open-menu
closeme
Potential Malicious Usage of CloudTrail System Manager
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.initial-access
attack.t1566
attack.t1566.002
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
calendar
Dec 9, 2025
·
attack.credential-access
attack.discovery
attack.t1552
attack.t1087
·
Share on:
twitter
facebook
linkedin
copy
Creation of WerFault.exe/Wer.dll in Unusual Folder
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Files With System Process Name In Unsuspected Locations
calendar
Dec 9, 2025
·
attack.defense-evasion
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
calendar
Dec 9, 2025
·
attack.defense-evasion
attack.t1006
·
Share on:
twitter
facebook
linkedin
copy
Potential System DLL Sideloading From Non System Locations
calendar
Dec 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load
calendar
Dec 9, 2025
·
attack.defense-evasion
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious WDAC Policy File Creation
calendar
Dec 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Startup Folder File Write
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Unauthorized System Time Modification
calendar
Dec 9, 2025
·
attack.defense-evasion
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
Uncommon AppX Package Locations
calendar
Dec 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
WMIC Loading Scripting Libraries
calendar
Dec 9, 2025
·
attack.defense-evasion
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
Load Of RstrtMgr.DLL By An Uncommon Process
calendar
Dec 9, 2025
·
attack.impact
attack.defense-evasion
attack.t1486
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Rare Remote Thread Creation By Uncommon Source Image
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Wow6432Node CurrentVersion Autorun Keys Modification
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CredUI.DLL Loaded By Uncommon Process
calendar
Dec 9, 2025
·
attack.credential-access
attack.collection
attack.t1056.002
·
Share on:
twitter
facebook
linkedin
copy
Desktop.INI Created by Uncommon Process
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Renamed Office Binary Execution
calendar
Dec 9, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
GUI Input Capture - macOS
calendar
Dec 9, 2025
·
attack.collection
attack.credential-access
attack.t1056.002
·
Share on:
twitter
facebook
linkedin
copy
ASLR Disabled Via Sysctl or Direct Syscall - Linux
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1562.001
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
Audio Capture
calendar
Dec 8, 2025
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
Auditing Configuration Changes on Linux Host
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1562.006
·
Share on:
twitter
facebook
linkedin
copy
Binary Padding - Linux
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
BPFDoor Abnormal Process ID or Lock File Accessed
calendar
Dec 8, 2025
·
attack.execution
attack.t1106
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Bpfdoor TCP Ports Redirect
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1070.002
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection of Image Data with Xclip Tool
calendar
Dec 8, 2025
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection with Xclip Tool - Auditd
calendar
Dec 8, 2025
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Creation Of An User Account
calendar
Dec 8, 2025
·
attack.t1136.001
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Credentials In Files - Linux
calendar
Dec 8, 2025
·
attack.credential-access
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Data Compressed
calendar
Dec 8, 2025
·
attack.exfiltration
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Data Exfiltration with Wget
calendar
Dec 8, 2025
·
attack.exfiltration
attack.t1048.003
·
Share on:
twitter
facebook
linkedin
copy
Disable System Firewall
calendar
Dec 8, 2025
·
attack.t1562.004
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
File or Folder Permissions Change
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
File Time Attribute Change - Linux
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
Hidden Files and Directories
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Linux Capabilities Discovery
calendar
Dec 8, 2025
·
attack.discovery
attack.defense-evasion
attack.privilege-escalation
attack.t1083
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Network Service Scanning - Auditd
calendar
Dec 8, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Loading of Kernel Module via Insmod
calendar
Dec 8, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1547.006
·
Share on:
twitter
facebook
linkedin
copy
Logging Configuration Changes on Linux Host
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1562.006
·
Share on:
twitter
facebook
linkedin
copy
Masquerading as Linux Crond Process
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Modification of ld.so.preload
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
Modify System Firewall
calendar
Dec 8, 2025
·
attack.t1562.004
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Network Sniffing - Linux
calendar
Dec 8, 2025
·
attack.credential-access
attack.discovery
attack.t1040
·
Share on:
twitter
facebook
linkedin
copy
Overwriting the File with Dev Zero or Null
calendar
Dec 8, 2025
·
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Possible Coin Miner CPU Priority Param
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Potential Abuse of Linux Magic System Request Key
calendar
Dec 8, 2025
·
attack.execution
attack.t1059.004
attack.impact
attack.t1529
attack.t1489
attack.t1499
·
Share on:
twitter
facebook
linkedin
copy
Program Executions in Suspicious Folders
calendar
Dec 8, 2025
·
attack.t1587
attack.t1584
attack.resource-development
·
Share on:
twitter
facebook
linkedin
copy
Remove Immutable File Attribute - Auditd
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Screen Capture with Import Tool
calendar
Dec 8, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Screen Capture with Xwd
calendar
Dec 8, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Service Reload or Start - Linux
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.002
·
Share on:
twitter
facebook
linkedin
copy
Special File Creation via Mknod Syscall
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Split A File Into Pieces - Linux
calendar
Dec 8, 2025
·
attack.exfiltration
attack.t1030
·
Share on:
twitter
facebook
linkedin
copy
Steganography Extract Files with Steghide
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Hide Files with Steghide
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Hide Zip Information in Picture File
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Unzip Hidden Information From Picture File
calendar
Dec 8, 2025
·
attack.defense-evasion
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Commands Linux
calendar
Dec 8, 2025
·
attack.execution
attack.t1059.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious History File Operations - Linux
calendar
Dec 8, 2025
·
attack.credential-access
attack.t1552.003
·
Share on:
twitter
facebook
linkedin
copy
System and Hardware Information Discovery
calendar
Dec 8, 2025
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
System Info Discovery via Sysinfo Syscall
calendar
Dec 8, 2025
·
attack.discovery
attack.t1057
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
System Owner or User Discovery - Linux
calendar
Dec 8, 2025
·
attack.discovery
attack.t1033
·
Share on:
twitter
facebook
linkedin
copy
System Shutdown/Reboot - Linux
calendar
Dec 8, 2025
·
attack.impact
attack.t1529
·
Share on:
twitter
facebook
linkedin
copy
Systemd Service Creation
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.002
·
Share on:
twitter
facebook
linkedin
copy
Unix Shell Configuration Modification
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.004
·
Share on:
twitter
facebook
linkedin
copy
Use Of Hidden Paths Or Files
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Webshell Remote Command Execution
calendar
Dec 8, 2025
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Github Self-Hosted Runner Execution
calendar
Dec 3, 2025
·
attack.command-and-control
attack.t1102.002
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download Via Certutil.EXE
calendar
Dec 3, 2025
·
attack.defense-evasion
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Downloaded From Direct IP Via Certutil.EXE
calendar
Dec 3, 2025
·
attack.defense-evasion
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
calendar
Dec 3, 2025
·
attack.defense-evasion
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
AWS GuardDuty Detector Deleted Or Updated
calendar
Nov 28, 2025
·
attack.defense-evasion
attack.t1562.001
attack.t1562.008
·
Share on:
twitter
facebook
linkedin
copy
LOL-Binary Copied From System Directory
calendar
Nov 27, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Copy From or To System Directory
calendar
Nov 27, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed Schtasks Execution
calendar
Nov 27, 2025
·
attack.defense-evasion
attack.execution
attack.persistence
attack.privilege-escalation
attack.t1036.003
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
DNS Query by Finger Utility
calendar
Nov 27, 2025
·
attack.command-and-control
attack.t1071.004
attack.execution
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
FileFix - Command Evidence in TypedPaths
calendar
Nov 27, 2025
·
attack.execution
attack.t1204.004
·
Share on:
twitter
facebook
linkedin
copy
Finger.EXE Execution
calendar
Nov 27, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated via Finger.EXE
calendar
Nov 27, 2025
·
attack.command-and-control
attack.t1071.004
attack.execution
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
Potential ClickFix Execution Pattern - Registry
calendar
Nov 27, 2025
·
attack.execution
attack.t1204.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
calendar
Nov 27, 2025
·
attack.execution
attack.t1204.004
attack.defense-evasion
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious FileFix Execution Pattern
calendar
Nov 27, 2025
·
attack.execution
attack.t1204.004
·
Share on:
twitter
facebook
linkedin
copy
Grixba Malware Reconnaissance Activity
calendar
Nov 27, 2025
·
attack.reconnaissance
attack.t1595.001
attack.discovery
attack.t1046
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DNS Query to External Service Interaction Domains
calendar
Nov 26, 2025
·
attack.initial-access
attack.t1190
attack.reconnaissance
attack.t1595.002
·
Share on:
twitter
facebook
linkedin
copy
Add Port Monitor Persistence in Registry
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Add SafeBoot Keys Via Reg Utility
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Advanced IP Scanner - File Event
calendar
Nov 26, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Allow RDP Remote Assistance Feature
calendar
Nov 26, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Anydesk Temporary Artefact
calendar
Nov 26, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using DelegateExecute
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using Event Viewer
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using SilentCleanup Task
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Certificate Exported Via Certutil.EXE
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Change Default File Association Via Assoc
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Chromium Browser Headless Execution To Mockbin Like Site
calendar
Nov 26, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Chromium Browser Instance Executed With Custom Extension
calendar
Nov 26, 2025
·
attack.persistence
attack.t1176.001
·
Share on:
twitter
facebook
linkedin
copy
Console CodePage Lookup Via CHCP
calendar
Nov 26, 2025
·
attack.discovery
attack.t1614.001
·
Share on:
twitter
facebook
linkedin
copy
Creation of a Local Hidden User Account by Registry
calendar
Nov 26, 2025
·
attack.persistence
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Non-Existent System DLL
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Cred Dump Tools Dropped Files
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1003.001
attack.t1003.002
attack.t1003.003
attack.t1003.004
attack.t1003.005
·
Share on:
twitter
facebook
linkedin
copy
Data Copied To Clipboard Via Clip.EXE
calendar
Nov 26, 2025
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Default RDP Port Changed to Non Standard Port
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Deleted Data Overwritten Via Cipher.EXE
calendar
Nov 26, 2025
·
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Directory Removal Via Rmdir
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
DirLister Execution
calendar
Nov 26, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Disable Administrative Share Creation at Startup
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Disable Microsoft Defender Firewall via Registry
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Security Center Notifications
calendar
Nov 26, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Dism Remove Online Package
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Domain Trust Discovery Via Dsquery
calendar
Nov 26, 2025
·
attack.discovery
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
DriverQuery.EXE Execution
calendar
Nov 26, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
EVTX Created In Uncommon Location
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
File And SubFolder Enumeration Via Dir Command
calendar
Nov 26, 2025
·
attack.discovery
attack.t1217
·
Share on:
twitter
facebook
linkedin
copy
File Decoded From Base64/Hex Via Certutil.EXE
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File Download From Browser Process Via Inline URL
calendar
Nov 26, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download with Headless Browser
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.command-and-control
attack.t1105
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
File Encoded To Base64 Via Certutil.EXE
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
calendar
Nov 26, 2025
·
attack.discovery
attack.t1135
·
Share on:
twitter
facebook
linkedin
copy
File In Suspicious Location Encoded To Base64 Via Certutil.EXE
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Files With System DLL Name In Unsuspected Locations
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Findstr GPP Passwords
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1552.006
·
Share on:
twitter
facebook
linkedin
copy
Gpresult Display Group Policy Information
calendar
Nov 26, 2025
·
attack.discovery
attack.t1615
·
Share on:
twitter
facebook
linkedin
copy
HH.EXE Execution
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1218.001
·
Share on:
twitter
facebook
linkedin
copy
Hiding User Account Via SpecialAccounts Registry Key
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
Hiding User Account Via SpecialAccounts Registry Key - CommandLine
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor Enforced Code Integrity Disabled
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
IE Change Domain Zone
calendar
Nov 26, 2025
·
attack.persistence
attack.t1137
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Memory Dump Creation Via Taskmgr.EXE
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Reconnaissance Via Findstr.EXE
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1552.006
·
Share on:
twitter
facebook
linkedin
copy
New Custom Shim Database Created
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
New Generic Credentials Added Via Cmdkey.EXE
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1003.005
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Installed Via Certutil.EXE
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Permission Misconfiguration Reconnaissance Via Findstr.EXE
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1552.006
·
Share on:
twitter
facebook
linkedin
copy
Potential COM Object Hijacking Via TreatAs Subkey - Registry
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Binary Rename
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1036.003
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Potential NTLM Coercion Via Certutil.EXE
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Attempt Via Run Keys Using Reg.EXE
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Logon Scripts - Registry
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.t1037.001
attack.persistence
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via New AMSI Providers - Registry
calendar
Nov 26, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation Using Symlink Between Osk and Cmd
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.008
·
Share on:
twitter
facebook
linkedin
copy
Potential Recon Activity Using DriverQuery.EXE
calendar
Nov 26, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1003.005
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious DMP/HDMP File Creation
calendar
Nov 26, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Powershell Executed From Headless ConHost Process
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.execution
attack.t1059.001
attack.t1059.003
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Logging Disabled Via Registry Key Tampering
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1564.001
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdFind Suspicious Execution
calendar
Nov 26, 2025
·
attack.discovery
attack.t1018
attack.t1087.002
attack.t1482
attack.t1069.002
stp.1u
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdFind.EXE Execution
calendar
Nov 26, 2025
·
attack.discovery
attack.t1087.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Advanced IP Scanner Execution
calendar
Nov 26, 2025
·
attack.discovery
attack.t1046
attack.t1135
·
Share on:
twitter
facebook
linkedin
copy
PUA - Advanced Port Scanner Execution
calendar
Nov 26, 2025
·
attack.discovery
attack.t1046
attack.t1135
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Execution
calendar
Nov 26, 2025
·
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1564.003
attack.t1134.002
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Suspicious Execution
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE
calendar
Nov 26, 2025
·
attack.discovery
attack.t1087.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Sysinternal Tool Execution - Registry
calendar
Nov 26, 2025
·
attack.resource-development
attack.t1588.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Sysinternals Tools Execution - Registry
calendar
Nov 26, 2025
·
attack.resource-development
attack.t1588.002
·
Share on:
twitter
facebook
linkedin
copy
Recon Command Output Piped To Findstr.EXE
calendar
Nov 26, 2025
·
attack.discovery
attack.t1057
·
Share on:
twitter
facebook
linkedin
copy
Registry Persistence via Service in Safe Mode
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Removal Of AMSI Provider Registry Keys
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Removal Of Index Value to Hide Schedule Task - Registry
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Removal Of SD Value to Hide Schedule Task - Registry
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Renamed AdFind Execution
calendar
Nov 26, 2025
·
attack.discovery
attack.t1018
attack.t1087.002
attack.t1482
attack.t1069.002
·
Share on:
twitter
facebook
linkedin
copy
Renamed CURL.EXE Execution
calendar
Nov 26, 2025
·
attack.execution
attack.t1059
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed FTP.EXE Execution
calendar
Nov 26, 2025
·
attack.execution
attack.t1059
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed Msdt.EXE Execution
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
RunMRU Registry Key Deletion - Registry
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Security Tools Keyword Lookup Via Findstr.EXE
calendar
Nov 26, 2025
·
attack.discovery
attack.t1518.001
·
Share on:
twitter
facebook
linkedin
copy
Stop Windows Service Via Sc.EXE
calendar
Nov 26, 2025
·
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Binaries and Scripts in Public Folder
calendar
Nov 26, 2025
·
attack.execution
attack.t1204
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Chromium Browser Instance Executed With Custom Extension
calendar
Nov 26, 2025
·
attack.persistence
attack.t1176.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CodePage Switch Via CHCP
calendar
Nov 26, 2025
·
attack.t1036
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Curl.EXE Download
calendar
Nov 26, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Execution Of Renamed Sysinternals Tools - Registry
calendar
Nov 26, 2025
·
attack.resource-development
attack.t1588.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation Activity From Fake Recycle.Bin Folder
calendar
Nov 26, 2025
·
attack.persistence
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Encoded To Base64 Via Certutil.EXE
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Kernel Dump Using Dtrace
calendar
Nov 26, 2025
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LNK Double Extension File Created
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Change
calendar
Nov 26, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
System Information Discovery via Registry Queries
calendar
Nov 26, 2025
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Tor Client/Browser Execution
calendar
Nov 26, 2025
·
attack.command-and-control
attack.t1090.003
·
Share on:
twitter
facebook
linkedin
copy
ArcSOC.exe Creating Suspicious Files
calendar
Nov 25, 2025
·
attack.defense-evasion
attack.command-and-control
attack.persistence
attack.t1127
attack.t1105
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ArcSOC.exe Child Process
calendar
Nov 25, 2025
·
attack.execution
attack.t1059
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Potential Container Discovery Via Inodes Listing
calendar
Nov 25, 2025
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Boot Configuration Tampering Via Bcdedit.EXE
calendar
Nov 25, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Interactive AT Job
calendar
Nov 25, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Disk Cleanup Handler - Registry
calendar
Nov 25, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Unsigned .node File Loaded
calendar
Nov 25, 2025
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1129
attack.t1574.001
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Filename with Embedded Base64 Commands
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.004
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Abused Debug Privilege by Arbitrary Parent Processes
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Active Directory Replication from Non Machine Account
calendar
Nov 24, 2025
·
attack.credential-access
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
Always Install Elevated MSI Spawned Cmd And Powershell
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
APT User Agent
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary Shell Command Execution Via Settingcontent-Ms
calendar
Nov 24, 2025
·
attack.t1204
attack.t1566.001
attack.execution
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM Backdoor Users Keys
calendar
Nov 24, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
AWS SecurityHub Findings Evasion
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Bitsadmin to Uncommon TLD
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1071.001
attack.defense-evasion
attack.persistence
attack.t1197
attack.s0190
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via CMSTP
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via Fodhelper.exe
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Cisco ASA FTD Exploit CVE-2020-3452
