c0.378,0.48,0.758,0.925,1.096,1.401 c2.975,4.207,4.543,8.876,4.494,14.044c-0.05,5.452-1.643,10.386-5.186,14.593c-3.484,4.133-7.929,6.73-13.182,7.895 c-6.313,1.398-12.216,0.275-17.695-3.131c-0.441-0.273-0.847-0.6-1.266-0.904c-0.11-0.078-0.208-0.174-0.337-0.287 c0.127-0.141,0.246-0.27,0.366-0.398c0.887-0.949,1.765-1.904,2.663-2.844c0.114-0.119,0.321-0.217,0.485-0.217 c3.658-0.006,7.318,0,10.975,0.008c3.458,0.006,6.913,0.02,10.369,0.02c0.957,0,1.871-0.193,2.62-0.844 c0.797-0.693,1.157-1.596,1.157-2.643c0.001-7.533,0.003-15.067-0.005-22.601c-0.002-0.309,0.088-0.524,0.3-0.743 C43.098,14.598,44.127,13.49,45.201,12.343"></path> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M41.402,8.822c-0.99,1.027-1.994,2.021-2.935,3.072 c-0.312,0.35-0.616,0.416-1.036,0.415c-6.98-0.009-13.957-0.007-20.938-0.007c-2.039,0-3.561,1.514-3.561,3.557 c0,6.504,0.002,13.008,0.006,19.512c0.002,0.973,0.011,1.943,0.004,2.914c0,0.133-0.04,0.301-0.127,0.393 c-1.069,1.162-2.15,2.314-3.229,3.469c-0.021,0.023-0.052,0.039-0.109,0.08c-0.159-0.188-0.323-0.369-0.471-0.562 c-2.535-3.348-4.119-7.102-4.605-11.268c-0.61-5.229,0.194-10.229,2.835-14.839c2.669-4.664,6.655-7.805,11.618-9.75 c3.205-1.257,6.533-1.852,9.977-1.621c4.478,0.298,8.553,1.754,12.227,4.325c0.101,0.072,0.197,0.151,0.291,0.229 C41.364,8.755,41.374,8.778,41.402,8.822"></path> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M39.799,12.47c0.873-0.911,1.749-1.829,2.676-2.797 c0.605,0.564,1.195,1.112,1.816,1.691c-0.941,0.985-1.817,1.903-2.703,2.83c-0.276-0.339-0.511-0.688-0.807-0.975 C40.492,12.941,40.145,12.728,39.799,12.47"></path> <path fill-rule="evenodd" clip-rule="evenodd" fill="#FFFFFF" d="M10.35,43.279c0.969-1.016,1.885-1.977,2.76-2.893 c0.213,0.369,0.376,0.762,0.639,1.072c0.265,0.312,0.627,0.539,0.98,0.832c-0.853,0.891-1.713,1.791-2.624,2.746 C11.513,44.445,10.939,43.869,10.35,43.279"></path> </g> </g> </svg> </div> </li> </ul> <ul class='top-nav-list-buttons'> <li class='nav-item'> <div id='top-nav-under-attack-button-wrapper'> <div id='top-nav-under-attack-button'> <span id='top-nav-under-attack-icon'></span> <p class='uppercase' id='top-nav-under-attack-icon-text'>Under Attack?</p> </div> </div> </li> <li class='acct_links desktop-hide'> <a class="login-button" href="/users/auth/saml">Cisco Login </a></li> </ul> </div> </div> </nav> <input class='nav-trigger' id='nav-trigger' type='checkbox'> <label for='nav-trigger'><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" width="22px" height="16px" viewBox="0 0 22 16"> <g id="menu-icon"> <path fill="#FFFFFF" d="M20.5,3h-19C0.672,3,0,2.329,0,1.5S0.672,0,1.5,0h19C21.328,0,22,0.671,22,1.5S21.328,3,20.5,3z"></path> <path fill="#FFFFFF" d="M20.5,9.5h-19C0.672,9.5,0,8.828,0,8c0-0.829,0.672-1.5,1.5-1.5h19C21.328,6.5,22,7.171,22,8 C22,8.828,21.328,9.5,20.5,9.5z"></path> <path fill="#FFFFFF" d="M20.5,16h-19C0.672,16,0,15.328,0,14.5S0.672,13,1.5,13h19c0.828,0,1.5,0.672,1.5,1.5S21.328,16,20.5,16z"></path> </g> </svg> </label> <div class='modal-wrapper'> <div class='modal' id='ir-contact-modal' role='dialog' tabindex='-1'> <div class='modal-dialog' role='document'> <div class='modal-content'> <div class='modal-header'> <h2 class='modal-email-header'>Contact Cisco Talos Incident Response</h2> <button aria-label='Close' class='close' data-bs-dismiss='modal' id='closeFormIcon' type='button'> <span aria-hidden='true'>×</span> </button> </div> <div class='modal-body'> <div class='modal-response-section hidden' id='ir-contact-modal-response-section'> <div class='modal-response-text-wrapper' id='ir-contact-modal-response-text-wrapper'> <div class='modal-response-icon' id='ir-contact-modal-response-icon'></div> <div