Hunting for APT1 Inside Your Network

Опубликовано: 22 Май 2026
на канале: Cisco Secure Network Analytics
2,939
5

The release of Mandiant's APT1 report describing computer network attacks tied to China was this year's shot heard 'round the world (so far) for cyber security. A number of organizations have released lists of technical indicators of compromise, such as IP addresses and Domain Names associated with these attacks. Lancope's StealthWatch Labs research team has discovered and published additional indicators of APT1 that have not yet been published elsewhere.

Of course, when indicators like these are published, you can assume that the attackers won't be using them any more, and so real time monitoring for these addresses may not be valuable. StealthWatch provides a unique way to look back into past activity that has occurred on a computer network in search of evidence that these addresses were being accessed when they were still active.

Learn about Lancope's research results and discover how to determine whether APT1 has successfully compromised your network. Lancope's Director of Security Research, Tom Cross, will shed light on exactly what organizations should be looking for in light of this new research.