Eric Russo

All posts by Eric Russo

Eric Russo is Director of SOC Defensive Security at Barracuda.

XDR 2024
XDR roundup 2024: Ransomware rises fourfold in a year of complex threats

XDR roundup 2024: Ransomware rises fourfold in a year of complex threats

In 2024, Barracuda Managed XDR logged many trillions of IT events to identify the critical security threats targeting organizations and neutralize malicious activity. Threat analysts in Barracuda Managed XDR’s Security Operations Center (SOC) have drawn on this unique dataset to highlight the...

/ February 14, 2025
SOC case files
The SOC case files: XDR detects Akira ransomware exploiting a ‘ghost’ account

The SOC case files: XDR detects Akira ransomware exploiting a ‘ghost’ account

This edition of the SOC case files showcases how Barracuda Managed XDR detects a breach via a ‘ghost’ account and an unprotected server. The SOC is part of Barracuda Managed XDR, an extended visibility, detection, and response (XDR) service that...

/ February 5, 2025 / 4 Comments
The SOC case files: XDR’s automation offers rapid cloud protection

The SOC case files: XDR’s automation offers rapid cloud protection

This edition of the SOC case files showcases how Barracuda Managed XDR detects an impossible travel, indicating a user login credentials were compromised. Incident summary An employee at a telecommunications company connected as usual to their cloud account. They then...

/ January 20, 2025 / 5 Comments
SOC case files
The SOC case files: XDR neutralizes threat targeting MSP

The SOC case files: XDR neutralizes threat targeting MSP

This edition of the SOC case files showcases how an incident was detected, contained, and mitigated in about a minute. The SOC is part of Barracuda Managed XDR, an extended visibility, detection, and response (XDR) service. It provides customers with...

/ December 24, 2024
SOC files
The SOC case files: Play ransomware targets manufacturing firm

The SOC case files: Play ransomware targets manufacturing firm

Incident summary A U.S.-based manufacturing company was recently targeted by the Play ransomware group in the early hours of the morning. The attackers broke into an under-protected domain controller at 1:00 am. At 3:20 a.m. the gang attempted to execute...

/ November 21, 2024 / 5 Comments