class='modal-response-text' id='ir-contact-modal-response-text'></div> </div> <div class='completed-close-button-wrapper'> <button class='secondary-button completed-close-button hidden' data-bs-dismiss='modal'>Close</button> </div> </div> <div class='modal-body-form-wrapper' id='ir-contact-modal-form-wrapper'> <div class='emergency-only-incident-response' id='emergency-only-warning-modal'> <div class='emergency-only-incident-response-wrapper'> <div class='incident-response-warning-icon'></div> <span class='emergency-note'>This form is for Incident Response service inquiries only, <span class="extra-bold">including emergency network security needs</span>.</span> </div> </div> <p id='ir-contact-form-subhead'> <span>For reputation or categorization inquiries, visit the <a href="/support">Talos Support site</a>.</span> <span class='ir-contact-form-subhead-note'>For emergency DDoS mitigation assistance, please contact the <a href="https://www.cisco.com/c/en/us/products/collateral/security/ddos-emergency-attack-mitigation-aag.pdf" target="_blank">Cisco Secure DDoS Protection Team</a>.</span> </p> <form id="ir-contact-form" action="/" accept-charset="UTF-8" data-remote="true" method="post"><input type="hidden" name="authenticity_token" value="DZd6AVl44y3/VrGaRkxAQ55hb7TIC1kzh7iBgdbVfYMYlw3btcIycNyEZz26OqB0q7JZdTo1RQk6Ohdk5DCgdg==" autocomplete="off" /> <div class='row'> <div class='col-6'> <label class="control-label" for="ctir_user_name">Name</label> <input required="required" type="text" name="ctir_user[name]" id="ctir_user_name" /> </div> <div class='col-6'> <label class="control-label" for="company">Company (optional)</label> <input type="text" name="ctir_user[company]" id="ctir_user_company" /> </div> </div> <div class='row'> <div class='col-6'> <label class="control-label" type="email" for="ctir_user_email">Email address</label> <input id="email_input" required="required" type="email" name="ctir_user[email]" /> </div> <div class='col-6'> <label class="control-label" for="phone_number">Phone number</label> <input id="phone_input" required="required" type="tel" name="ctir_user[phone_number]" /> </div> </div> <div class='row'> <div class='col-4'> <label class='radio-selection-label'>Preferred communication:</label> </div> <div class='col-3'> <input type="radio" name="contact_method" id="contact_method_email_ir-contact-form" value="email" checked="checked" /> <label class="form-radio-label" for="contact_method_email_ir-contact-form">Email</label> </div> <div class='col-3'> <input type="radio" name="contact_method" id="contact_method_phone_ir-contact-form" value="phone" /> <label class="form-radio-label" for="contact_method_phone_ir-contact-form">Phone</label> </div> </div> <div class='row extra-padding'> <div class='col-12'> <label class="control-label" for="service">What Incident Response Service are you interested in?</label> <select name="service" id="service" class="col-sm-12 form-control ir-contact-modal__selection"><option selected="selected" value="general">General Talos IR services and retainer information</option> <option value="emergency">Emergency Response</option> <option value="plans">IR Plan</option> <option value="playbooks">IR Playbooks</option> <option value="readiness">IR Readiness Assessment</option> <option value="tabletop">Tabletop Exercises</option> <option value="compromise">Compromise Assessment</option> <option value="hunting">Threat Hunting</option> <option value="cyberrange">Cyber Range Training</option> <option value="intel">Intelligence on Demand</option></select> </div> </div> <div class='row extra-padding'> <div class='col-12'> <label class="control-label" for="details">Please provide as much detail as possible so we can best address your needs</label> <textarea name="details" id="details" required="required"> </textarea> </div> </div> <div class='row form-footer-row'> <div class='col-12 emergency-checkbox-wrapper'> <input id='emergency-checkbox' required='required' type='checkbox'> <label class='col-emergency-label' for='emergency-checkbox'>I acknowledge that this is an inquiry for Incident Response services and that any other use of this form will not receive a response.