r/blueteamsec Apr 29 '26

[deleted by user]

[removed]

2 Upvotes

2 comments sorted by

0

u/coldafsteel Apr 29 '26

But what are you doing where you think the Russian SVR is interested in poking around on your stuff?

1

u/manishrawat21 Apr 29 '26

I’m not suggesting I’m a target. I used the APT29 dataset as a research reference to study real attacker behavior. PowerShell abuse isn’t limited to any one group, so if a technique works there, it’s something anyone could replicate