
Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).
This project presents a detailed threat intelligence and incident response analysis of the October 2023 LockBit ransomware attack targeting Boeing. The attackers exploited CVE-2023-4966 (Citrix Bleed) to hijack NetScaler session tokens, bypass authentication, deploy persistence mechanisms, and exfiltrate approximately 40GB of sensitive data.
This case study examines the full attack lifecycle, maps adversary behavior to the MITRE ATT&CK framework, and proposes defensive controls aligned with CISA and CIS guidelines.