</label> </div> <div class='col-12 emergency-checkbox-wrapper ir-recaptcha-wrapper'> <script src="https://www.recaptcha.net/recaptcha/api.js" async defer ></script> <div data-sitekey="6LfvKEIUAAAAAJhtwenMMoXIk5L2-G7er24RWKmR" class="g-recaptcha "></div> <noscript> <div> <div style="width: 302px; height: 422px; position: relative;"> <div style="width: 302px; height: 422px; position: absolute;"> <iframe src="https://www.recaptcha.net/recaptcha/api/fallback?k=6LfvKEIUAAAAAJhtwenMMoXIk5L2-G7er24RWKmR" name="ReCAPTCHA" style="width: 302px; height: 422px; border-style: none; border: 0; overflow: hidden;"> </iframe> </div> </div> <div style="width: 300px; height: 60px; border-style: none; bottom: 12px; left: 25px; margin: 0px; padding: 0px; right: 25px; background: #f9f9f9; border: 1px solid #c1c1c1; border-radius: 3px;"> <textarea id="g-recaptcha-response" name="g-recaptcha-response" class="g-recaptcha-response" style="width: 250px; height: 40px; border: 1px solid #c1c1c1; margin: 10px 25px; padding: 0px; resize: none;"> </textarea> </div> </div> </noscript> </div> <div class='col-12'> <button class='primary-button submit disabled' disabled='true' id='submit-tir-email' type='submit'>Send Email</button> <button class='secondary-button cancel' data-bs-dismiss='modal' id='closeFormButton'>Cancel</button> </div> </div> </form> </div> </div> </div> </div> </div> </div> <div id="page_wrapper"> <div class="mobile-page-header" title="Cisco Talos Intelligence"> </div> <small> </small> <div class='container-fluid ir'> <div class='container-fluid' id='carousel_homepage_wrapper'> <div class='container-fluid' id='carousel_homepage_slide_wrapper'> <div class='carousel slide' data-bs-interval='false' data-bs-ride='false' id='carousel_homepage'> <div class='carousel-indicators'> <button aria-current='true' aria-label='Slide 0' class='active' data-bs-slide-to='0' data-bs-target='#carousel_homepage' type='button'></button> <button aria-label='Slide 1' data-bs-slide-to='1' data-bs-target='#carousel_homepage' type='button'></button> <button aria-label='Slide 2' data-bs-slide-to='2' data-bs-target='#carousel_homepage' type='button'></button> <button aria-label='Slide 3' data-bs-slide-to='3' data-bs-target='#carousel_homepage' type='button'></button> </div> <div class='carousel-inner'> <div class='carousel-item panel_tir align-right active' style=''> <div class='carousel-template-bg'> <div class='carousel-caption'> <h2> Every second matters </h2> <p>We provide best-in-class, global incident response and proactive services, powered by Talos threat intelligence.</p> <div class='carousel-button-wrapper'> <a class='btn btn-call-to-action' href='/incident_response/services'>Learn More</a> <a class='btn btn-call-to-action btn-call-to-action-secondary' href='https://talosintelligence.com/resources/72'> Download Datasheet </a> </div> </div> </div> </div> <div class='carousel-item panel_angle align-left ' style='background-image: url('https://talosintelligence-cms.s3.amazonaws.com/recurring_carousel_quarterly_trends_b6e7d6b5cf.jpg?AWSAccessKeyId=AKIAU7AK5ITMHFVJUAQ5&Expires=1739712281&Signature=DEFHRSuhcm77UZL2vWtzwTIegn8%3D')'> <div class='carousel-template-bg'> <div class='carousel-caption'> <h2> Exploitation of public-facing applications spike </h2> <p>The new Cisco Talos Incident Response Quarterly Trends report explores how threat actors increasingly deployed web shells against vulnerable web applications. Plus, get all the latest insights into attacker trends in Q4 2024.