Hermes CTI

โ† Back to canonical report

Remediation

Gootloader campaign uses SEO poisoning, Cobalt Strike, and SystemBC

Immediate Containment

! If authorized telemetry confirms matching activity, contain affected endpoints and preserve volatile evidence before cleanup.

Exposure Reduction & Patching

๐Ÿ›ก๏ธ Avoid exposing RDP, WinRM, SMB administration, and management interfaces directly to the internet; restrict by network policy and MFA where supported.

๐Ÿ“ฆ Apply current supported Windows and security-product updates; verify Defender and logging protections remain enabled.

Configuration & Credentials

โš™๏ธ Enable PowerShell script-block and process-creation auditing, scheduled-task and registry auditing, and restrict unnecessary remote service/WMI use.

๐Ÿ”‘ Review and rotate credentials only when authorized evidence indicates credential access or compromise; pay particular attention to privileged accounts used over RDP.

Evidence Preservation

๐Ÿ“ Preserve scripts, registry/task exports, process and network telemetry, and UTC timestamps before eradication.

Verification & Rollback

โœ“ Confirm telemetry, endpoint controls, RDP/WinRM restrictions, and detections are functioning after changes.

โ†ฉ๏ธ Rollback: Use approved change-control rollback if a defensive control disrupts required administration.