calendar
Nov 24, 2025
·
attack.t1190
attack.initial-access
cve.2020-3452
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Cisco BGP Authentication Failures
calendar
Nov 24, 2025
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Cisco Denial of Service
calendar
Nov 24, 2025
·
attack.impact
attack.t1495
attack.t1529
attack.t1565.001
·
Share on:
twitter
facebook
linkedin
copy
Cisco Disabling Logging
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Cisco File Deletion
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.impact
attack.t1070.004
attack.t1561.001
attack.t1561.002
·
Share on:
twitter
facebook
linkedin
copy
Cisco LDP Authentication Failures
calendar
Nov 24, 2025
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Cisco Local Accounts
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1136.001
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Cisco Modify Configuration
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.impact
attack.t1490
attack.t1505
attack.t1565.002
attack.t1053
·
Share on:
twitter
facebook
linkedin
copy
Cisco Show Commands Input
calendar
Nov 24, 2025
·
attack.credential-access
attack.t1552.003
·
Share on:
twitter
facebook
linkedin
copy
Cisco Sniffing
calendar
Nov 24, 2025
·
attack.credential-access
attack.discovery
attack.t1040
·
Share on:
twitter
facebook
linkedin
copy
Cisco Stage Data
calendar
Nov 24, 2025
·
attack.collection
attack.lateral-movement
attack.command-and-control
attack.exfiltration
attack.t1074
attack.t1105
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2020-8193
cve.2020-8195
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Citrix Netscaler Attack CVE-2019-19781
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2019-19781
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Data Collection Via OSAScript
calendar
Nov 24, 2025
·
attack.collection
attack.execution
attack.t1115
attack.t1059.002
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Process Creation
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.execution
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Registry Event
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.execution
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
Command Line Execution with Suspicious URL and AppData Strings
calendar
Nov 24, 2025
·
attack.execution
attack.command-and-control
attack.t1059.003
attack.t1059.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Conti Volume Shadow Listing
calendar
Nov 24, 2025
·
attack.t1587.001
attack.resource-development
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Cross Site Scripting Strings
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1189
·
Share on:
twitter
facebook
linkedin
copy
Crypto Miner User Agent
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
CurrentControlSet Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-0688 Exchange Exploitation via Web Log
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2020-0688
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-5902 F5 BIG-IP Exploitation Attempt
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2020-5902
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-1675 Print Spooler Exploitation
calendar
Nov 24, 2025
·
attack.execution
attack.t1569
cve.2021-1675
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-26858 Exchange Exploitation
calendar
Nov 24, 2025
·
attack.t1203
attack.execution
cve.2021-26858
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
attack.persistence
attack.t1505.003
cve.2021-40539
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Default Cobalt Strike Certificate
calendar
Nov 24, 2025
·
attack.command-and-control
attack.s0154
·
Share on:
twitter
facebook
linkedin
copy
Denied Access To Remote Desktop
calendar
Nov 24, 2025
·
attack.lateral-movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
DEWMODE Webshell Access
calendar
Nov 24, 2025
·
attack.persistence
attack.t1505.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Direct Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Disable Security Events Logging Adding Reg Key MiniNt
calendar
Nov 24, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.002
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
DLL Execution Via Register-cimprovider.exe
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
DLL Loaded via CertOC.EXE
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DNS Events Related To Mining Pools
calendar
Nov 24, 2025
·
attack.execution
attack.t1569.002
attack.impact
attack.t1496
·
Share on:
twitter
facebook
linkedin
copy
DNS TOR Proxies
calendar
Nov 24, 2025
·
attack.exfiltration
attack.t1048
·
Share on:
twitter
facebook
linkedin
copy
Download from Suspicious Dyndns Hosts
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.command-and-control
attack.t1105
attack.t1568
·
Share on:
twitter
facebook
linkedin
copy
Download From Suspicious TLD - Blacklist
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1566
attack.execution
attack.t1203
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Download From Suspicious TLD - Whitelist
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1566
attack.execution
attack.t1203
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
DPAPI Domain Master Key Backup Attempt
calendar
Nov 24, 2025
·
attack.credential-access
attack.t1003.004
·
Share on:
twitter
facebook
linkedin
copy
Droppers Exploiting CVE-2017-11882
calendar
Nov 24, 2025
·
attack.execution
attack.t1203
attack.t1204.002
attack.initial-access
attack.t1566.001
cve.2017-11882
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Esentutl Gather Credentials
calendar
Nov 24, 2025
·
attack.credential-access
attack.t1003
attack.t1003.003
attack.s0404
·
Share on:
twitter
facebook
linkedin
copy
Execute Files with Msdeploy.exe
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Execution of Powershell Script in Public Folder
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Exploit Framework User Agent
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Exploitation of CVE-2021-26814 in Wazuh
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2021-21978
cve.2021-26814
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exports Critical Registry Keys To a File
calendar
Nov 24, 2025
·
attack.exfiltration
attack.discovery
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Exports Registry Key To a File
calendar
Nov 24, 2025
·
attack.exfiltration
attack.discovery
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Exports Registry Key To an Alternate Data Stream
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Failed MSExchange Transport Agent Installation
calendar
Nov 24, 2025
·
attack.persistence
attack.t1505.002
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Bitsadmin
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.persistence
attack.t1197
attack.s0190
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Bitsadmin To An Uncommon Target Folder
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.persistence
attack.t1197
attack.s0190
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
File Was Not Allowed To Run
calendar
Nov 24, 2025
·
attack.execution
attack.t1204.002
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.006
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Fireball Archer Install
calendar
Nov 24, 2025
·
attack.execution
attack.defense-evasion
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Formbook Process Creation
calendar
Nov 24, 2025
·
attack.resource-development
attack.t1587.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Fortinet CVE-2018-13379 Exploitation
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2018-13379
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Fortinet CVE-2021-22123 Exploitation
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2021-22123
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Grafana Path Traversal Exploitation CVE-2021-43798
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2021-43798
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Hack Tool User Agent
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
attack.credential-access
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec Execution
calendar
Nov 24, 2025
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.discovery
attack.t1047
attack.t1053
attack.t1059.003
attack.t1059.001
attack.t1110
attack.t1201
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec PowerShell Obfuscation
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.001
attack.defense-evasion
attack.t1027.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Empire PowerShell UAC Bypass
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Koadic Execution
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.003
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential Impacket Lateral Movement Activity
calendar
Nov 24, 2025
·
attack.execution
attack.t1047
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Huawei BGP Authentication Failures
calendar
Nov 24, 2025
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From a File
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From an ADS
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Indirect Command Execution By Program Compatibility Wizard
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
InfDefaultInstall.exe .inf Execution
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.t1068
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Internet Explorer Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
ISO File Created Within Temp Folders
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Java Running with Remote Debugging
calendar
Nov 24, 2025
·
attack.t1203
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
JexBoss Command Sequence
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.004
·
Share on:
twitter
facebook
linkedin
copy
Juniper BGP Missing MD5
calendar
Nov 24, 2025
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
JXA In-memory Execution Via OSAScript
calendar
Nov 24, 2025
·
attack.t1059.002
attack.t1059.007
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
LOLBAS Data Exfiltration by DataSvcUtil.exe
calendar
Nov 24, 2025
·
attack.exfiltration
attack.t1567
·
Share on:
twitter
facebook
linkedin
copy
Metasploit Or Impacket Service Installation Via SMB PsExec
calendar
Nov 24, 2025
·
attack.lateral-movement
attack.t1021.002
attack.t1570
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
MMC Spawning Windows Shell
calendar
Nov 24, 2025
·
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
MSExchange Transport Agent Installation
calendar
Nov 24, 2025
·
attack.persistence
attack.t1505.002
·
Share on:
twitter
facebook
linkedin
copy
MSExchange Transport Agent Installation - Builtin
calendar
Nov 24, 2025
·
attack.persistence
attack.t1505.002
·
Share on:
twitter
facebook
linkedin
copy
New ActiveScriptEventConsumer Created Via Wmic.EXE
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
New DLL Added to AppCertDlls Registry Key
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.009
·
Share on:
twitter
facebook
linkedin
copy
New Kind of Network (NKN) Detection
calendar
Nov 24, 2025
·
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Node Process Executions
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.execution
attack.t1127
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Office Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Oracle WebLogic Exploit
calendar
Nov 24, 2025
·
attack.t1190
attack.initial-access
attack.persistence
attack.t1505.003
cve.2018-2894
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Oracle WebLogic Exploit CVE-2020-14882
calendar
Nov 24, 2025
·
attack.t1190
attack.initial-access
cve.2020-14882
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Oracle WebLogic Exploit CVE-2021-2109
calendar
Nov 24, 2025
·
attack.t1190
attack.initial-access
cve.2021-2109
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OSACompile Run-Only Execution
calendar
Nov 24, 2025
·
attack.t1059.002
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Ping Hex IP
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1140
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Possible CVE-2021-1675 Print Spooler Exploitation
calendar
Nov 24, 2025
·
attack.execution
attack.t1569
cve.2021-1675
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-42278 Exploitation Attempt
calendar
Nov 24, 2025
·
attack.credential-access
attack.t1558.003
cve.2021-42278
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-23752 Exploitation Attempt
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2023-23752
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection
calendar
Nov 24, 2025
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
cve.2024-3400
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Emotet Activity
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.001
attack.defense-evasion
attack.t1027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential File Overwrite Via Sysinternals SDelete
calendar
Nov 24, 2025
·
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation
calendar
Nov 24, 2025
·
attack.collection
attack.credential-access
attack.t1557.003
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential Maze Ransomware Activity
calendar
Nov 24, 2025
·
attack.execution
attack.t1204.002
attack.t1047
attack.impact
attack.t1490
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Meterpreter/CobaltStrike Activity
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Potential PetitPotam Attack Via EFS RPC Calls
calendar
Nov 24, 2025
·
attack.collection
attack.credential-access
attack.t1557.001
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Potential PlugX Activity
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.s0013
attack.defense-evasion
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential QBot Activity
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote Desktop Connection to Non-Domain Host
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Ryuk Ransomware Activity
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded Reflective Assembly Load
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.001
attack.defense-evasion
attack.t1027
attack.t1620
·
Share on:
twitter
facebook
linkedin
copy
Process Access via TrolleyExpress Exclusion
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218.011
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
PUA - Mouse Lock Execution
calendar
Nov 24, 2025
·
attack.credential-access
attack.collection
attack.t1056.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - NirCmd Execution
calendar
Nov 24, 2025
·
attack.execution
attack.t1569.002
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
PUA - NirCmd Execution As LOCAL SYSTEM
calendar
Nov 24, 2025
·
attack.execution
attack.t1569.002
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
PUA - Rclone Execution
calendar
Nov 24, 2025
·
attack.exfiltration
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - RunXCmd Execution
calendar
Nov 24, 2025
·
attack.execution
attack.t1569.002
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
Pulse Secure Attack CVE-2019-11510
calendar
Nov 24, 2025
·
attack.initial-access
attack.t1190
cve.2019-11510
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PwnDrp Access
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1071.001
attack.t1102.001
attack.t1102.003
·
Share on:
twitter
facebook
linkedin
copy
Rclone Activity via Proxy
calendar
Nov 24, 2025
·
attack.exfiltration
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
Registry Entries For Azorult Malware
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Via Regini.EXE
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Silent Installation
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote PowerShell Session Host Process (WinRM)
calendar
Nov 24, 2025
·
attack.execution
attack.lateral-movement
attack.t1059.001
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
Renamed Sysinternals Sdelete Execution
calendar
Nov 24, 2025
·
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Execution Without Parameters
calendar
Nov 24, 2025
·
attack.lateral-movement
attack.t1021.002
attack.t1570
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
SAM Registry Hive Handle Request
calendar
Nov 24, 2025
·
attack.discovery
attack.t1012
attack.credential-access
attack.t1552.002
·
Share on:
twitter
facebook
linkedin
copy
Script Event Consumer Spawning Process
calendar
Nov 24, 2025
·
attack.execution
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Session Manager Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
attack.t1546.009
·
Share on:
twitter
facebook
linkedin
copy
Share And Session Enumeration Using Net.EXE
calendar
Nov 24, 2025
·
attack.discovery
attack.t1018
·
Share on:
twitter
facebook
linkedin
copy
ShimCache Flush
calendar
Nov 24, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Solarwinds SUPERNOVA Webshell Access
calendar
Nov 24, 2025
·
attack.persistence
attack.t1505.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
SonicWall SSL/VPN Jarrewrite Exploitation
calendar
Nov 24, 2025
·
attack.t1190
attack.initial-access
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Source Code Enumeration Detection by Keyword
calendar
Nov 24, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Suspect Svchost Activity
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Binary In User Directory Spawned From Office Application
calendar
Nov 24, 2025
·
attack.execution
attack.t1204.002
attack.g0046
car.2013-05-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Cobalt Strike DNS Beaconing - Sysmon
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Account Name Change CVE-2021-42287
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1036
attack.t1098
cve.2021-42287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Control Panel DLL Load
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Csi.exe Usage
calendar
Nov 24, 2025
·
attack.lateral-movement
attack.execution
attack.t1072
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Desktopimgdownldr Command
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Desktopimgdownldr Target File
calendar
Nov 24, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download From Direct IP Via Bitsadmin
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.persistence
attack.t1197
attack.s0190
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Driver Install by pnputil.exe
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
calendar
Nov 24, 2025
·
attack.execution
attack.defense-evasion
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Encoded Scripts in a WMI Consumer
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.execution
attack.t1047
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Characteristics Due to Missing Fields
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.006
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outlook Child Process
calendar
Nov 24, 2025
·
attack.execution
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Mailbox Export to Share
calendar
Nov 24, 2025
·
attack.exfiltration
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Mailbox Export to Share - PS
calendar
Nov 24, 2025
·
attack.exfiltration
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Program Names
calendar
Nov 24, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet
calendar
Nov 24, 2025
·
attack.discovery
attack.t1087.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Recursive Takeown
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Registry Modification From ADS Via Regini.EXE
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rejected SMB Guest Logon From IP
calendar
Nov 24, 2025
·
attack.credential-access
attack.t1110.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Setupapi.dll Activity
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Runscripthelper.exe
calendar
Nov 24, 2025
·
attack.execution
attack.t1059
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scripting in a WMI Consumer
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Path Modification
calendar
Nov 24, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Userinit Child Process
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious VBoxDrvInst.exe Parameters
calendar
Nov 24, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Vsls-Agent Command With AgentExtensionPath Load
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Workstation Locking via Rundll32
calendar
Nov 24, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Execute Arbitrary PowerShell Code
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
System Scripts Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Tasks Folder Evasion
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.execution
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Telegram API Access
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.command-and-control
attack.t1071.001
attack.t1102.002
·
Share on:
twitter
facebook
linkedin
copy
TerraMaster TOS CVE-2020-28188
calendar
Nov 24, 2025
·
attack.t1190
attack.initial-access
cve.2020-28188
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Via Wsreset
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Using SettingSyncHost.exe as LOLBin
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.defense-evasion
attack.t1574.008
·
Share on:
twitter
facebook
linkedin
copy
Verclsid.exe Runs COM Object
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Virtualbox Driver Installation or Starting of VMs
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1564.006
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Netlogon Secure Channel Connection Allowed
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
WannaCry Ransomware Activity
calendar
Nov 24, 2025
·
attack.lateral-movement
attack.t1210
attack.discovery
attack.t1083
attack.defense-evasion
attack.t1222.001
attack.impact
attack.t1486
attack.t1490
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Webshell ReGeorg Detection Via Web Logs
calendar
Nov 24, 2025
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Win Susp Computer Name Containing Samtheadmin
calendar
Nov 24, 2025
·
attack.initial-access
attack.defense-evasion
cve.2021-42278
cve.2021-42287
attack.persistence
attack.privilege-escalation
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Definition Files Removed
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Pcap Drivers
calendar
Nov 24, 2025
·
attack.discovery
attack.credential-access
attack.t1040
·
Share on:
twitter
facebook
linkedin
copy
Windows Shell/Scripting Processes Spawning Suspicious Programs
calendar
Nov 24, 2025
·
attack.execution
attack.defense-evasion
attack.t1059.005
attack.t1059.001
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Windows Webshell Strings
calendar
Nov 24, 2025
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
WINEKEY Registry Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
WinSock2 Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Wow6432Node Classes Autorun Keys Modification
calendar
Nov 24, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
WScript or CScript Dropper - File
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
ZxShell Malware
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.003
attack.defense-evasion
attack.t1218.011
attack.s0412
attack.g0001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Atomic MacOS Stealer - FileGrabber Activity
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Atomic MacOS Stealer - Persistence Indicators
calendar
Nov 24, 2025
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1564.001
attack.t1543.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Kerberos Ticket Request via CLI
calendar
Nov 23, 2025
·
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock
calendar
Nov 23, 2025
·
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
calendar
Nov 23, 2025
·
attack.persistence
attack.defense-evasion
attack.lateral-movement
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed
calendar
Nov 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Windows Default Domain GPO Modification
calendar
Nov 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Default Domain GPO Modification via GPME
calendar
Nov 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - WSASS Execution
calendar
Nov 23, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
PPL Tampering Via WerFaultSecure
calendar
Nov 23, 2025
·
attack.defense-evasion
attack.t1562.001
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
System File Execution Location Anomaly
calendar
Nov 23, 2025
·
attack.defense-evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Visual Studio Code Tunnels Domain
calendar
Nov 21, 2025
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript - PowerShell
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Tampering by Potentially Suspicious Processes
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
calendar
Nov 21, 2025
·
attack.lateral-movement
attack.t1021.001
attack.execution
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed to Zero
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ClickFix/FileFix Execution Pattern
calendar
Nov 21, 2025
·
attack.execution
attack.t1204.001
attack.t1204.004
·
Share on:
twitter
facebook
linkedin
copy
Cisco ASA Exploitation Activity - Proxy
calendar
Nov 21, 2025
·
attack.initial-access
attack.t1190
cve.2025-20333
cve.2025-20362
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Svchost Command Line Parameter
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1036.005
attack.t1055
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Usage of For Loop with Recursive Directory Search in CMD
calendar
Nov 21, 2025
·
attack.execution
attack.t1059.003
attack.defense-evasion
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious NTFS Symlink Behavior Modification
calendar
Nov 17, 2025
·
attack.execution
attack.t1059
attack.defense-evasion
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Office Macros Warning Disabled
calendar
Nov 13, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Outlook Security Settings Updated - Registry
calendar
Nov 13, 2025
·
attack.persistence
attack.t1137
·
Share on:
twitter
facebook
linkedin
copy
Trust Access Disable For VBApplications
calendar
Nov 13, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
COM Object Hijacking Via Modification Of Default System CLSID Default Value
calendar
Nov 13, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Common Autorun Keys Modification
calendar
Nov 13, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CurrentVersion NT Autorun Keys Modification
calendar
Nov 13, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Ursnif Malware Activity - Registry
calendar
Nov 13, 2025
·
attack.persistence
attack.defense-evasion
attack.execution
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Wow6432Node Windows NT CurrentVersion Autorun Keys Modification
calendar
Nov 13, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Dtrack RAT Activity
calendar
Nov 12, 2025
·
attack.impact
attack.t1490
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Classes Autorun Keys Modification
calendar
Nov 10, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Copy From Or To Admin Share Or Sysvol Folder
calendar
Nov 10, 2025
·
attack.lateral-movement
attack.collection
attack.exfiltration
attack.t1039
attack.t1048
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
CurrentVersion Autorun Keys Modification
calendar
Nov 10, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Modification of IE Registry Settings
calendar
Nov 10, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Shim Database Modification
calendar
Nov 10, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Product Reconnaissance Via Wmic.EXE
calendar
Nov 10, 2025
·
attack.execution
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation Via Schtasks.EXE
calendar
Nov 10, 2025
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.t1053.005
attack.s0111
car.2013-08-001
stp.1u
·
Share on:
twitter
facebook
linkedin
copy
Scheduled TaskCache Change by Uncommon Program
calendar
Nov 10, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
WMIC Remote Command Execution
calendar
Nov 10, 2025
·
attack.execution
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Capture Credentials with Rpcping.exe
calendar
Nov 10, 2025
·
attack.credential-access
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
DeviceCredentialDeployment Execution
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Explorer Process Tree Break
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
MSDT Execution Via Answer File
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Office Macro File Download
calendar
Nov 10, 2025
·
attack.initial-access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CustomShellHost Execution
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Wlrmdr.EXE Uncommon Argument Or Child Process
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
detection.emerging-threats
cve.2021-34527
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Apache Spark Shell Command Injection - ProcessCreation
calendar
Nov 10, 2025
·
attack.initial-access
attack.t1190
cve.2022-33891
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Atlassian Confluence CVE-2022-26134
calendar
Nov 10, 2025
·
attack.initial-access
attack.execution
attack.t1190
attack.t1059
cve.2022-26134
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird - Registry
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.execution
attack.persistence
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-1675 Print Spooler Exploitation Filename Pattern
calendar
Nov 10, 2025
·
attack.execution
attack.privilege-escalation
attack.resource-development
attack.t1587
cve.2021-1675
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD HTTP No Authentication RCE - CVE-2021-38647
calendar
Nov 10, 2025
·
attack.privilege-escalation
attack.initial-access
attack.execution
attack.lateral-movement
attack.t1068
attack.t1190
attack.t1203
attack.t1021.006
attack.t1210
detection.emerging-threats
cve.2021-38647
·
Share on:
twitter
facebook
linkedin
copy
Pandemic Registry Key
calendar
Nov 10, 2025
·
attack.command-and-control
attack.t1105
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Possible PrintNightmare Print Driver Install - CVE-2021-1675
calendar
Nov 10, 2025
·
attack.execution
cve.2021-1678
cve.2021-1675
cve.2021-34527
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-42287 Exploitation Attempt
calendar
Nov 10, 2025
·
attack.credential-access
attack.t1558.003
detection.emerging-threats
cve.2021-42287
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CVE-2022-21919 or CVE-2021-34484 for LPE
calendar
Nov 10, 2025
·
attack.execution
detection.emerging-threats
cve.2022-21919
cve.2021-34484
·
Share on:
twitter
facebook
linkedin
copy
Potential KDC RC4-HMAC Downgrade Exploit - CVE-2022-37966
calendar
Nov 10, 2025
·
attack.privilege-escalation
detection.emerging-threats
cve.2022-37966
·
Share on:
twitter
facebook
linkedin
copy
Potential NetWire RAT Activity - Registry
calendar
Nov 10, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Nimbuspwn Exploit CVE-2022-29799 and CVE-2022-27800
calendar
Nov 10, 2025
·
attack.privilege-escalation
attack.t1068
detection.emerging-threats
cve.2022-29799
cve.2022-27800
·
Share on:
twitter
facebook
linkedin
copy
Potential PrintNightmare Exploitation Attempt
calendar
Nov 10, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574
cve.2021-1675
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential RDP Exploit CVE-2019-0708
calendar
Nov 10, 2025
·
attack.lateral-movement
attack.t1210
car.2013-07-002
cve.2019-0708
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PrinterNightmare Mimikatz Driver Name
calendar
Nov 10, 2025
·
attack.execution
attack.t1204
cve.2021-1675
cve.2021-34527
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PwnKit Local Privilege Escalation
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.001
detection.emerging-threats
cve.2021-4034
·
Share on:
twitter
facebook
linkedin
copy
Scanner PoC for CVE-2019-0708 RDP RCE Vuln
calendar
Nov 10, 2025
·
attack.lateral-movement
attack.t1210
car.2013-07-002
detection.emerging-threats
cve.2019-0708
·
Share on:
twitter
facebook
linkedin
copy
SSHD Error Message CVE-2018-15473
calendar
Nov 10, 2025
·
attack.reconnaissance
attack.t1589
cve.2018-15473
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1068
attack.t1548.003
cve.2019-14287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287 - Builtin
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1068
attack.t1548.003
cve.2019-14287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Cobalt Strike DNS Beaconing - DNS Client
calendar
Nov 10, 2025
·
attack.t1071.004
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Windows Spooler Service Suspicious Binary Load
calendar
Nov 10, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574
cve.2021-1675
cve.2021-34527
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CertReq Command to Download
calendar
Nov 6, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Space Characters in RunMRU Registry Path - ClickFix
calendar
Nov 5, 2025
·
attack.execution
attack.t1204.004
attack.defense-evasion
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Space Characters in TypedPaths Registry Path - FileFix
calendar
Nov 5, 2025
·
attack.execution
attack.t1204.004
attack.defense-evasion
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Audit Log Configuration Updated
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Full Data Export Triggered
calendar
Nov 3, 2025
·
attack.collection
attack.t1213.003
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global Permission Changed
calendar
Nov 3, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global Secret Scanning Rule Deleted
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global SSH Settings Changed
calendar
Nov 3, 2025
·
attack.lateral-movement
attack.defense-evasion
attack.t1562.001
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Project Secret Scanning Allowlist Added
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Exempt Repository Added
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Rule Deleted
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Unauthorized Access To A Resource
calendar
Nov 3, 2025
·
attack.resource-development
attack.t1586
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Unauthorized Full Data Export Triggered
calendar
Nov 3, 2025
·
attack.collection
attack.resource-development
attack.t1213.003
attack.t1586
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket User Details Export Attempt Detected
calendar
Nov 3, 2025
·
attack.collection
attack.reconnaissance
attack.discovery
attack.t1213
attack.t1082
attack.t1591.004
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket User Login Failure
calendar
Nov 3, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket User Login Failure Via SSH
calendar
Nov 3, 2025
·
attack.lateral-movement
attack.credential-access
attack.t1021.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket User Permissions Export Attempt
calendar
Nov 3, 2025
·
attack.reconnaissance
attack.collection
attack.discovery
attack.t1213
attack.t1082
attack.t1591.004
·
Share on:
twitter
facebook
linkedin
copy
Cisco Duo Successful MFA Authentication Via Bypass Code
calendar
Nov 3, 2025
·
attack.credential-access
attack.defense-evasion
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Github Delete Action Invoked
calendar
Nov 3, 2025
·
attack.impact
attack.collection
attack.t1213.003
·
Share on:
twitter
facebook
linkedin
copy
Github Fork Private Repositories Setting Enabled/Cleared
calendar
Nov 3, 2025
·
attack.persistence
attack.exfiltration
attack.t1020
attack.t1537
·
Share on:
twitter
facebook
linkedin
copy
Github High Risk Configuration Disabled
calendar
Nov 3, 2025
·
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Github New Secret Created
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Github Outside Collaborator Detected
calendar
Nov 3, 2025
·
attack.privilege-escalation
attack.persistence
attack.collection
attack.t1098.001
attack.t1098.003
attack.t1213.003
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Bypass Detected
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Disabled
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
GitHub Repository Archive Status Changed
calendar
Nov 3, 2025
·
attack.persistence
attack.defense-evasion
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
GitHub Repository Pages Site Changed to Public
calendar
Nov 3, 2025
·
attack.collection
attack.exfiltration
attack.t1567.001
·
Share on:
twitter
facebook
linkedin
copy
Github Repository/Organization Transferred
calendar
Nov 3, 2025
·
attack.persistence
attack.exfiltration
attack.t1020
attack.t1537
·
Share on:
twitter
facebook
linkedin
copy
Github Secret Scanning Feature Disabled
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Github Self Hosted Runner Changes Detected
calendar
Nov 3, 2025
·
attack.impact
attack.discovery
attack.collection
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.t1526
attack.t1213.003
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Github SSH Certificate Configuration Changed
calendar
Nov 3, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
New Github Organization Member Added
calendar
Nov 3, 2025
·
attack.persistence
attack.t1136.003
·
Share on:
twitter
facebook
linkedin
copy
New Okta User Created
calendar
Nov 3, 2025
·
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Okta Admin Functions Access Through Proxy
calendar
Nov 3, 2025
·
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Okta Admin Role Assigned to an User or Group
calendar
Nov 3, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Okta Admin Role Assignment Created
calendar
Nov 3, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Okta API Token Created
calendar
Nov 3, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Okta API Token Revoked
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Application Modified or Deleted
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Application Sign-On Policy Modified or Deleted
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta FastPass Phishing Detection
calendar
Nov 3, 2025
·
attack.initial-access
attack.t1566
·
Share on:
twitter
facebook
linkedin
copy
Okta Identity Provider Created
calendar
Nov 3, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.001
·
Share on:
twitter
facebook
linkedin
copy
Okta MFA Reset or Deactivated
calendar
Nov 3, 2025
·
attack.persistence
attack.credential-access
attack.defense-evasion
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Okta Network Zone Deactivated or Deleted
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta New Admin Console Behaviours
calendar
Nov 3, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Okta Policy Modified or Deleted
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Policy Rule Modified or Deleted
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Security Threat Detected
calendar
Nov 3, 2025
·
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Okta Suspicious Activity Reported by End-user
calendar
Nov 3, 2025
·
attack.resource-development
attack.t1586.003
·
Share on:
twitter
facebook
linkedin
copy
Okta Unauthorized Access to App
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta User Account Locked Out
calendar
Nov 3, 2025
·
attack.impact
attack.t1531
·
Share on:
twitter
facebook
linkedin
copy
Okta User Session Start Via An Anonymising Proxy Service
calendar
Nov 3, 2025
·
attack.defense-evasion
attack.t1562.006
·
Share on:
twitter
facebook
linkedin
copy
OneLogin User Account Locked
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
OneLogin User Assumed Another User
calendar
Nov 3, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Outdated Dependency Or Vulnerability Alert Disabled
calendar
Nov 3, 2025
·
attack.initial-access
attack.t1195.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Okta Password in AlternateID Field
calendar
Nov 3, 2025
·
attack.credential-access
attack.t1552
·
Share on:
twitter
facebook
linkedin
copy
Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
calendar
Nov 1, 2025
·
attack.execution
attack.initial-access
attack.t1190
attack.t1203
cve.2025-59287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
calendar
Nov 1, 2025
·
attack.execution
attack.initial-access
attack.t1190
attack.t1203
cve.2025-59287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - Firewall Address Object Added
calendar
Nov 1, 2025
·
attack.defense-evasion
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - New Administrator Account Created
calendar
Nov 1, 2025
·
attack.persistence
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - New Firewall Policy Added
calendar
Nov 1, 2025
·
attack.defense-evasion
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - New Local User Created
calendar
Nov 1, 2025
·
attack.persistence
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - New VPN SSL Web Portal Added
calendar
Nov 1, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - User Group Modified
calendar
Nov 1, 2025
·
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - VPN SSL Settings Modified
calendar
Nov 1, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Kerberoasting Activity - Initial Query
calendar
Oct 29, 2025
·
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Mint Sandstorm - AsperaFaspex Suspicious Process Execution
calendar
Oct 29, 2025
·
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Mint Sandstorm - ManageEngine Suspicious Process Execution
calendar
Oct 29, 2025
·
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Data Exfiltration Activity Via CommandLine Tools
calendar
Oct 29, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Devil Bait Malware Reconnaissance
calendar
Oct 29, 2025
·
attack.defense-evasion
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Snatch Ransomware Activity
calendar
Oct 29, 2025
·
attack.execution
attack.t1204
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Network Command
calendar
Oct 29, 2025
·
attack.discovery
attack.t1016
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SYSTEM User Process Creation
calendar
Oct 29, 2025
·
attack.credential-access
attack.defense-evasion
attack.privilege-escalation
attack.t1134
attack.t1003
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Commands May 2020
calendar
Oct 29, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.g0010
attack.execution
attack.t1059.001
attack.t1053.005
attack.t1027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Speech Runtime Binary Child Process
calendar
Oct 29, 2025
·
attack.defense-evasion
attack.lateral-movement
attack.t1021.003
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
PUA - AWS TruffleHog Execution
calendar
Oct 29, 2025
·
attack.credential-access
attack.t1555
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
Potential Lateral Movement via Windows Remote Shell
calendar
Oct 29, 2025
·
attack.lateral-movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
Winrs Local Command Execution
calendar
Oct 29, 2025
·
attack.lateral-movement
attack.defense-evasion
attack.t1021.006
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Syslog Clearing or Removal Via System Utilities
calendar
Oct 28, 2025
·
attack.defense-evasion
attack.t1070.002
·
Share on:
twitter
facebook
linkedin
copy
Audit Rules Deleted Via Auditctl
calendar
Oct 28, 2025
·
attack.defense-evasion
attack.t1562.012
·
Share on:
twitter
facebook
linkedin
copy
Python WebServer Execution - Linux
calendar
Oct 28, 2025
·
attack.exfiltration
attack.t1048.003
·
Share on:
twitter
facebook
linkedin
copy
Kaspersky Endpoint Security Stopped Via CommandLine - Linux
calendar
Oct 28, 2025
·
attack.execution
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
AWS KMS Imported Key Material Usage
calendar
Oct 28, 2025
·
attack.impact
attack.t1486
attack.resource-development
attack.t1608.003
·
Share on:
twitter
facebook
linkedin
copy
File Access Of Signal Desktop Sensitive Data
calendar
Oct 28, 2025
·
attack.credential-access
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
WFP Filter Added via Registry
calendar
Oct 27, 2025
·
attack.defense-evasion
attack.execution
attack.t1562
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Restic Backup Tool Execution
calendar
Oct 24, 2025
·
attack.exfiltration
attack.t1048
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
A Member Was Added to a Security-Enabled Global Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
A Member Was Removed From a Security-Enabled Global Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
A New Trust Was Created To A Domain
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
A Security-Enabled Global Group Was Deleted
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Account Created And Deleted Within A Close Time Frame
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Account Disabled or Blocked for Sign in Attempts
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Activate Suppression of Windows Security Center Notifications
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Add DisallowRun Execution to Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Added Credentials to Existing Application
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1098.001
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Addition of SID History to Active Directory Object
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1134.005
·
Share on:
twitter
facebook
linkedin
copy
Admin User Remote Logon
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.lateral-movement
attack.initial-access
attack.t1078.001
attack.t1078.002
attack.t1078.003
car.2016-04-005
·
Share on:
twitter
facebook
linkedin
copy
Allow Service Access Using Security Descriptor Tampering Via Sc.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Always Install Elevated Windows Installer
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Anomalous User Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1098
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Application AppID Uri Configuration Changes
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.t1552
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Application URI Configuration Changes
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1528
attack.t1078.004
attack.persistence
attack.credential-access
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
APT27 - Emissary Panda Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.g0027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
APT31 Judgement Panda Activity
calendar
Oct 23, 2025
·
attack.collection
attack.lateral-movement
attack.credential-access
attack.g0128
attack.t1003.001
attack.t1560.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Aruba Network Service Potential DLL Sideloading
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.persistence
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Atbroker Registry Change
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1218
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Attempts of Kerberos Coercion Via DNS SPN Spoofing
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1557.001
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Authentications To Important Apps Using Single Factor Authentication
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
AWS Console GetSigninToken Potential Abuse
calendar
Oct 23, 2025
·
attack.lateral-movement