</p> <a class='btn btn-call-to-action' href='https://blog.talosintelligence.com/talos-ir-trends-q4-2024/'> Get the report </a> </div> </div> </div> <div class='carousel-item panel_pixel align-right ' style='background-image: url('https://talosintelligence-cms.s3.amazonaws.com/IR_overview_caroursel_22b2a4424a.jpg?AWSAccessKeyId=AKIAU7AK5ITMHFVJUAQ5&Expires=1739712281&Signature=8v5jtMjXt%2Fn2DmVvWq85%2Fh7x5SY%3D')'> <div class='carousel-template-bg'> <div class='carousel-caption'> <h2> Video: Overview of Cisco Talos Incident Response </h2> <p>This video showcases the Cisco Talos Incident Response services and ongoing value they provide to customers across the globe. Partner with us for all of your incident response needs.</p> <a class='btn btn-call-to-action' href='https://www.youtube.com/watch?v=h5px_dsoyi0'> Watch Video </a> </div> </div> </div> <div class='carousel-item panel_angle align-left ' style='background-image: url('https://talosintelligence-cms.s3.amazonaws.com/TTP_carousel_ce6ea83634.jpg?AWSAccessKeyId=AKIAU7AK5ITMHFVJUAQ5&Expires=1739712281&Signature=zO8LVMrcaR1%2BttS8wwoakypfOi0%3D')'> <div class='carousel-template-bg'> <div class='carousel-caption'> <h2> Video: The biggest takeaways from the Talos IR report </h2> <p>In this episode of The Talos Threat Perspective, the team discuss new ransomware variants, and the growing trend of threat actors tampering with security tools.</p> <a class='btn btn-call-to-action' href='https://www.youtube.com/watch?v=R4iYhzZijQE'> Watch Video </a> </div> </div> </div> </div> <button class='carousel-control-prev' data-bs-slide='prev' data-bs-target='#carousel_homepage' type='button'> <span aria-hidden='true' class='carousel-control-prev-icon'></span> <span class='visually-hidden'>Previous</span> </button> <button class='carousel-control-next' data-bs-slide='next' data-bs-target='#carousel_homepage' type='button'> <span aria-hidden='true' class='carousel-control-next-icon'></span> <span class='visually-hidden'>Next</span> </button> </div> </div> </div> <div class='container-fluid blade' id='ir-news-blade'> <div class='ir-news-wrapper'> <div class='ir-news-blocks-wrapper'> <div class='ir-blog-preview-wrapper'> <div class='ir-news-header-wrapper'> <h5 class='ir-news-title'>Talos IR trends Q4 2024: Web shell usage and exploitation of public-facing applications spike</h5> </div> <p> This new report from Cisco Talos Incident Response explores how threat actors increasingly deployed web shells against vulnerable web applications, and exploited vulnerable or unpatched public-facing applications to gain initial access. <a class="blog-link" id="ir-news-contact" target="_blank" href="https://blog.talosintelligence.com/talos-ir-trends-q4-2024/">Learn More </a></p> </div> </div> <div class='ir-news-blocks-wrapper'> <div class='ir-blog-preview-wrapper'> <div class='ir-news-header-wrapper'> <h5 class='ir-news-title'>Unwrapping the emerging Interlock ransomware attack</h5> </div> <p> Cisco Talos Incident Response (Talos IR) recently observed an attacker conducting big-game hunting and double extortion attacks using the relatively new Interlock ransomware. <a class="blog-link" id="ir-news-contact" target="_blank" href="https://blog.talosintelligence.com/emerging-interlock-ransomware/">Learn More </a></p> </div> </div> <div class='ir-news-blocks-wrapper'> <div class='ir-blog-preview-wrapper'> <div