Blog:

On 2026-07-30
by Kynan Jones, Incident Responder @ Airbus Protect
Cybersecurity

What the Shell? Accelerating Incident Response: Letting the Malware do the work for you

What the Shell? Accelerating Incident Response: Letting the Malware do the work for you
Intrusion Context Last month, Airbus Protect’s CSIRT responded to an intrusion targeting a vulnerable, internet-facing Windows Server. What began as typical automated scanning quickly transitioned into a targeted attack utilising tools such as SQLMap and vulnerability scanners. By leveraging a flurry of SQL injection attacks, the threat actor successfully enabled xp_cmdshell which facilitated remote code [...]
  • Share

Discover all the latest releases

Women in stem - pip Cybersecurity

Women in STEM: Phillipa Phipps, Cybersecurity Consultant

Phillipa Phipps is a Cybersecurity Consultant at Airbus Protect. She didn’t take the traditional route into a cybersecurity career. But that just makes her journey more interesting! Find out more in this interview.

Read more
experts working in a SOC Cybersecurity

How to provide Cyber Threat Intelligence in the frame of a modern SOC?

Find out how to use CTI as an Operational Support (part 1) Introduction to Cyber Threat Intelligence Cyber Threat Intelligence is a discipline of Intelligence applied to the cyber field. According to Kent’s Analytic Doctrine[1], the role of (Cyber) Intelligence Analysts is to provide “information and insights to policy decision-makers and action-takers”. In the context […]

Read more
Star Wars Day with Airbus Protect Sustainability

Star Wars Day 2023 – Airbus Protect’s challenge

For Star Wars Day, we invited employees of Airbus Protect to invent a new and sustainable mode of transportation in the Star Wars Universe. Here are the winning answers from our contest: ANSWER 1: 3 options for all types of travel by Leo Picou I’ll start by splitting the type of trip into three categories […]

Read more
man search on Internet cybersecurity information Cybersecurity

Cybersecurity jargon busting: MDR, SOC, EDR, XDR, SOAR and SIEM

MDR, SOC, EDR, XDR, SOAR and SIEM, what does it all mean? In cyber-security, we’re notorious for using an abundance of two, three and even four-word acronyms. If you’re new to the space, these can be confusing, to say the least. To make things a little easier, we’ve created this guide! It explains some of [...]

Read more
AD Canary part 3 Cybersecurity

Active Directory: A canary under your hat part 3

Foreword: This three-part blog article series focuses on some research work on how to detect effectively Active Directory enumeration in a SOC environment. To help you through this quite long journey, grab a cup of hot beverage of your liking, and use this short reference: Part 1: about detecting AD enumeration This first part explains [...]

Read more