attack.defense-evasion
attack.t1021.007
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser LoginProfile Creation
calendar
Oct 23, 2025
·
attack.execution
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser Templated S3 Bucket Policy Creation
calendar
Oct 23, 2025
·
attack.execution
attack.t1059.009
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser User or AccessKey Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Identity Center Identity Provider Change
calendar
Oct 23, 2025
·
attack.persistence
attack.credential-access
attack.defense-evasion
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
AWS Key Pair Import Activity
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
AWS Root Credentials
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Route 53 Domain Transfer Lock Disabled
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
AWS Route 53 Domain Transferred to Another Account
calendar
Oct 23, 2025
·
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
AWS SAML Provider Deletion Activity
calendar
Oct 23, 2025
·
attack.t1078.004
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1531
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
AWS STS AssumeRole Misuse
calendar
Oct 23, 2025
·
attack.lateral-movement
attack.privilege-escalation
attack.defense-evasion
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS STS GetSessionToken Misuse
calendar
Oct 23, 2025
·
attack.lateral-movement
attack.privilege-escalation
attack.defense-evasion
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS Successful Console Login Without MFA
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Suspicious SAML Activity
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.initial-access
attack.lateral-movement
attack.persistence
attack.privilege-escalation
attack.t1078
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS User Login Profile Was Modified
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Only Single Factor Authentication Required
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Azure Domain Federation Settings Modified
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Admission Controller
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Azure Login Bypassing Conditional Access Policies
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via ActivityLogs
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via AuditLogs
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Unusual Authentication Interruption
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Bitlocker Key Retrieval
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Blackbyte Ransomware Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.execution
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Browser Execution In Headless Mode
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.command-and-control
attack.t1105
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Bulk Deletion Changes To Privileged Account Permissions
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Removed by Non Approved Actor
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Updated by Non Approved Actor
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Certificate-Based Authentication Enabled
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Change Default File Association To Executable Via Assoc
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Change the Fax Dll
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Change to Authentication Method
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.t1556
attack.persistence
attack.defense-evasion
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Change User Account Associated with the FAX Service
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Changes To PIM Settings
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.persistence
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Changing Existing Service ImagePath Value Via Reg.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
ChromeLoader Malware Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
attack.t1176
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ClickOnce Trust Prompt Tampering
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations - Security
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.lateral-movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations - System
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.lateral-movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Code Injection by ld.so Preload
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Blocked Driver Load With Revoked Certificate
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Blocked Image/Driver Load For Policy Violation
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
COM Hijack via Sdclt
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1546
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
COM Hijacking via TreatAs
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.001
detection.emerging-threats
cve.2025-57788
·
Share on:
twitter
facebook
linkedin
copy
Control Panel Items
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.defense-evasion
attack.t1218.002
attack.persistence
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
CosmicDuke Service Installation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1543.003
attack.t1569.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CrashControl CrashDump Disabled
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1564
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Created Files by Microsoft Sync Center
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1055
attack.t1218
attack.execution
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Creation Exe for Service with Unquoted Path
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Credential Dumping Attempt Via Svchost
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-31979 CVE-2021-33771 Exploits
calendar
Oct 23, 2025
·
attack.initial-access
attack.execution
attack.credential-access
attack.t1566
attack.t1203
cve.2021-33771
cve.2021-31979
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
calendar
Oct 23, 2025
·
attack.initial-access
attack.execution
attack.credential-access
attack.t1566
attack.t1203
cve.2021-33771
cve.2021-31979
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2022-24527 Microsoft Connected Cache LPE
calendar
Oct 23, 2025
·
attack.execution
attack.privilege-escalation
attack.t1059.001
cve.2022-24527
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2024-50623 Exploitation Attempt - Cleo
calendar
Oct 23, 2025
·
attack.initial-access
attack.execution
attack.t1190
cve.2024-50623
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Defrag Deactivation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.s0111
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Defrag Deactivation - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
attack.s0111
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Deny Service Access Using Security Descriptor Tampering Via Sc.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Device Registration or Join Without MFA
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
DHCP Callout DLL Installation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Error Failed Loading the CallOut DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Loaded the CallOut DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT DLL Sideloading Indicators
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Directory Service Restore Mode(DSRM) Registry Value Tampering
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.persistence
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Disable Internal Tools or Feature in Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Disabled MFA to Bypass Authentication Mechanisms
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.persistence
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
DLL Load via LSASS
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1547.008
·
Share on:
twitter
facebook
linkedin
copy
DLL Names Used By SVR For GraphicalProton Backdoor
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading by VMware Xfer Utility
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Dllhost.EXE Execution Anomaly
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
DNS Query Request To OneLaunch Update Service
calendar
Oct 23, 2025
·
attack.credential-access
attack.collection
attack.t1056
·
Share on:
twitter
facebook
linkedin
copy
DNS Server Error Failed Loading the ServerLevelPluginDLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DNS-over-HTTPS Enabled by Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1140
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DotNet CLR DLL Loaded By Scripting Applications
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.execution
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Dropping Of Password Filter DLL
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.credential-access
attack.t1556.002
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage - ProcCreation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enabled User Right in AD to Control User Objects
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Equation Group C2 Communication
calendar
Oct 23, 2025
·
attack.exfiltration
attack.command-and-control
attack.g0020
attack.t1041
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ESXi Admin Permission Assigned To Account Via ESXCLI
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1059.012
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For rpcrt4.dll
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For SCM
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Sysmon Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Exploiting SetupComplete.cmd CVE-2019-1378
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1068
attack.execution
attack.t1059.003
attack.t1574
cve.2019-1378
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Explorer NOUACCHECK Flag
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
External Remote RDP Logon from Public IP
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
External Remote SMB Logon from Public IP
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Authentications From Countries You Do Not Operate Out Of
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Logon From Public IP
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1078
attack.t1190
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Fax Service DLL Search Order Hijack
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
File Creation In Suspicious Directory By Msdt.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
cve.2022-30190
·
Share on:
twitter
facebook
linkedin
copy
FlowCloud Registry Markers
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - Custom Protocol Handler Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - Custom Protocol Handler DLL Registry Set
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
FunkLocker Ransomware File Creation
calendar
Oct 23, 2025
·
attack.impact
attack.t1486
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
GCP Break-glass Container Workload Deployed
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Kubernetes Admission Controller
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Granted Domain API Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace User Granted Admin Privileges
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Granting Of Permissions To An Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Group Policy Abuse for Privilege Addition
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Guest Account Enabled Via Sysadminctl
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
attack.t1078.001
·
Share on:
twitter
facebook
linkedin
copy
Guest User Invited By Non Approved Inviters
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Guest Users Invited To Tenant By Non Approved Inviters
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
HackTool - ADCSPwn Execution
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CACTUSTORCH Remote Thread Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.execution
attack.t1055.012
attack.t1059.005
attack.t1059.007
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec Execution Patterns
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1047
attack.t1053
attack.t1059.003
attack.t1059.001
attack.s0106
·
Share on:
twitter
facebook
linkedin
copy
HackTool - DInjector PowerShell Cradle Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - HollowReaper Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Impacket Tools Execution
calendar
Oct 23, 2025
·
attack.collection
attack.execution
attack.credential-access
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Koh Default Named Pipe
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.credential-access
attack.t1528
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - KrbRelayUp Execution
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.t1558.003
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LittleCorporal Generated Maldoc Injection
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.execution
attack.privilege-escalation
attack.t1204.002
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - NoFilter Execution
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential CobaltStrike Process Injection
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - PPID Spoofing SelectMyParent Tool Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1134.004
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Rubeus Execution
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.t1003
attack.t1558.003
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Rubeus Execution - ScriptBlock
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.t1003
attack.t1558.003
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharPersist Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpUp PrivEsc Tool Execution
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.discovery
attack.execution
attack.t1615
attack.t1569.002
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
Hacktool Ruler
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.discovery
attack.execution
attack.collection
attack.lateral-movement
attack.t1087
attack.t1114
attack.t1059
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
HAFNIUM Exchange Exploitation Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1546
attack.t1053
attack.g0125
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Increased Failed Authentications Of Any Type
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Injected Browser Process Spawning Rundll32 - GuLoader Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Invalid PIM License
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
ISATAP Router Address Was Set
calendar
Oct 23, 2025
·
attack.impact
attack.credential-access
attack.collection
attack.initial-access
attack.privilege-escalation
attack.execution
attack.t1557
attack.t1565.002
·
Share on:
twitter
facebook
linkedin
copy
Kalambur Backdoor Curl TOR SOCKS Proxy Execution
calendar
Oct 23, 2025
·
attack.execution
attack.command-and-control
attack.t1090
attack.t1573
attack.t1071.001
attack.t1059.001
attack.s0183
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Autorun Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Persistence Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
KrbRelayUp Service Installation
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Admission Controller Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Launch Agent/Daemon Execution Via Launchctl
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1569.001
attack.t1543.001
attack.t1543.004
·
Share on:
twitter
facebook
linkedin
copy
Lazarus APT DLL Sideloading Activity
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.persistence
attack.t1574.001
attack.g0032
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Leviathan Registry Key Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Linux Doas Conf File Creation
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Doas Tool Execution
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Keylogging with Pam.d
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.t1003
attack.t1056.001
·
Share on:
twitter
facebook
linkedin
copy
Local Privilege Escalation Indicator TabTip
calendar
Oct 23, 2025
·
attack.collection
attack.execution
attack.credential-access
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Login to Disabled Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Logon from a Risky IP Address
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Lummac Stealer Activity - Execution Of More.com And Vbc.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Macro Enabled In A Potentially Suspicious Document
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Malicious Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Malicious Driver Load By Name
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1078
attack.t1078.002
·
Share on:
twitter
facebook
linkedin
copy
ManageEngine Endpoint Central Dctask64.EXE Potential Abuse
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Measurable Increase Of Successful Authentications
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - Security
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - System
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Microsoft 365 - Impossible Travel Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Defender Blocked from Loading Unsigned DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Sync Center Suspicious Network Connections
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1055
attack.t1218
attack.execution
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
MITRE BZAR Indicators for Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1047
attack.t1053.002
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
MITRE BZAR Indicators for Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.004
·
Share on:
twitter
facebook
linkedin
copy
Modifying Crontab
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Monitoring For Persistence Via BITS
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
MSSQL Extended Stored Procedure Backdoor Maggie
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Denied
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Interrupted
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
Narrator's Feedback-Hub Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
NET NGenAssemblyUsageLog Registry Key Tamper
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated Via Notepad.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.command-and-control
attack.execution
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom DB Path Registry Configuration
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom VBScript Registry Configuration
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom WMI Query Registry Configuration
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New CA Policy by Non-approved Actor
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
New DLL Added to AppInit_DLLs Registry Key
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.010
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New Netsh Helper DLL Registered From A Suspicious Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.007
·
Share on:
twitter
facebook
linkedin
copy
New Outlook Macro Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
New PDQDeploy Service - Client Side
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
New PDQDeploy Service - Server Side
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Authority Added
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
New RUN Key Pointing to Suspicious Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Non-privileged Usage of Reg or Powershell
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NTLM Logon
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.lateral-movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Number Of Resource Creation Or Deployment Activities
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
OceanLotus Registry Activity
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Registry Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - System
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH Login Attempt
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.lateral-movement
attack.persistence
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH New Connection Attempt
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.lateral-movement
attack.persistence
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - Telnet Login Attempt
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.command-and-control
attack.t1133
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.t1012
attack.defense-evasion
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.t1012
attack.defense-evasion
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Outlook Macro Execution Without Warning Setting Enabled
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Pass the Hash Activity 2
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.lateral-movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Password Change on Directory Service Restore Mode (DSRM) Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Password Reset By User Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.credential-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Password Set to Never Expire via WMI
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1047
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Persistence and Execution at Scale via GPO Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.lateral-movement
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via Cron Files
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via Sticky Key Backdoor
calendar
Oct 23, 2025
·
attack.persistence
attack.t1546.008
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via Sudoers Files
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
PIM Alert Setting Changes To Disabled
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
PIM Approvals And Deny Elevation
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor DLL Loading Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor File Indicators
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PktMon.EXE Execution
calendar
Oct 23, 2025
·
attack.discovery
attack.credential-access
attack.t1040
·
Share on:
twitter
facebook
linkedin
copy
Possible Shadow Credentials Added
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.credential-access
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Potential ACTINIUM Persistence Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
attack.t1053.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential appverifUI.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential AVKkid.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Azure Browser SSO Abuse
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential BearLPE Exploitation
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1053.005
car.2013-08-001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CobaltStrike Service Installations - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.lateral-movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Data Stealing Via Chromium Headless Debugging
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1185
