
Detect Volt Typhoon TTPs that Evade EDR

Over the past year, several sophisticated cyber-espionage campaigns have grabbed the attention of the IT industry and challenged defenders and vendors with advanced tactics, techniques, and procedures (TTPs). One of the most visible is Volt Typhoon, named by the Microsoft threat intelligence team in May 2023 and attributed to Chinese state-sponsored threat actors. It primarily targets critical infrastructure organizations in the US, using legitimate network administration tools to avoid detection—and is believed to be part of a broader effort to establish footholds in critical infrastructure for politically driven future disruptions. Download this guide to discover a SOC analyst’s perspective on combating Volt Typhoon attacks.
Report Snapshot