Back to Intel

Intel Node

From the field to the report and back again: How incident responders can use the Year in Review

highransomware2026-04-09T10:00:03+00:00source excerpt
ransomwareexploitationtradecraftwindowsidentityemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

The Year in Review distills Talos IR's observations into structured intelligence, but defenders should also be feeding this report back into their own preparation cycles. Here's how.

Every year, Cisco Talos publishes  Year in Review , a comprehensive look at the previous year’s threat landscape.  It’s drawn from an enormous volume of telemetry, such as endpoint detections, network traffic, email data, and boots-on-the-ground  Cisco Talos Incident   Response (Talos   IR)   engagements .

  As incident responders, we see threats mid-detonation in the wreckage of an Active Directory environment, or in the lateral movement artifacts left behind by an affiliate who got in using nothing more than a valid account. The Year in Review distills those raw observations into structured intelligence, but that intelligence loop works both ways.

Read Original Source