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Injection Or Execution Using Tracker.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DbgModel.DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MpSvc.DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MsCorSvc.DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Using Coregen.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1218
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via DeviceEnroller.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via VMware Xfer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential EACore.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Edputil.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.execution
attack.t1059.001
attack.t1059.003
attack.t1068
attack.t1190
cve.2025-54309
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053
calendar
Oct 23, 2025
·
attack.command-and-control
attack.execution
attack.defense-evasion
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
calendar
Oct 23, 2025
·
attack.command-and-control
attack.execution
attack.defense-evasion
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
calendar
Oct 23, 2025
·
attack.command-and-control
attack.execution
attack.defense-evasion
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Goopdate.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Initial Access via DLL Search Order Hijacking
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1566
attack.t1566.001
attack.initial-access
attack.t1574
attack.t1574.001
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Iviewers.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential KamiKakaBot Activity - Winlogon Shell Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Process Code Injection Via DD Utility
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
Potential MFA Bypass Using Legacy Client Authentication
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Potential Mfdetours.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading Via Defender Binaries
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Notepad++ CVE-2025-49144 Exploitation
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.008
cve.2025-49144
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Attempt Via Existing Service Tampering
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1543.003
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Using DebugPath
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via App Paths Default Property
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.012
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via AppCompat RegisterAppRestart Layer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Custom Protocol Handler
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Logon Scripts - CommandLine
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1037.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Microsoft Compatibility Appraiser
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Netsh Helper DLL - Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.007
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Home Page
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Today Page
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via PlistBuddy
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.001
attack.t1543.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Powershell Search Order Hijacking - Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Scrobj.dll COM Hijacking
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Shim Database In Uncommon Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Pikabot Hollowing Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.012
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.command-and-control
attack.execution
attack.t1059.003
attack.t1105
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Local Kerberos Relay over LDAP
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.credential-access
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Service Permissions Weakness
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Injection Via Msra.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential PSFactoryBuffer COM Hijacking
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential Python DLL SideLoading
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Qakbot Registry Activity
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Aclui Dll SideLoading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
calendar
Oct 23, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Rcdll.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Registry Persistence Attempt Via DbgManagedDebugger
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
Potential Registry Persistence Attempt Via Windows Telemetry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Potential RipZip Attack on Startup Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Default Location
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Non-Default Location
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RoboForm.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SAP NetWeaver Webshell Creation
calendar
Oct 23, 2025
·
attack.execution
attack.initial-access
attack.t1190
attack.persistence
attack.t1059.003
cve.2025-31324
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential SAP NetWeaver Webshell Creation - Linux
calendar
Oct 23, 2025
·
attack.execution
attack.initial-access
attack.t1190
attack.persistence
attack.t1059.003
cve.2025-31324
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential ShellDispatch.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SmadHook.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SMB Relay Attack Tool Execution
calendar
Oct 23, 2025
·
attack.collection
attack.execution
attack.credential-access
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SolidPDFCreator.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SSH Tunnel Persistence Install Using A Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Potential Startup Shortcut Persistence Via PowerShell.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Activity Using SeCEdit
calendar
Oct 23, 2025
·
attack.collection
attack.discovery
attack.persistence
attack.defense-evasion
attack.credential-access
attack.privilege-escalation
attack.t1562.002
attack.t1547.001
attack.t1505.005
attack.t1556.002
attack.t1562
attack.t1574.007
attack.t1564.002
attack.t1546.008
attack.t1546.007
attack.t1547.014
attack.t1547.010
attack.t1547.002
attack.t1557
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Child Process Of 3CXDesktopApp
calendar
Oct 23, 2025
·
attack.command-and-control
attack.execution
attack.defense-evasion
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Registry File Imported Via Reg.EXE
calendar
Oct 23, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Vivaldi_elf.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Waveedit.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential WWlib.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process of KeyScrambler.exe
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1203
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Using Reg.EXE
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.impact
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Via Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.impact
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Create Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Powershell Detect Virtualization Environment
calendar
Oct 23, 2025
·
attack.discovery
attack.defense-evasion
attack.t1497.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Install a DLL in System Directory
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.credential-access
attack.t1556.002
·
Share on:
twitter
facebook
linkedin
copy
Powershell Keylogging
calendar
Oct 23, 2025
·
attack.credential-access
attack.collection
attack.t1056.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell LocalAccount Manipulation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Web Access Feature Enabled Via DISM
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Powershell WMI Persistence
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
Powerview Add-DomainObjectAcl DCSync AD Extend Right
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Privileged Account Creation
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Privileged User Has Been Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1136.001
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
ProcessHacker Privilege Elevation
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Process Hacker Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
cve.2021-21551
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PUA - System Informer Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
RedMimicry Winnti Playbook Registry Manipulation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Reg Add Suspicious Paths
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Regedit as Trusted Installer
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Registry Explorer Policy Modification
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Hide Function from User
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Manipulation via WMI Stdregprov
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.defense-evasion
attack.discovery
attack.t1047
attack.t1112
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Registry Persistence Mechanisms in Recycle Bin
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Registry Persistence via Explorer Run Key
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Registry-Free Process Scope COR_PROFILER
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.012
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Uncommon Extension
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Rejetto HTTP File Server RCE
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1190
attack.t1505.003
cve.2014-6287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Installation Execution
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Team Viewer Session Started On Linux Host
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Team Viewer Session Started On MacOS Host
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Team Viewer Session Started On Windows Host
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool Services Have Been Installed - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool Services Have Been Installed - System
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Registry Lateral Movement
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.lateral-movement
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via ATSvc
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.lateral-movement
attack.execution
attack.persistence
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via ITaskSchedulerService
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.lateral-movement
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via SASec
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.lateral-movement
attack.execution
attack.persistence
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Task Creation via ATSVC Named Pipe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.lateral-movement
attack.persistence
car.2013-05-004
car.2015-04-001
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Task Creation via ATSVC Named Pipe - Zeek
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.lateral-movement
attack.persistence
car.2013-05-004
car.2015-04-001
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Removal of Potential COM Hijacking Registry Keys
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Renamed Vmnat.exe Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Renamed ZOHO Dctask64 Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1036
attack.t1055.001
attack.t1202
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Restricted Software Access By SRP
calendar
Oct 23, 2025
·
attack.lateral-movement
attack.execution
attack.defense-evasion
attack.t1072
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering - ProcCreation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Roles Activated Too Frequently
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Activation Doesn't Require MFA
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Are Not Being Used
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Assigned Outside PIM
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Root Account Enable Via Dsenableroot
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1078
attack.t1078.001
attack.t1078.003
attack.initial-access
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
RottenPotato Like Attack Pattern
calendar
Oct 23, 2025
·
attack.collection
attack.privilege-escalation
attack.credential-access
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Configuration in Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Execution as Configured in Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Running Chrome VPN Extensions via the Registry 2 VPN Extension
calendar
Oct 23, 2025
·
attack.initial-access
attack.persistence
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation Masquerading as System Processes
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.defense-evasion
attack.t1036.004
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation with Curl and PowerShell Execution Combo
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.defense-evasion
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executed From A Suspicious Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executed Uncommon LOLBIN
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executing Encoded Payload from Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executing Payload from Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task/Job At
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Schtasks Creation Or Modification With SYSTEM Privileges
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Schtasks From Suspicious Folders
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
SCM Database Privileged Operation
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Sdclt Child Processes
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Process
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.002
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Registry Set
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.002
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Security Support Provider (SSP) Added to LSA Configuration
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.005
·
Share on:
twitter
facebook
linkedin
copy
Serpent Backdoor Payload Execution Via Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.006
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Service Binary in Suspicious Folder
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Service Installed By Unusual Client - Security
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Service Installed By Unusual Client - System
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Permissions Weakness Check
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.011
stp.2a
·
Share on:
twitter
facebook
linkedin
copy
Setuid and Setgid
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1548.001
·
Share on:
twitter
facebook
linkedin
copy
Setup16.EXE Execution With Custom .Lst File
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
Shell Open Registry Keys Manipulation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Sign-in Failure Due to Conditional Access Requirements Not Met
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins by Unknown Devices
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins from Non-Compliant Devices
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sliver C2 Default Service Installation
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware CommandLine Indicator
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Stale Accounts In A Privileged Role
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Startup/Logon Script Added to Group Policy Object
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
StoneDrill Service Install
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.g0064
attack.t1543.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Successful Authentications From Countries You Do Not Operate Out Of
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Successful Overpass the Hash Attempt
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.lateral-movement
attack.s0002
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Autorun Registry Modified via WMI
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1547.001
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Created as System
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process of SAP NetWeaver
calendar
Oct 23, 2025
·
attack.execution
attack.initial-access
attack.t1190
attack.persistence
attack.t1059.003
cve.2025-31324
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process of SAP NetWeaver - Linux
calendar
Oct 23, 2025
·
attack.execution
attack.initial-access
attack.t1190
attack.persistence
attack.t1059.003
cve.2025-31324
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Command Patterns In Scheduled Task Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Machine Password by PowerShell
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1557.001
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1557.001
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get-Variable.exe Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GrpConv Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GUP Usage
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Modification Of Scheduled Tasks
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Network Communication With IPFS
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.t1056
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outlook Macro Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell In Registry Run Keys
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Printer Driver Empty Manufacturer
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Spawned by CentreStack Portal AppPool
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.t1059.003
attack.t1505.003
cve.2025-30406
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RazerInstaller Explorer Subprocess
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1553
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Logon with Explicit Credentials
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Run Key from Download
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Invoking Inline VBScript
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation Involving Temp Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation via Masqueraded XML File
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.defense-evasion
attack.persistence
attack.t1036.005
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Name As GUID
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Write to System32 Tasks
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Schtasks Execution AppData Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Schtasks Schedule Type With High Privileges
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Schtasks Schedule Types
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ScreenSave Change by Reg.exe
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Screensaver Binary File Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service DACL Modification Via Set-Service Cmdlet
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Shim Database Patching Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SignIns From A Non Registered Device
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Startup Folder Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.t1204.002
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Unsigned Thor Scanner Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious VBScript UN2452 Pattern
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Velociraptor Child Process
calendar
Oct 23, 2025
·
attack.command-and-control
attack.persistence
attack.defense-evasion
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals PsService Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.discovery
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals PsSuspend Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.discovery
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Channel Reference Deletion
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
TAIDOOR RAT DLL Load
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.execution
attack.t1055.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Temporary Access Pass Added To An Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Terminal Server Client Connection History Cleared - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1070
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Too Many Global Admins
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Default Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-evasion
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Trusted Path Bypass via Windows Directory Spoofing
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.007
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
TrustedPath UAC Bypass Pattern
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Turla PNG Dropper Service
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.g0010
attack.t1543.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Turla Service Install
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.g0010
attack.t1543.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via Windows Firewall Snap-In Hijack
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Microsoft Office Trusted Location Added
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Outbound Kerberos Connection
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.t1558
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Userinit Child Process
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1037.001
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Binary Loaded From Suspicious Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Mfdetours.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Module Loaded by ClickOnce Application
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unusual Child Process of dns.exe
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Deletion by Dns.exe
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Modification by dns.exe
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Use of Legacy Authentication Protocols
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
User Access Blocked by Azure Conditional Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.credential-access
attack.initial-access
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Dscl
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via DseditGroup
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Sysadminctl
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added to an Administrator's Azure AD Role
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1098.003
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
User Added To Group With CA Policy Modification Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User Added To Highly Privileged Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added to Local Administrator Group
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.t1078
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added to Local Administrators Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added To Privilege Role
