
← Back to Labs
← Volver a Labs
Medium
Bypass, Campaign
Defense Evasion
EDR, Sysmon, Windows
When Forensics Becomes Offensive: Abuse of FTK Imager in the STAC3725 Tradecraft
STAC3725 campaign leveraging FTK Imager abuse to evade defenses, highlighting a stealthy technique repurposing forensic tools for low-noise persistence in pre-ransomware operations, once again weaponizing trusted investigative software.



