Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LockBit-Ransomware-Analysis — Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed). | Kitploit
Tools/GitHubGitHub/vignesh-hp/lockbit-ransomware-analysis
Indicator of Compromise (IOC) ManagementPrivilege EscalationVulnerability AnalysisLateral MovementData ExfiltrationMalware AnalysisDigital ForensicsThreat IntelligencePapers & Research

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Learning & Education
Incident Response
GitHubvignesh-hp/lockbit-ransomware-analysis

LockBit-Ransomware-Analysis

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

View Repository
126 months agoNot yet reviewed
Share

🔐 LockBit Ransomware Analysis – Citrix Bleed Exploitation

📌 Overview

This project presents a detailed threat intelligence and incident response analysis of the October 2023 LockBit ransomware attack targeting Boeing. The attackers exploited CVE-2023-4966 (Citrix Bleed) to hijack NetScaler session tokens, bypass authentication, deploy persistence mechanisms, and exfiltrate approximately 40GB of sensitive data.

This case study examines the full attack lifecycle, maps adversary behavior to the MITRE ATT&CK framework, and proposes defensive controls aligned with CISA and CIS guidelines.

🧠 Key Areas Covered

  • Initial Access via CVE-2023-4966
  • Session hijacking and MFA bypass
  • Lateral movement tools (PsExec, Mimikatz, AnyDesk)
  • Data exfiltration (40GB)
  • MITRE ATT&CK technique mapping
  • Kill Chain defensive matrix
  • CIS and CISA control alignment

🔎 SOC-Relevant Skills Demonstrated

  • Threat intelligence analysis
  • IOC identification
  • MITRE ATT&CK mapping
  • Ransomware investigation
  • Defensive control recommendations
Download Tool