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User Added to Remote Desktop Users Group
calendar
Oct 23, 2025
·
attack.initial-access
attack.persistence
attack.lateral-movement
attack.t1133
attack.t1136.001
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'
calendar
Oct 23, 2025
·
attack.credential-access
attack.lateral-movement
attack.privilege-escalation
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
User Removed From Group With CA Policy Modification Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User State Changed From Guest To Member
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Added to Global or Device Admin Roles
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Authenticating To Other Azure AD Tenants
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
VBScript Payload Stored in Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Load By Name
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable HackSys Extreme Vulnerable Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable WinRing0 Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Wdigest CredGuard Registry Modification
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Wdigest Enable UseLogonCredential
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
WinDivert Driver Load
calendar
Oct 23, 2025
·
attack.credential-access
attack.collection
attack.defense-evasion
attack.t1599.001
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Log Access Tampering Via Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1547.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Windows Network Access Suspicious desktop.ini Action
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Windows Terminal Profile Settings Modification By Uncommon Process
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.015
·
Share on:
twitter
facebook
linkedin
copy
Winlogon Helper DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.004
·
Share on:
twitter
facebook
linkedin
copy
Winlogon Notify Key Logon Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.004
·
Share on:
twitter
facebook
linkedin
copy
Winnti Malware HK University Campaign
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Winnti Pipemon Characteristics
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
WinRAR Creating Files in Startup Locations
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
WMI Backdoor Exchange Transport Agent
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Event Subscription
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Command Line Event Consumer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1546.003
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Script Event Consumer File Write
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1546.003
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Writing Local Admin Share
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.lateral-movement
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Xwizard.EXE Execution From Non-Default Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Installation of WSL Kali-Linux
calendar
Oct 23, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
WSL Kali-Linux Usage
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
AWS STS GetCallerIdentity Enumeration Via TruffleHog
calendar
Oct 23, 2025
·
attack.discovery
attack.t1087.004
·
Share on:
twitter
facebook
linkedin
copy
Unsigned or Unencrypted SMB Connection to Share Established
calendar
Oct 23, 2025
·
attack.lateral-movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Windows Credential Editor (WCE) Execution
calendar
Oct 23, 2025
·
attack.credential-access
attack.t1003.001
attack.s0005
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Using Alias Cmdlets
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.execution
attack.t1027
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non PowerShell WSMAN COM Provider
calendar
Oct 23, 2025
·
attack.execution
attack.t1059.001
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
RunMRU Registry Key Deletion
calendar
Oct 22, 2025
·
attack.defense-evasion
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
AWS Bucket Deleted
calendar
Oct 22, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
AWS ConsoleLogin Failed Authentication
calendar
Oct 22, 2025
·
attack.credential-access
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
AWS EnableRegion Command Monitoring
calendar
Oct 22, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
AWS VPC Flow Logs Deleted
calendar
Oct 22, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Hacktool - EDR-Freeze Execution
calendar
Oct 21, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
PUA - TruffleHog Execution
calendar
Oct 21, 2025
·
attack.discovery
attack.credential-access
attack.t1083
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
PUA - TruffleHog Execution - Linux
calendar
Oct 21, 2025
·
attack.discovery
attack.credential-access
attack.t1083
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious JWT Token Search Via CLI
calendar
Oct 21, 2025
·
attack.credential-access
attack.t1528
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Potential LSASS Process Dump Via Procdump
calendar
Oct 20, 2025
·
attack.defense-evasion
attack.t1036
attack.credential-access
attack.t1003.001
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Local Accounts Discovery
calendar
Oct 20, 2025
·
attack.discovery
attack.t1033
attack.t1087.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Download Pattern
calendar
Oct 20, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
System Disk And Volume Reconnaissance Via Wmic.EXE
calendar
Oct 20, 2025
·
attack.execution
attack.discovery
attack.t1047
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Usage Of Web Request Commands And Cmdlets
calendar
Oct 20, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Usage Of Web Request Commands And Cmdlets - ScriptBlock
calendar
Oct 20, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Use Short Name Path in Image
calendar
Oct 20, 2025
·
attack.defense-evasion
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791)
calendar
Oct 20, 2025
·
attack.initial-access
attack.t1190
detection.emerging-threats
cve.2025-57791
·
Share on:
twitter
facebook
linkedin
copy
Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790)
calendar
Oct 20, 2025
·
attack.persistence
attack.t1505.003
detection.emerging-threats
cve.2025-57790
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Write to Webapps Root Directory
calendar
Oct 20, 2025
·
attack.persistence
attack.t1505.003
attack.initial-access
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
Mask System Power Settings Via Systemctl
calendar
Oct 20, 2025
·
attack.persistence
attack.impact
attack.t1653
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of GoAnywhere MFT Vulnerability
calendar
Oct 20, 2025
·
attack.initial-access
attack.t1190
attack.execution
attack.t1059.001
attack.persistence
attack.t1133
detection.emerging-threats
cve.2025-10035
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud Malicious GitHub Workflow Creation
calendar
Oct 19, 2025
·
attack.persistence
attack.credential-access
attack.t1552.001
attack.collection
attack.t1119
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud NPM Attack GitHub Activity
calendar
Oct 19, 2025
·
attack.persistence
attack.impact
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud NPM Package Malicious Exfiltration via Curl
calendar
Oct 19, 2025
·
attack.exfiltration
attack.t1041
attack.collection
attack.t1005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Linux Sudo Chroot Execution
calendar
Oct 19, 2025
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
calendar
Oct 19, 2025
·
attack.privilege-escalation
attack.t1068
cve.2025-32463
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-23397 Exploitation Attempt - SMB
calendar
Oct 18, 2025
·
attack.exfiltration
cve.2023-23397
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
BaaUpdate.exe Suspicious DLL Load
calendar
Oct 18, 2025
·
attack.defense-evasion
attack.t1218
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Firewall Configuration Discovery Via Netsh.EXE
calendar
Oct 18, 2025
·
attack.discovery
attack.t1016
·
Share on:
twitter
facebook
linkedin
copy
Suspicious BitLocker Access Agent Update Utility Execution
calendar
Oct 18, 2025
·
attack.defense-evasion
attack.t1218
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious C2 Activities
calendar
Oct 18, 2025
·
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Download and Execution Cradles
calendar
Oct 17, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
WinRAR Execution in Non-Standard Folder
calendar
Oct 17, 2025
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Account Tampering - Suspicious Failed Logon Reasons
calendar
Oct 17, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Alternate PowerShell Hosts - PowerShell Module
calendar
Oct 17, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
SMB Create Remote File Admin Share
calendar
Oct 17, 2025
·
attack.lateral-movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
File With Uncommon Extension Created By An Office Application
calendar
Oct 17, 2025
·
attack.t1204.002
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Office Application Initiated Network Connection Over Uncommon Ports
calendar
Oct 17, 2025
·
attack.defense-evasion
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Office Application Initiated Network Connection To Non-Local IP
calendar
Oct 17, 2025
·
attack.execution
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Access to Sensitive File Extensions
calendar
Oct 17, 2025
·
attack.collection
attack.t1039
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Access to Sensitive File Extensions - Zeek
calendar
Oct 17, 2025
·
attack.collection
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Volume Shadow Copy Vssapi.dll Load
calendar
Oct 17, 2025
·
attack.defense-evasion
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Suspicious WSMAN Provider Image Loads
calendar
Oct 17, 2025
·
attack.execution
attack.t1059.001
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Program Executed Using Proxy/Local Command Via SSH.EXE
calendar
Oct 16, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
calendar
Oct 16, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Alternate PowerShell Hosts Pipe
calendar
Oct 9, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Amsi.DLL Loaded Via LOLBIN Process
calendar
Oct 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Change PowerShell Policies to an Insecure Level
calendar
Oct 9, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Delete Defender Scan ShellEx Context Menu Registry Key
calendar
Oct 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Filter Driver Unloaded Via Fltmc.EXE
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1070
attack.t1562
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
Firewall Rule Deleted Via Netsh.EXE
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LaZagne Execution
calendar
Oct 9, 2025
·
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Internet Explorer DisableFirstRunCustomize Enabled
calendar
Oct 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
New Kernel Driver Via SC.EXE
calendar
Oct 9, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Antivirus Software DLL Sideloading
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential AutoLogger Sessions Tampering
calendar
Oct 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGCORE.DLL
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGHELP.DLL
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential JLI.dll Side-Loading
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PendingFileRenameOperations Tampering
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Visual Studio Tools for Office
calendar
Oct 9, 2025
·
attack.t1137.006
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potential Privileged System Service Operation - SeLoadDriverPrivilege
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Browser Launch From Document Reader Process
calendar
Oct 9, 2025
·
attack.execution
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Windows App Activity
calendar
Oct 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Core DLL Loaded By Non PowerShell Process
calendar
Oct 9, 2025
·
attack.t1059.001
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Deleted Mounted Share
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Module File Created By Non-PowerShell Process
calendar
Oct 9, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Process Creation Using Sysnative Folder
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Process Proxy Execution Via Squirrel.EXE
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.execution
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
PSScriptPolicyTest Creation By Uncommon Process
calendar
Oct 9, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Python Inline Command Execution
calendar
Oct 9, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Eventlog Clear
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1070.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msiexec Quiet Install From Remote Location
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Uncommon New Firewall Rule Added In Windows Firewall Exception List
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
Unsigned DLL Loaded by Windows Utility
calendar
Oct 9, 2025
·
attack.t1218.011
attack.t1218.010
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Windows Binaries Write Suspicious Extensions
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
IIS WebServer Access Logs Deleted
calendar
Oct 7, 2025
·
attack.defense-evasion
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
IIS WebServer Log Deletion via CommandLine Utilities
calendar
Oct 7, 2025
·
attack.defense-evasion
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
MMC Executing Files with Reversed Extensions Using RTLO Abuse
calendar
Oct 1, 2025
·
attack.execution
attack.t1204.002
attack.defense-evasion
attack.t1218.014
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
MMC Loading Script Engines DLLs
calendar
Oct 1, 2025
·
attack.execution
attack.defense-evasion
attack.t1059.005
attack.t1218.014
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Right-to-Left Override
calendar
Oct 1, 2025
·
attack.defense-evasion
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
Potential File Extension Spoofing Using Right-to-Left Override
calendar
Oct 1, 2025
·
attack.execution
attack.defense-evasion
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Processes Spawned by ConHost
calendar
Oct 1, 2025
·
attack.t1202
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Conhost.EXE
calendar
Oct 1, 2025
·
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
NodeJS Execution of JavaScript File
calendar
Oct 1, 2025
·
attack.execution
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
calendar
Oct 1, 2025
·
attack.execution
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potential Hello-World Scraper Botnet Activity
calendar
Oct 1, 2025
·
attack.reconnaissance
attack.t1595
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get Local Groups Information
calendar
Oct 1, 2025
·
attack.discovery
attack.t1069.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get Local Groups Information - PowerShell
calendar
Oct 1, 2025
·
attack.discovery
attack.t1069.001
·
Share on:
twitter
facebook
linkedin
copy
Python Image Load By Non-Python Process
calendar
Oct 1, 2025
·
attack.defense-evasion
attack.t1027.002
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Barracuda ESG Exploitation Indicators
calendar
Oct 1, 2025
·
attack.execution
attack.persistence
attack.defense-evasion
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Uninstall of Windows Defender Feature via PowerShell
calendar
Oct 1, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CoercedPotato Execution
calendar
Oct 1, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ShellExec_RunDLL Call Via Ordinal
calendar
Oct 1, 2025
·
attack.defense-evasion
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
DNS Query Tor .Onion Address - Sysmon
calendar
Oct 1, 2025
·
attack.command-and-control
attack.t1090.003
·
Share on:
twitter
facebook
linkedin
copy
Query Tor Onion Address - DNS Client
calendar
Oct 1, 2025
·
attack.command-and-control
attack.t1090.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Creation of .library-ms File — Potential CVE-2025-24054 Exploit
calendar
Sep 22, 2025
·
detection.emerging-threats
attack.credential-access
attack.t1187
cve.2025-24054
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Console History Access Attempt via History File
calendar
Sep 22, 2025
·
attack.credential-access
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
calendar
Sep 22, 2025
·
attack.command-and-control
attack.t1219
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Suspicious File Extension
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Service Tampering
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.impact
attack.t1489
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Renamed Visual Studio Code Tunnel Execution
calendar
Sep 22, 2025
·
attack.command-and-control
attack.t1071.001
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Visual Studio Code Tunnel Execution
calendar
Sep 22, 2025
·
attack.command-and-control
attack.t1071.001
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Certificate Use With No Strong Mapping
calendar
Sep 22, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
No Suitable Encryption Key Found For Generating Kerberos Ticket
calendar
Sep 22, 2025
·
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
New Service Creation Using Sc.EXE
calendar
Sep 22, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Notepad++ Plugins
calendar
Sep 22, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potential PsExec Remote Execution
calendar
Sep 22, 2025
·
attack.resource-development
attack.t1587.001
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Download From File Sharing Domains
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.persistence
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging/Processing Option Disabled On IIS Server
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.persistence
attack.t1562.002
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
HTTP Logging Disabled On IIS Server
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.persistence
attack.t1562.002
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
New Module Module Added To IIS Server
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.persistence
attack.t1562.002
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious File Download From File Sharing Domain Via PowerShell.EXE
calendar
Sep 22, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Previously Installed IIS Module Was Removed
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.persistence
attack.t1562.002
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Domain Via Curl.EXE
calendar
Sep 22, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Domain Via Wget.EXE
calendar
Sep 22, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Websites - File Stream
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Download From File Sharing Websites - File Stream
calendar
Sep 22, 2025
·
attack.defense-evasion
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution From Tmp Folder
calendar
Aug 29, 2025
·
attack.defense-evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Capabilities Discovery - Linux
calendar
Aug 28, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Copying Sensitive Files with Credential Data
calendar
Aug 28, 2025
·
attack.credential-access
attack.t1003.002
attack.t1003.003
car.2013-07-001
attack.s0404
·
Share on:
twitter
facebook
linkedin
copy
Curl Download And Execute Combination
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Diskshadow Script Mode - Execution From Potential Suspicious Location
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Diskshadow Script Mode - Uncommon Script Extension Execution
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DllUnregisterServer Function Call Via Msiexec.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Enumerate All Information With Whoami.EXE
calendar
Aug 28, 2025
·
attack.discovery
attack.t1033
car.2016-03-001
·
Share on:
twitter
facebook
linkedin
copy
Esentutl Steals Browser Information
calendar
Aug 28, 2025
·
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
File Deletion Via Del
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Forfiles Command Execution
calendar
Aug 28, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
IIS Native-Code Module Command Line Installation
calendar
Aug 28, 2025
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Insensitive Subfolder Search Via Findstr.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.credential-access
attack.command-and-control
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Kernel Memory Dump Via LiveKD
calendar
Aug 28, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Loaded Module Enumeration Via Tasklist.EXE
calendar
Aug 28, 2025
·
attack.t1003
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Lolbin Unregmp2.exe Use As Proxy
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Msiexec Quiet Installation
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
New Remote Desktop Connection Initiated Via Mstsc.EXE
calendar
Aug 28, 2025
·
attack.lateral-movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Port Forwarding Activity Via SSH.EXE
calendar
Aug 28, 2025
·
attack.command-and-control
attack.lateral-movement
attack.t1572
attack.t1021.001
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Command Execution Using Msdt.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Command Execution Via FTP.EXE
calendar
Aug 28, 2025
·
attack.execution
attack.t1059
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Execution of Sysinternals Tools
calendar
Aug 28, 2025
·
attack.resource-development
attack.t1588.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation To LOCAL SYSTEM
calendar
Aug 28, 2025
·
attack.resource-development
attack.t1587.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Regsvr32 Commandline Flag Anomaly
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Cabinet File Expansion
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Ping/Copy Command Combination
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Process Memory Dump via RdrLeakDiag.EXE
calendar
Aug 28, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
PsExec/PAExec Escalation to LOCAL SYSTEM
calendar
Aug 28, 2025
·
attack.resource-development
attack.t1587.001
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Regsvr32 Calc Pattern
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Raspberry Robin Initial Execution From External Drive
calendar
Aug 28, 2025
·
attack.execution
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Raspberry Robin Subsequent Execution of Commands
calendar
Aug 28, 2025
·
attack.execution
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Rebuild Performance Counter Values Via Lodctr.EXE
calendar
Aug 28, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Remote File Download Via Findstr.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.credential-access
attack.command-and-control
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Renamed ProcDump Execution
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Replace.exe Usage
calendar
Aug 28, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Response File Execution Via Odbcconf.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Cabinet File Execution Via Msdt.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DLL Loaded via CertOC.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msiexec Execute Arbitrary DLL