class='ir-news-header-wrapper'> <h5 class='ir-news-title'>Talos IR trends Q3 2024: Identity-based operations loom large</h5> </div> <p> Credential theft was the main goal in 25% of incidents last quarter, and new ransomware variants made their appearance - read more about the top trends, TTPs, and security weaknesses that facilitated adversary actions. <a class="blog-link" id="ir-news-contact" target="_blank" href="https://blog.talosintelligence.com/incident-response-trends-q3-2024/">Learn More </a></p> </div> </div> </div> </div> <div class='video-active container-fluid blade' id='services-blade'> <div class='services-container'> <div class='services-content'> <div class='russian-doll-container'> <h3 class='video-header'> <a href='/incident_response/services'>Talos Incident Response Services</a> </h3> <div class='responsive-iframe-container'> <iframe allow='accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share' allowfullscreen frameborder='0' referrerpolicy='strict-origin-when-cross-origin' src='https://www.youtube.com/embed/_cfG1Q46fto' title='Video test'></iframe> </div> </div> </div> <div class='services-content'> <h3 aria-hidden class='secondary-video-header'> <a href='/incident_response/services'> Talos Incident Response Services </a> </h3> <div> <p> The Talos IR Retainer service provides emergency response services to support you through active incidents and proactive services to assess, strengthen and evolve your incident response readiness. <a class="blog-link" href="/incident_response/services">Learn more </a></p> <p class='extra-bold'> Our team is equipped and ready to help you meet your goals. </p> </div> <div class='services-lists'> <h4 class='highlight-orange'>Reactive Services</h4> <ul> <li>Emergency Incident Response</li> <li>Emerging and relevant threat information</li> </ul> <h4 class='highlight-orange'>Proactive Services</h4> <ul> <li>Assessment of current environment vulnerabilities and IR preparedness</li> <li>Recommendations to prevent possible incidents</li> <li>Detailed playbooks to follow in case of an incident</li> <li>Training and simulations</li> </ul> </div> </div> </div> </div> <div class='container-fluid blade alt-blade' id='differentiator-blade'> <h3>Intelligence is the root of our approach</h3> <div class='background-fade'></div> <div class='differentiator-content'> <div class='lottie-player lottie' id='ir_cycle_animation' src='/assets/Lottie/IR-Cycle-layers.json'></div> </div> <div class='differentiator-content'> <p>We leverage proven incident response processes and methodologies to respond to emergencies as they happen, and prepare your organization for when an incident occurs.</p> </div> </div> <div class='container-fluid blade' id='contact-blade'> <div class='ir-service-contact-wrapper'> <div class='left-bg'></div> <div class='right-bg'></div> <div class='contact-content'> <h3>Fortify Your Security Resilience</h3> <p>For questions regarding our Talos IR retainer subscription or to sign up:</p> <button class='primary-button' data-bs-target='#ir-contact-modal' data-bs-toggle='modal'>Connect with us</button> </div> </div> </div> </div> <script> //<![CDATA[ window.ypk = "AIzaSyAh1sEji54mqZCZO0Z5E41f48IzhgHxQmo" //]]> </script> </div> <footer id='footer'> <div class='row footer_nav_wrapper'> <div class='col-xl-10 col-12'> <div class='multi-col-list-wrapper'> <ul class='footer-parent-list'> <li class='footer-links-group'> <ul> <li> <h6><a href="/reputation">Intelligence Center</a></h6> </li> <li><a href="/reputation_center">Intelligence Search</a></li> <li><a href="/reputation_center/email_rep">Email & Spam Trends</a></li> </ul> </li> <li class='footer-links-group'> <ul> <li> <h6><a