Keynote | Adapting Tradecraft: Examining Ransomware Attacks in 2024 - Insights from The DFIR Report

Keynote | Adapting Tradecraft: Examining Ransomware Attacks in 2024 - Insights from The DFIR Report

Source: YouTube · SANS Digital Forensics and Incident Response · published Jun 26, 2025 · 40:48

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Volunteer analysts from the DFIO report present key trends in ransomware attacks over the past year, noting that despite improved detection and law enforcement efforts, threat actors continue to successfully evolve their tradecraft 0:04-0:31.

Key Takeaways:
• Ransomware attacks remain highly persistent, continuing to succeed despite advancements in detection, response capabilities, and law enforcement actions 0:23-0:31.
• Threat actors have adapted to these defensive improvements by actively evolving their operational tradecraft 0:34-0:41.
• The analysis focuses on the 2024 to early 2025 timeframe, specifically highlighting how attacker tooling and lateral movement techniques have changed 0:44-1:00.

Understanding these evolving tactics is crucial for defenders to anticipate new methods of lateral movement and tool deployment in the ongoing ransomware landscape.

Sources:

  • 0:04-0:12 Introduction of speakers as volunteer analysts for the DFIO report
  • 0:23-0:31 The ongoing persistence of ransomware despite defensive improvements
  • 0:34-0:41 The evolution of threat actor tradecraft
  • 0:44-1:00 Focus on 2024-2025 attacker tooling and lateral movement trends

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Ryan, it's great to be back at the ranchware summit. Um, so both me and my colleague Angelo were volunteer analyst for the DFIO report. So today we're going to be discussing some of the uh key trends and develop developments in ransomware attacks over the last year. Um so just to know that ransomware attacks are still ongoing um despite improvements in detections and response and actions by law and enforcement. So there has been changes over the years. Um the threat actors have evolved their trade craft. Um so that's what we're going to be looking at today. So we'll look at ransomware attacks in the last 12 months. So around the 2024 to the start of this year. So we're going to be looking more at the attacker tooling and how these have evolved over the time and then we'll cover lateral mov…