
Threat Hunting Case Study: FileFix
FileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.

A lot has been said about threat hunting, by a lot of people. They'll tell you how difficult it is, what products you should use, how to automate the pain away, and how you should've been doing this all along. But here's the thing...you have been doing it all along.
Watch the recording of the
Black Hat
Webcast Series below to listen to our speakers as they present the need to know information on practical threat hunting.
Key takeaways:
video-embedTo watch more webcasts with Cyborg, check out our Threat Hunting Virtual Launch Event, focusing on threat intelligence and cyber threat emulation.

FileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.

Initial access brokers sell information about or access to compromised computers. Here's how to threat hunt for a known attack behavior involving PowerShell that's used by a prolific initial access broker.

In July 2025 threat actors exploited zero-day vulnerabilities in on-premises Microsoft SharePoint servers in an incident known as ToolShell. In this case study, we conduct a threat hunt for ToolShell-related activity.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.