BRICKSTORM: KQL Detections for vSphere Backdoor Activity
BRICKSTORM is a Go-based backdoor attributed to UNC5221 / Warp Panda targeting VMware vSphere infrastructure. Operating beneath the guest OS layer, it exploits the EDR visibility gap on virtualisation control planes. This post covers 8 KQL detections spanning initial access through to C2 and tamper detection.
Read more →