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Ping/Del Command Combination
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Response File Execution Via Odbcconf.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Installation Script
calendar
Aug 28, 2025
·
attack.persistence
attack.privilege-escalation
car.2013-09-005
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Use of PsLogList
calendar
Aug 28, 2025
·
attack.discovery
attack.t1087
attack.t1087.001
attack.t1087.002
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Update
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Sysinternals Sysmon
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Recovery Environment Disabled Via Reagentc
calendar
Aug 28, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
XSL Script Execution Via WMIC.EXE
calendar
Aug 28, 2025
·
attack.defense-evasion
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
Active Directory Database Snapshot Via ADExplorer
calendar
Aug 14, 2025
·
attack.discovery
attack.t1087.002
attack.t1069.002
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
ADExplorer Writing Complete AD Snapshot Into .dat File
calendar
Aug 14, 2025
·
attack.discovery
attack.t1087.002
attack.t1069.002
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
Create Volume Shadow Copy with Powershell
calendar
Aug 14, 2025
·
attack.credential-access
attack.t1003.003
attack.ds0005
·
Share on:
twitter
facebook
linkedin
copy
Potential WerFault ReflectDebugger Registry Value Abuse
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Active Directory Database Snapshot Via ADExplorer
calendar
Aug 14, 2025
·
attack.discovery
attack.t1087.002
attack.t1069.002
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
AWS CloudTrail Important Change
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.t1562.008
·
Share on:
twitter
facebook
linkedin
copy
AWS Config Disabling Channel/Recorder
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.t1562.008
·
Share on:
twitter
facebook
linkedin
copy
Cloudflared Tunnels Related DNS Requests
calendar
Aug 14, 2025
·
attack.command-and-control
attack.t1071.001
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Disabling Multi Factor Authentication
calendar
Aug 14, 2025
·
attack.persistence
attack.defense-evasion
attack.credential-access
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Devtunnels Domain
calendar
Aug 14, 2025
·
attack.command-and-control
attack.t1071.001
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
New Federated Domain Added
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.002
·
Share on:
twitter
facebook
linkedin
copy
New Network ACL Entry Added
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.t1562.007
·
Share on:
twitter
facebook
linkedin
copy
New Network Route Added
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.t1562.007
·
Share on:
twitter
facebook
linkedin
copy
Potential Bucket Enumeration on AWS
calendar
Aug 14, 2025
·
attack.discovery
attack.t1580
attack.t1619
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Inbox Forwarding Identity Protection
calendar
Aug 14, 2025
·
attack.t1114.003
attack.collection
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated To BTunnels Domains
calendar
Aug 14, 2025
·
attack.exfiltration
attack.command-and-control
attack.t1567
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - MeshAgent Command Execution via MeshCentral
calendar
Aug 14, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated To Mega.nz
calendar
Jul 30, 2025
·
attack.exfiltration
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Dropbox API Usage
calendar
Jul 30, 2025
·
attack.command-and-control
attack.exfiltration
attack.t1105
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated To Visual Studio Code Tunnels Domain
calendar
Jul 30, 2025
·
attack.exfiltration
attack.command-and-control
attack.t1567
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated To Cloudflared Tunnels Domains
calendar
Jul 30, 2025
·
attack.exfiltration
attack.command-and-control
attack.t1567
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Process Initiated Network Connection To Ngrok Domain
calendar
Jul 30, 2025
·
attack.exfiltration
attack.command-and-control
attack.t1567
attack.t1572
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated To DevTunnels Domain
calendar
Jul 30, 2025
·
attack.exfiltration
attack.command-and-control
attack.t1567.001
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non-Browser Network Communication With Telegram API
calendar
Jul 30, 2025
·
attack.command-and-control
attack.exfiltration
attack.t1102
attack.t1567
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Double Extension Files
calendar
Jul 29, 2025
·
attack.defense-evasion
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created in Outlook Temporary Directory
calendar
Jul 29, 2025
·
attack.initial-access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
calendar
Jul 28, 2025
·
attack.initial-access
attack.t1190
cve.2025-53770
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Write to SharePoint Layouts Directory
calendar
Jul 28, 2025
·
attack.initial-access
attack.t1190
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Change User Agents with WebRequest
calendar
Jul 28, 2025
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated IP Download Activity
calendar
Jul 28, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL File Download Via PowerShell Invoke-WebRequest
calendar
Jul 28, 2025
·
attack.command-and-control
attack.execution
attack.t1059.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script With File Upload Capabilities
calendar
Jul 28, 2025
·
attack.exfiltration
attack.t1020
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invoke-WebRequest Execution
calendar
Jul 28, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invoke-WebRequest Execution With DirectIP
calendar
Jul 28, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Disabling Windows Defender WMI Autologger Session via Reg.exe
calendar
Jul 28, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
calendar
Jul 28, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Context Menu Removed
calendar
Jul 28, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Threat Severity Default Action Modified
calendar
Jul 28, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
calendar
Jul 21, 2025
·
attack.initial-access
attack.t1190
cve.2025-53770
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS
calendar
Jul 21, 2025
·
attack.initial-access
attack.t1190
cve.2025-53770
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Volume Shadow Copy VSS_PS.dll Load
calendar
Jul 14, 2025
·
attack.defense-evasion
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Transferring Files with Credential Data via Network Shares
calendar
Jul 14, 2025
·
attack.credential-access
attack.t1003.002
attack.t1003.001
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
ADS Zone.Identifier Deleted By Uncommon Application
calendar
Jul 8, 2025
·
attack.defense-evasion
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Active Directory Reconnaissance/Enumeration Via LDAP
calendar
Jul 8, 2025
·
attack.discovery
attack.t1069.002
attack.t1087.002
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Or Script Dropper Via PowerShell
calendar
Jul 8, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation By Uncommon Source Image
calendar
Jul 8, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation In Uncommon Target Image
calendar
Jul 8, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Sysmon as Execution Parent
calendar
Jul 8, 2025
·
attack.privilege-escalation
attack.t1068
cve.2022-41120
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Commandlets - PoshModule
calendar
Jul 7, 2025
·
attack.execution
attack.discovery
attack.t1482
attack.t1087
attack.t1087.001
attack.t1087.002
attack.t1069.001
attack.t1069.002
attack.t1069
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Commandlets - ProcessCreation
calendar
Jul 7, 2025
·
attack.execution
attack.discovery
attack.t1482
attack.t1087
attack.t1087.001
attack.t1087.002
attack.t1069.001
attack.t1069.002
attack.t1069
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Commandlets - ScriptBlock
calendar
Jul 7, 2025
·
attack.execution
attack.discovery
attack.t1482
attack.t1087
attack.t1087.001
attack.t1087.002
attack.t1069.001
attack.t1069.002
attack.t1069
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Scripts - FileCreation
calendar
Jul 7, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Scripts - PoshModule
calendar
Jul 7, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential AS-REP Roasting via Kerberos TGT Requests
calendar
Jul 7, 2025
·
Share on:
twitter
facebook
linkedin
copy
Proxy Execution via Vshadow
calendar
Jul 3, 2025
·
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Doppelanger LSASS Dumper Execution
calendar
Jul 3, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Filter Driver Disallowed On Dev Drive - Registry
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Capsh Shell Invocation - Linux
calendar
Jul 1, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Data Export From MSSQL Table Via BCP.EXE
calendar
Jul 1, 2025
·
attack.execution
attack.exfiltration
attack.t1048
·
Share on:
twitter
facebook
linkedin
copy
Disk Image Creation Via Hdiutil - MacOS
calendar
Jul 1, 2025
·
attack.exfiltration
·
Share on:
twitter
facebook
linkedin
copy
Disk Image Mounting Via Hdiutil - MacOS
calendar
Jul 1, 2025
·
attack.initial-access
attack.collection
attack.t1566.001
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Put.io - DNS Client
calendar
Jul 1, 2025
·
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Driver Added To Disallowed Images In HVCI - Registry
calendar
Jul 1, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Emotet Loader Execution Via .LNK File
calendar
Jul 1, 2025
·
attack.execution
attack.t1059.006
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
FakeUpdates/SocGholish Activity
calendar
Jul 1, 2025
·
attack.execution
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpWSUS/WSUSpendu Execution
calendar
Jul 1, 2025
·
attack.execution
attack.lateral-movement
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
Hidden Flag Set On File/Directory Via Chflags - MacOS
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.credential-access
attack.command-and-control
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Inline Python Execution - Spawn Shell Via OS System Library
calendar
Jul 1, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Multi Factor Authentication Disabled For User Account
calendar
Jul 1, 2025
·
attack.credential-access
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Rundll32.EXE Execution of UDL File
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.execution
attack.command-and-control
attack.t1218.011
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
Process Deletion of Its Own Executable
calendar
Jul 1, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Shell Execution GCC - Linux
calendar
Jul 1, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Shell Execution via Find - Linux
calendar
Jul 1, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Shell Execution via Flock - Linux
calendar
Jul 1, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Shell Execution via Git - Linux
calendar
Jul 1, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Shell Execution via Nice - Linux
calendar
Jul 1, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Shell Invocation via Env Command - Linux
calendar
Jul 1, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Shell Invocation Via Ssh - Linux
calendar
Jul 1, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of Wermgr.EXE
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download From File-Sharing Website Via Bitsadmin
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.persistence
attack.t1197
attack.s0190
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invocation of Shell via AWK - Linux
calendar
Jul 1, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Masquerading As SvcHost.EXE
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote AppX Package Locations
calendar
Jul 1, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
User Risk and MFA Registration Policy Updated
calendar
Jul 1, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Wusa.EXE Executed By Parent Process Located In Suspicious Location
calendar
Jul 1, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download and Execute Pattern via Curl/Wget
calendar
Jun 25, 2025
·
attack.execution
attack.t1059.004
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
PowerShell MSI Install via WindowsInstaller COM From Remote Location
calendar
Jun 25, 2025
·
attack.execution
attack.t1059.001
attack.defense-evasion
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Potential MeshAgent Execution - MacOS
calendar
Jun 24, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Potential MeshAgent Execution - Windows
calendar
Jun 24, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Renamed MeshAgent Execution - MacOS
calendar
Jun 24, 2025
·
attack.command-and-control
attack.defense-evasion
attack.t1219.002
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Renamed MeshAgent Execution - Windows
calendar
Jun 24, 2025
·
attack.command-and-control
attack.defense-evasion
attack.t1219.002
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Exploitation Framework Detection
calendar
Jun 13, 2025
·
attack.execution
attack.t1203
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Atera Agent Installation
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To AzureWebsites.NET By Non-Browser Process
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Remote Access Software Domain From Non-Browser App
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
GoToAssist Temporary Installation Artefact
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Inveigh Execution Artefacts
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Hijack Legit RDP Session to Move Laterally
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Installation of TeamViewer Desktop
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Mesh Agent Service Installation
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Mstsc.EXE Execution With Local RDP File
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Amazon SSM Agent Hijacking
calendar
Jun 13, 2025
·
attack.command-and-control
attack.persistence
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential CSharp Streamer RAT Loading .NET Executable Image
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Amazon SSM Agent Hijacking
calendar
Jun 13, 2025
·
attack.command-and-control
attack.persistence
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential SocGholish Second Stage C2 DNS Query
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
QuickAssist Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Anydesk Execution From Suspicious Folder
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Incoming Connection
calendar
Jun 13, 2025
·
attack.persistence
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Piped Password Via CLI
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - GoToAssist Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - LogMeIn Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - NetSupport Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Simple Help Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - UltraViewer Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect Temporary Installation Artefact
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Binary Writes Via AnyDesk
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Mstsc.EXE Execution With Local RDP File
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious TSCON Start as SYSTEM
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
TacticalRMM Service Installation
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Domain Query By Non-TeamViewer Application
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Remote Session
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Use of UltraVNC Remote Access Software
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
HKTL - SharpSuccessor Privilege Escalation Tool Execution
calendar
Jun 12, 2025
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Common Malware Hosting and Shortener Services
calendar
Jun 12, 2025
·
attack.command-and-control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
APT40 Dropbox Tool User Agent
calendar
Jun 12, 2025
·
attack.command-and-control
attack.t1071.001
attack.exfiltration
attack.t1567.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Chafer Malware URL Pattern
calendar
Jun 12, 2025
·
attack.command-and-control
attack.t1071.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ComRAT Network Communication
calendar
Jun 12, 2025
·
attack.defense-evasion
attack.command-and-control
attack.t1071.001
attack.g0010
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
calendar
Jun 12, 2025
·
attack.persistence
attack.execution
attack.defense-evasion
attack.t1112
cve.2020-1048
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Ursnif Malware C2 URL Pattern
calendar
Jun 12, 2025
·
attack.initial-access
attack.t1566.001
attack.execution
attack.t1204.002
attack.command-and-control
attack.t1071.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Ursnif Malware Download URL Pattern
calendar
Jun 12, 2025
·
attack.command-and-control
attack.t1071.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
MSHTA Execution with Suspicious File Extensions
calendar
Jun 11, 2025
·
attack.defense-evasion
attack.t1140
attack.t1218.005
attack.execution
attack.t1059.007
cve.2020-1599
·
Share on:
twitter
facebook
linkedin
copy
Potential Java WebShell Upload in SAP NetViewer Server
calendar
Jun 11, 2025
·
attack.persistence
attack.t1505.003
detection.emerging-threats
cve.2025-31324
·
Share on:
twitter
facebook
linkedin
copy
Potential SAP NetViewer Webshell Command Execution
calendar
Jun 11, 2025
·
attack.persistence
attack.t1505.003
attack.initial-access
attack.t1190
detection.emerging-threats
cve.2025-31324
·
Share on:
twitter
facebook
linkedin
copy
RegAsm.EXE Execution Without CommandLine Flags or Files
calendar
Jun 11, 2025
·
attack.defense-evasion
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
MSSQL Destructive Query
calendar
Jun 11, 2025
·
attack.exfiltration
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
calendar
Jun 5, 2025
·
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Double Extension File Execution
calendar
Jun 5, 2025
·
attack.initial-access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Local Groups Discovery - Linux
calendar
Jun 5, 2025
·
attack.discovery
attack.t1069.001
·
Share on:
twitter
facebook
linkedin
copy
Access of Sudoers File Content
calendar
Jun 5, 2025
·
attack.reconnaissance
attack.t1592.004
·
Share on:
twitter
facebook
linkedin
copy
AddinUtil.EXE Execution From Uncommon Directory
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
AspNetCompiler Execution
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious ASP.NET Compilation Via AspNetCompiler
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Via WCHAR/CHAR
calendar
Jun 4, 2025
·
attack.execution
attack.t1059.001
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Ransomware Detection
calendar
Jun 4, 2025
·
attack.t1486
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Base64 Encoded PowerShell Command Detected
calendar
Jun 4, 2025
·
attack.t1027
attack.defense-evasion
attack.execution
attack.t1140
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Container With A hostPath Mount Created
calendar
Jun 4, 2025
·
attack.t1611
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Deployment Deleted From Kubernetes Cluster
calendar
Jun 4, 2025
·
attack.t1498
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
DNS Query Request By QuickAssist.EXE
calendar
Jun 4, 2025
·
attack.command-and-control
attack.initial-access
attack.lateral-movement
attack.t1071.001
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
DPAPI Backup Keys And Certificate Export Activity IOC
calendar
Jun 4, 2025
·
attack.credential-access
attack.t1555
attack.t1552.004
·
Share on:
twitter
facebook
linkedin
copy
F5 BIG-IP iControl Rest API Command Execution - Webserver
calendar
Jun 4, 2025
·
attack.execution
attack.t1190
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Hacktool Execution - Imphash
calendar
Jun 4, 2025
·
attack.credential-access
attack.resource-development
attack.t1588.002
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
Interesting Service Enumeration Via Sc.EXE
calendar
Jun 4, 2025
·
attack.t1003
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Secrets Enumeration
calendar
Jun 4, 2025
·
attack.t1552.007
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Live Memory Dump Using Powershell
calendar
Jun 4, 2025
·
attack.credential-access
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
MMC20 Lateral Movement
calendar
Jun 4, 2025
·
attack.execution
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Octopus Scanner Malware
calendar
Jun 4, 2025
·
attack.initial-access
attack.t1195
attack.t1195.001
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - FTP Login Attempt
calendar
Jun 4, 2025
·
attack.initial-access
attack.exfiltration
attack.lateral-movement
attack.t1190
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote Command Execution In Pod Container
calendar
Jun 4, 2025
·
attack.t1609
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Sidecar Injection Into Running Deployment
calendar
Jun 4, 2025
·
attack.t1609
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious ODBC Driver Registered
calendar
Jun 4, 2025
·
attack.credential-access
attack.persistence
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Web Access Installation - PsScript
calendar
Jun 4, 2025
·
attack.persistence
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Privileged Container Deployed
calendar
Jun 4, 2025
·
attack.t1611
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Psexec Execution
calendar
Jun 4, 2025
·
attack.execution
attack.lateral-movement
attack.t1569
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
PUA - Advanced IP/Port Scanner Update Check
calendar
Jun 4, 2025
·
attack.discovery
attack.reconnaissance
attack.t1590
·
Share on:
twitter
facebook
linkedin
copy
PUA - Crassus Execution
calendar
Jun 4, 2025
·
attack.discovery
attack.reconnaissance
attack.t1590.001
·
Share on:
twitter
facebook
linkedin
copy
Rare Subscription-level Operations In Azure
calendar
Jun 4, 2025
·
attack.t1003
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
RBAC Permission Enumeration Attempt
calendar
Jun 4, 2025
·
attack.t1069.003
attack.t1087.004
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Remote DCOM/WMI Lateral Movement
calendar
Jun 4, 2025
·
attack.lateral-movement
attack.execution
attack.t1021.003
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Remote Server Service Abuse for Lateral Movement
calendar
Jun 4, 2025
·
attack.lateral-movement
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Renamed Powershell Under Powershell Channel
calendar
Jun 4, 2025
·
attack.execution
attack.defense-evasion
attack.t1059.001
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 UNC Path Execution
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.execution
attack.lateral-movement
attack.t1021.002
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download from Office Domain
calendar
Jun 4, 2025
·
attack.command-and-control
attack.resource-development
attack.t1105