href="/vulnerability_info">Vulnerability Research</a></h6> </li> <li><a href="/vulnerability_reports">Vulnerability Reports</a></li> <li><a href="/ms_advisories">Microsoft Advisories</a></li> </ul> </li> <li class='footer-links-group'> <ul> <li> <h6><a href="/incident_response">Incident Response</a></h6> </li> <li><a href="/incident_response/services#reactive-services">Reactive Services</a></li> <li><a href="/incident_response/services#proactive-services">Proactive Services</a></li> <li> <a href='' id='emergency_report_modal'>Emergency Support</a> </li> </ul> </li> <li class='footer-links-group'> <ul> <li> <h6>Security Resources</h6> </li> <li><a href="/software">Open Source Security Tools</a></li> <li><a href="/categories">Intelligence Categories Reference</a></li> <li><a href="/secure-endpoint-naming">Secure Endpoint Naming Reference</a></li> </ul> </li> <li class='footer-links-group'> <ul> <li> <h6>Media</h6> </li> <li><a href="https://blog.talosintelligence.com">Talos Intelligence Blog</a></li> <li><a href="https://blog.talosintelligence.com/category/threat-source-newsletter/">Threat Source Newsletter</a></li> <li><a href="/podcasts/shows/beers_with_talos">Beers with Talos Podcast</a></li> <li><a href="/podcasts/shows/talos_takes">Talos Takes Podcast</a></li> <li><a target="_blank" href="https://www.youtube.com/channel/UCPZ1DtzQkStYBSG3GTNoyfg/featured">Talos Videos</a></li> </ul> </li> <li class='footer-links-group'> <ul> <li> <h6>Support</h6> </li> <li><a href="https://support.talosintelligence.com">Support Documentation</a></li> </ul> </li> <li class='footer-links-group'> <ul> <li> <h6>Company</h6> </li> <li><a href="/about">About Talos</a></li> <li><a href="/careers">Careers</a></li> <li><a target="_blank" href="https://www.cisco.com/c/en/us/products/security/product-listing.html">Cisco Security</a></li> </ul> </li> </ul> </div> </div> <div class='col-xl-2 col-12 connect_social'> <div class='connect-footer-section-wrapper'> <h6>Follow us</h6> <ul> <li> <a target="_blank" href="https://x.com/talossecurity"><div class='footer-media-icon' id='footer-media-icon-x'></div> </a></li> <li> <a target="_blank" href="https://www.youtube.com/channel/UCPZ1DtzQkStYBSG3GTNoyfg/featured"><div class='footer-media-icon' id='footer-media-icon-youtube'></div> </a></li> <li> <a target="_blank" href="https://www.linkedin.com/company/cisco-talos-intelligence-group/"><div class='footer-media-icon' id='footer-media-icon-linkedin'></div> </a></li> </ul> </div> </div> </div> <div class='row'> <div class='col-12 footer_corporate'> <a target="_blank" href="http://tools.cisco.com/security/center/home.x"><img alt="Cisco" src="/assets/logo_cisco_white-d87b7f7d3152ad412e48aad924a972cc5b802b7a53cb56b0792a4456c9b7b3a5.svg" /> </a><p class='copyright'> © 2025 Cisco Systems, Inc. and/or its affiliates. All rights reserved. View our <a target="_blank" class="underline" href="http://www.cisco.com/web/siteassets/legal/privacy_full.html">Privacy Policy.</a> </p> </div> </div> </footer> <div id="nav_page_layer"></div> <!-- Twitter universal website tag code --> <script> !function(e,t,n,s,u,a){e.twq||(s=e.twq=function(){s.exe?s.exe.apply(s,arguments):s.queue.push(arguments); },s.version='1.1',s.queue=[],u=t.createElement(n),u.async=!0,u.src='//static.ads-twitter.com/uwt.js', a=t.getElementsByTagName(n)[0],a.parentNode.insertBefore(u,a))}(window,document,'script'); // Insert Twitter Pixel ID and Standard Event data below twq('init','nzhct'); twq('track','PageView'); </script> <!-- End Twitter universal website tag code --> <div id="toast-container" aria-live="polite" aria-atomic="true" class="position-fixed bottom-0 end-0"> </div> </body> </html>