<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #TTPs</title><description>Cybersecurity articles tagged #TTPs on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Proactive Ransomware Defense: Leveraging Threat Intelligence</title><link>https://runtimerebel.com/blog/proactive-ransomware-defense-leveraging-threat-intelligence</link><guid isPermaLink="true">https://runtimerebel.com/blog/proactive-ransomware-defense-leveraging-threat-intelligence</guid><description>Learn how external threat intelligence enables early detection and disruption of ransomware attacks, moving beyond reactive, post-encryption defense.</description><pubDate>Thu, 01 Oct 2026 15:07:52 GMT</pubDate><category>Ransomware</category><category>Threat Intelligence</category><category>Initial Access</category><category>TTPs</category><category>IOCs</category></item><item><title>AI-Driven Attacks Accelerate Lateral Movement to Minutes</title><link>https://runtimerebel.com/blog/ai-driven-attacks-accelerate-lateral-movement-to-minutes</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-attacks-accelerate-lateral-movement-to-minutes</guid><description>AI-driven attacks leveraging models like Mythos dramatically accelerate TTPs, enabling lateral movement in minutes. Learn how to adapt defenses against this rapid threat.</description><pubDate>Thu, 09 Jul 2026 15:13:09 GMT</pubDate><category>AI Attacks</category><category>Mythos</category><category>Rapid Lateral Movement</category><category>Threat Acceleration</category><category>Cybersecurity Defense</category><category>TTPs</category></item><item><title>BRICKSTORM Malware: Hardening vSphere &amp; VCSA Against Advanced Threats</title><link>https://runtimerebel.com/blog/brickstorm-malware-hardening-vsphere-vcsa-against-advanced-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/brickstorm-malware-hardening-vsphere-vcsa-against-advanced-threats</guid><description>Defend VMware vSphere and VCSA against BRICKSTORM malware. Learn hardening strategies, identity management, Zero Trust networking, and advanced logging to thwart…</description><pubDate>Thu, 02 Apr 2026 16:29:31 GMT</pubDate><category>BRICKSTORM</category><category>vSphere</category><category>VCSA</category><category>ESXi</category><category>VMware</category><category>Photon OS</category><category>Hardening</category><category>Virtualization</category><category>TTPs</category><category>Ransomware</category><category>Espionage</category><category>CVE-2021-21972</category><category>Mandiant</category></item><item><title>Fileless Malware Registry Persistence Techniques Exposed</title><link>https://runtimerebel.com/blog/fileless-malware-registry-persistence-techniques-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/fileless-malware-registry-persistence-techniques-exposed</guid><description>Analyzes how fileless malware leverages the Windows registry for persistence, minimizing filesystem footprint and complicating traditional detection.</description><pubDate>Wed, 01 Apr 2026 12:30:01 GMT</pubDate><category>Fileless Malware</category><category>Registry Persistence</category><category>TTPs</category><category>Malware Analysis</category><category>Detection</category><category>Windows Registry</category></item><item><title>Application Control Bypass for Data Exfiltration: A Persistent Threat</title><link>https://runtimerebel.com/blog/application-control-bypass-for-data-exfiltration-a-persistent-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/application-control-bypass-for-data-exfiltration-a-persistent-threat</guid><description>Analyze methods for bypassing application control to exfiltrate sensitive data. Understand the risks and implement effective mitigations against these advanced TTPs.</description><pubDate>Tue, 31 Mar 2026 08:33:22 GMT</pubDate><category>Data Exfiltration</category><category>Application Control Bypass</category><category>TTPs</category><category>Egress Filtering</category><category>Incident Response</category><category>Information Security</category></item><item><title>Beast Gang OpSec Fail: Ransomware Server Exposes TTPs</title><link>https://runtimerebel.com/blog/beast-gang-opsec-fail-ransomware-server-exposes-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/beast-gang-opsec-fail-ransomware-server-exposes-ttps</guid><description>Beast Gang&apos;s OpSec failure exposes their cloud ransomware server, revealing aggressive tactics against network backups. Defenders gain insight into their TTPs.</description><pubDate>Fri, 20 Mar 2026 20:12:37 GMT</pubDate><category>Beast Gang</category><category>Ransomware</category><category>OpSec Failure</category><category>Backup Attacks</category><category>TTPs</category><category>Cloud Security</category></item><item><title>Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges</title><link>https://runtimerebel.com/blog/ransomware-ttps-shift-from-cobalt-strike-to-native-tools-data-theft-surges</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-ttps-shift-from-cobalt-strike-to-native-tools-data-theft-surges</guid><description>Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.</description><pubDate>Wed, 18 Mar 2026 00:37:35 GMT</pubDate><category>Ransomware</category><category>TTPs</category><category>Cobalt Strike</category><category>Data Theft</category><category>Native Windows Tools</category><category>Post Exploitation</category></item><item><title>GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally</title><link>https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</link><guid isPermaLink="true">https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</guid><description>Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.</description><pubDate>Wed, 25 Feb 2026 16:34:59 GMT</pubDate><category>UNC2814</category><category>GRIDTIDE</category><category>PRC Nexus</category><category>Cyber Espionage</category><category>Telecommunications</category><category>Government</category><category>Google Sheets API</category><category>SoftEther VPN</category><category>C2</category><category>Linux Malware</category><category>TTPs</category></item></channel></rss>