attack.t1608
·
Share on:
twitter
facebook
linkedin
copy
Suspicious External WebDAV Execution
calendar
Jun 4, 2025
·
attack.initial-access
attack.resource-development
attack.t1584
attack.t1566
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process By Web Server Process
calendar
Jun 4, 2025
·
attack.persistence
attack.initial-access
attack.t1505.003
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
Wmiexec Default Output File
calendar
Jun 4, 2025
·
attack.lateral-movement
attack.execution
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Writing Of Malicious Files To The Fonts Folder
calendar
Jun 4, 2025
·
attack.t1211
attack.t1059
attack.defense-evasion
attack.persistence
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated PowerShell MSI Install via WindowsInstaller COM
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.t1027.010
attack.t1218.007
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Arcadyan Router Exploitations
calendar
Jun 4, 2025
·
attack.initial-access
attack.t1190
cve.2021-20090
cve.2021-20091
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Azure Container Registry Created or Deleted
calendar
Jun 4, 2025
·
attack.impact
attack.t1485
attack.t1496
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Cluster Created or Deleted
calendar
Jun 4, 2025
·
attack.impact
attack.t1485
attack.t1496
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Network Policy Change
calendar
Jun 4, 2025
·
attack.impact
attack.credential-access
attack.t1485
attack.t1496
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted
calendar
Jun 4, 2025
·
attack.impact
attack.credential-access
attack.t1485
attack.t1496
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Secret or Config Object Access
calendar
Jun 4, 2025
·
attack.impact
attack.t1485
attack.t1496
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Sensitive Role Access
calendar
Jun 4, 2025
·
attack.impact
attack.t1485
attack.t1496
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Service Account Modified or Deleted
calendar
Jun 4, 2025
·
attack.impact
attack.t1531
attack.t1485
attack.t1496
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Buffer Overflow Attempts
calendar
Jun 4, 2025
·
attack.t1068
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Connection Proxy
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.command-and-control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Cscript/Wscript Potentially Suspicious Child Process
calendar
Jun 4, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
calendar
Jun 4, 2025
·
attack.credential-access
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpView Execution
calendar
Jun 4, 2025
·
attack.discovery
attack.t1049
attack.t1069.002
attack.t1482
attack.t1135
attack.t1033
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SysmonEnte Execution
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - TruffleSnout Execution
calendar
Jun 4, 2025
·
attack.discovery
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Event Auditing Disabled
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
MSI Installation From Web
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.t1218
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
MSMQ Corrupted Packet Encountered
calendar
Jun 4, 2025
·
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Mstsc.EXE Execution From Uncommon Parent
calendar
Jun 4, 2025
·
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
PaperCut MF/NG Potential Exploitation
calendar
Jun 4, 2025
·
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PetitPotam Suspicious Kerberos TGT Request
calendar
Jun 4, 2025
·
attack.credential-access
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Portable Gpg.EXE Execution
calendar
Jun 4, 2025
·
attack.impact
attack.t1486
·
Share on:
twitter
facebook
linkedin
copy
Possible DCSync Attack
calendar
Jun 4, 2025
·
attack.t1033
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Possible Exploitation of Exchange RCE CVE-2021-42321
calendar
Jun 4, 2025
·
attack.lateral-movement
attack.t1210
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Publicly Accessible RDP Service
calendar
Jun 4, 2025
·
attack.lateral-movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Recon Activity via SASec
calendar
Jun 4, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Remote Encrypting File System Abuse
calendar
Jun 4, 2025
·
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Remote Event Log Recon
calendar
Jun 4, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Remote File Copy
calendar
Jun 4, 2025
·
attack.command-and-control
attack.lateral-movement
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Remote Printing Abuse for Lateral Movement
calendar
Jun 4, 2025
·
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Remote Registry Recon
calendar
Jun 4, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Recon via AtScv
calendar
Jun 4, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Recon via ITaskSchedulerService
calendar
Jun 4, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Remote Server Service Abuse
calendar
Jun 4, 2025
·
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
SharpHound Recon Account Discovery
calendar
Jun 4, 2025
·
attack.t1087
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
SharpHound Recon Sessions
calendar
Jun 4, 2025
·
attack.discovery
attack.t1033
·
Share on:
twitter
facebook
linkedin
copy
Start of NT Virtual DOS Machine
calendar
Jun 4, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Log Entries
calendar
Jun 4, 2025
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Microsoft Office Child Process
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.execution
attack.t1047
attack.t1204.002
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Named Pipes
calendar
Jun 4, 2025
·
attack.g0010
attack.execution
attack.t1106
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Connection to Active Directory Web Services
calendar
Jun 4, 2025
·
attack.discovery
attack.t1087
·
Share on:
twitter
facebook
linkedin
copy
Access To Crypto Currency Wallets By Uncommon Applications
calendar
Jun 2, 2025
·
attack.t1003
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Access To Potentially Sensitive Sysvol Files By Uncommon Applications
calendar
Jun 2, 2025
·
attack.credential-access
attack.t1552.006
·
Share on:
twitter
facebook
linkedin
copy
Access To Windows Credential History File By Uncommon Applications
calendar
Jun 2, 2025
·
attack.credential-access
attack.t1555.004
·
Share on:
twitter
facebook
linkedin
copy
Access To Windows DPAPI Master Keys By Uncommon Applications
calendar
Jun 2, 2025
·
attack.credential-access
attack.t1555.004
·
Share on:
twitter
facebook
linkedin
copy
BitLockerTogo.EXE Execution
calendar
Jun 2, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Credential Manager Access By Uncommon Applications
calendar
Jun 2, 2025
·
attack.t1003
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - File Creation Activity
calendar
Jun 2, 2025
·
attack.defense-evasion
attack.t1562.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes CronJob/Job Modification
calendar
Jun 2, 2025
·
attack.persistence
attack.privilege-escalation
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Rolebinding Modification
calendar
Jun 2, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Secrets Modified or Deleted
calendar
Jun 2, 2025
·
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Teams Sensitive File Access By Uncommon Applications
calendar
Jun 2, 2025
·
attack.credential-access
attack.t1528
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated To AzureWebsites.NET By Non-Browser Process
calendar
Jun 2, 2025
·
attack.command-and-control
attack.t1102
attack.t1102.001
·
Share on:
twitter
facebook
linkedin
copy
PDF File Created By RegEdit.EXE
calendar
Jun 2, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential APT FIN7 Exploitation Activity
calendar
Jun 2, 2025
·
attack.execution
attack.t1059.001
attack.t1059.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CVE-2024-37085 - Suspicious Creation Of ESX Admins Group
calendar
Jun 2, 2025
·
attack.execution
cve.2024-37085
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity
calendar
Jun 2, 2025
·
attack.execution
cve.2024-37085
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Process Launched Without Image Name
calendar
Jun 2, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Renamed BOINC Client Execution
calendar
Jun 2, 2025
·
attack.defense-evasion
attack.t1553
·
Share on:
twitter
facebook
linkedin
copy
Renamed Microsoft Teams Execution
calendar
Jun 2, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
MSSQL Server Failed Logon From External Network
calendar
May 31, 2025
·
attack.credential-access
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Deno File Written from Remote Source
calendar
May 27, 2025
·
attack.execution
attack.t1204
attack.t1059.007
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Impacket File Indicators
calendar
May 27, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Katz Stealer Domains
calendar
May 26, 2025
·
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Katz Stealer Domains - Network
calendar
May 26, 2025
·
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Enumeration for 3rd Party Creds From CLI
calendar
May 26, 2025
·
attack.credential-access
attack.t1552.002
·
Share on:
twitter
facebook
linkedin
copy
Katz Stealer DLL Loaded
calendar
May 26, 2025
·
attack.execution
attack.t1129
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Katz Stealer Suspicious User-Agent
calendar
May 26, 2025
·
attack.command-and-control
attack.t1071.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Registry Export of Third-Party Credentials
calendar
May 26, 2025
·
attack.credential-access
attack.t1552.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Access to Browser Credential Storage
calendar
May 26, 2025
·
attack.credential-access
attack.t1555.003
attack.discovery
attack.t1217
·
Share on:
twitter
facebook
linkedin
copy
Crash Dump Created By Operating System
calendar
May 21, 2025
·
attack.credential-access
attack.collection
attack.t1003.002
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
ESXi Account Creation Via ESXCLI
calendar
May 21, 2025
·
attack.persistence
attack.execution
attack.t1136
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ESXi Network Configuration Discovery Via ESXCLI
calendar
May 21, 2025
·
attack.discovery
attack.execution
attack.t1033
attack.t1007
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ESXi Storage Information Discovery Via ESXCLI
calendar
May 21, 2025
·
attack.discovery
attack.execution
attack.t1033
attack.t1007
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ESXi Syslog Configuration Change Via ESXCLI
calendar
May 21, 2025
·
attack.defense-evasion
attack.execution
attack.t1562.001
attack.t1562.003
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ESXi System Information Discovery Via ESXCLI
calendar
May 21, 2025
·
attack.discovery
attack.execution
attack.t1033
attack.t1007
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ESXi VM Kill Via ESXCLI
calendar
May 21, 2025
·
attack.execution
attack.impact
attack.t1059.012
attack.t1529
·
Share on:
twitter
facebook
linkedin
copy
ESXi VM List Discovery Via ESXCLI
calendar
May 21, 2025
·
attack.discovery
attack.execution
attack.t1033
attack.t1007
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ESXi VSAN Information Discovery Via ESXCLI
calendar
May 21, 2025
·
attack.discovery
attack.execution
attack.t1033
attack.t1007
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script
calendar
May 20, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Active Directory Certificate Services Denied Certificate Enrollment Request
calendar
May 20, 2025
·
attack.credential-access
attack.defense-evasion
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Pod In System Namespace
calendar
May 20, 2025
·
attack.defense-evasion
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Events Deleted
calendar
May 20, 2025
·
attack.defense-evasion
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Mount Execution With Hidepid Parameter
calendar
May 20, 2025
·
attack.credential-access
attack.defense-evasion
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Outlook EnableUnsafeClientMailRules Setting Enabled
calendar
May 20, 2025
·
attack.execution
attack.defense-evasion
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed BrowserCore.EXE Execution
calendar
May 20, 2025
·
attack.credential-access
attack.defense-evasion
attack.t1528
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Silenttrinity Stager Msbuild Activity
calendar
May 20, 2025
·
attack.execution
attack.defense-evasion
attack.t1127.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Child Process From Outlook
calendar
May 20, 2025
·
attack.execution
attack.defense-evasion
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Use of CSharp Interactive Console
calendar
May 20, 2025
·
attack.execution
attack.defense-evasion
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Browser Started with Remote Debugging
calendar
May 20, 2025
·
attack.credential-access
attack.collection
attack.t1185
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - HTTPPROXY Login Attempt
calendar
May 20, 2025
·
attack.initial-access
attack.defense-evasion
attack.command-and-control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Outbound Network Connection Initiated By Microsoft Dialer
calendar
May 20, 2025
·
attack.execution
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Curl File Upload - Linux
calendar
May 20, 2025
·
attack.exfiltration
attack.command-and-control
attack.t1567
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Hacktool Execution - PE Metadata
calendar
May 20, 2025
·
attack.credential-access
attack.resource-development
attack.t1588.002
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
New Kubernetes Service Account Created
calendar
May 20, 2025
·
attack.persistence
attack.t1136
·
Share on:
twitter
facebook
linkedin
copy
Possible DC Shadow Attack
calendar
May 20, 2025
·
attack.credential-access
attack.defense-evasion
attack.t1207
·
Share on:
twitter
facebook
linkedin
copy
Potential Discovery Activity Via Dnscmd.EXE
calendar
May 20, 2025
·
attack.discovery
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Windows Defender Tampering Via Wmic.EXE
calendar
May 20, 2025
·
attack.defense-evasion
attack.execution
attack.t1047
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SQL Query
calendar
May 20, 2025
·
attack.exfiltration
attack.initial-access
attack.privilege-escalation
attack.persistence
attack.t1190
attack.t1505.001
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Outbound Kerberos Connection - Security
calendar
May 20, 2025
·
attack.lateral-movement
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Windows LAPS Credential Dump From Entra ID
calendar
May 20, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
calendar
May 20, 2025
·
attack.initial-access
attack.t1190
attack.execution
attack.t1203
cve.2025-4427
cve.2025-4428
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Communication To LocaltoNet Tunneling Service Initiated
calendar
May 20, 2025
·
attack.command-and-control
attack.t1572
attack.t1090
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Communication To LocaltoNet Tunneling Service Initiated - Linux
calendar
May 20, 2025
·
attack.command-and-control
attack.t1572
attack.t1090
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21
calendar
May 20, 2025
·
attack.initial-access
attack.t1190
cve.2023-1389
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DSInternals Suspicious PowerShell Cmdlets
calendar
May 20, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
DSInternals Suspicious PowerShell Cmdlets - ScriptBlock
calendar
May 20, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec File Indicators
calendar
May 20, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - RemoteKrbRelay Execution
calendar
May 20, 2025
·
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpDPAPI Execution
calendar
May 20, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor Enforced Paging Translation Disabled
calendar
May 20, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Configuration Persistence
calendar
May 20, 2025
·
attack.persistence
attack.defense-evasion
attack.t1553.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Execution Via RunDLL32.EXE
calendar
May 20, 2025
·
attack.defense-evasion
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Loaded Via Rundll32.EXE
calendar
May 20, 2025
·
attack.execution
attack.t1204.002
attack.defense-evasion
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Scheduled Task Creation
calendar
May 20, 2025
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.t1053.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
MSSQL Server Failed Logon
calendar
May 20, 2025
·
attack.credential-access
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Periodic Backup For System Registry Hives Enabled
calendar
May 20, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process
calendar
May 20, 2025
·
attack.execution
cve.2024-3094
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Kapeka Decrypted Backdoor Indicator
calendar
May 20, 2025
·
attack.defense-evasion
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DLL Search Order Hijackig Via Additional Space in Path
calendar
May 15, 2025
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading Of ShellChromeAPI.DLL
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL File Dropped in the Teams or OneDrive Folder
calendar
May 15, 2025
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Office DLL Sideload
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential 7za.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerDU.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerReactivator.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Chrome Frame Helper DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Non-Existent DLLs From System Folders
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via ClassicExplorer32.dll
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via comctl32.dll
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via JsSchHlp
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Libvlc.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Wazuh Security Platform DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Third Party Software DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass With Fake DLL
calendar
May 15, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMGuestLib DLL Sideload
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Signed Dbghelp.DLL Potential Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Unsigned Dbghelp.DLL Potential Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Invocations - Specific
calendar
May 12, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Invocations - Specific - PowerShell Module
calendar
May 12, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
CreateDump Process Dump
calendar
Apr 25, 2025
·
attack.defense-evasion
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
DumpMinitool Execution
calendar
Apr 25, 2025
·
attack.defense-evasion
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
HackTool - HandleKatz Duplicating LSASS Handle
calendar
Apr 25, 2025
·
attack.execution
attack.t1106
attack.defense-evasion
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
HackTool - XORDump Execution
calendar
Apr 25, 2025
·
attack.defense-evasion
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Potential SysInternals ProcDump Evasion
calendar
Apr 25, 2025
·
attack.defense-evasion
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Procdump Execution
calendar
Apr 25, 2025
·
attack.defense-evasion
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Renamed CreateDump Utility Execution
calendar
Apr 25, 2025
·
attack.defense-evasion
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DumpMinitool Execution
calendar
Apr 25, 2025
·
attack.defense-evasion
attack.credential-access
attack.t1036
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Chopper Webshell Process Pattern
calendar
Apr 25, 2025
·
attack.persistence
attack.discovery
attack.t1505.003
attack.t1018
attack.t1033
attack.t1087
·
Share on:
twitter
facebook
linkedin
copy
HackTool - winPEAS Execution
calendar
Apr 25, 2025
·
attack.privilege-escalation
attack.discovery
attack.t1082
attack.t1087
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Webshell Detection With Command Line Keywords
calendar
Apr 25, 2025
·
attack.persistence
attack.discovery
attack.t1505.003
attack.t1018
attack.t1033
attack.t1087
·
Share on:
twitter
facebook
linkedin
copy
Webshell Hacking Activity Patterns
calendar
Apr 25, 2025
·
attack.persistence
attack.discovery
attack.t1505.003
attack.t1018
attack.t1033
attack.t1087
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CrushFTP Child Process
calendar
Apr 17, 2025
·
attack.initial-access
attack.execution
attack.t1059.001
attack.t1059.003
attack.t1190
cve.2025-31161
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC
calendar
Apr 17, 2025
·
attack.execution
attack.lateral-movement
attack.t1210
cve.2020-1472
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated PowerShell OneLiner Execution
calendar
Apr 17, 2025
·
attack.defense-evasion
attack.execution
attack.t1059.001
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
calendar
Apr 17, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
calendar
Apr 17, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
calendar
Apr 17, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
calendar
Apr 17, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Eventlog Clearing or Configuration Change Activity
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.t1070.001
attack.t1562.002
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Potential Product Class Reconnaissance Via Wmic.EXE
calendar
Apr 16, 2025
·
attack.execution
attack.t1047
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Browser Data Stealing
calendar
Apr 16, 2025
·
attack.credential-access
attack.t1555.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LNK Command-Line Padding with Whitespace Characters
calendar
Apr 16, 2025
·
attack.initial-access
attack.execution
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
DarkGate - Drop DarkGate Loader In C:\Temp Directory
calendar
Apr 16, 2025
·
attack.execution
attack.t1059
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Nscurl - MacOS
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Recovery From Backup Via Wbadmin.EXE
calendar
Apr 16, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Network Communication Initiated To Portmap.IO Domain
calendar
Apr 16, 2025
·
attack.t1041
attack.command-and-control
attack.t1090.002
attack.exfiltration
·
Share on:
twitter
facebook
linkedin
copy
New File Exclusion Added To Time Machine Via Tmutil - MacOS
calendar
Apr 16, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock
calendar
Apr 16, 2025
·
attack.credential-access
attack.discovery
attack.t1040
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Malware Callback Communication - Linux
calendar
Apr 16, 2025
·
attack.persistence
attack.command-and-control
attack.t1571
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Usage Of Qemu
calendar
Apr 16, 2025
·
attack.command-and-control
attack.t1090
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Sensitive File Dump Via Wbadmin.EXE
calendar
Apr 16, 2025
·
attack.credential-access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Sensitive File Recovery From Backup Via Wbadmin.EXE
calendar
Apr 16, 2025
·
attack.credential-access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
System Information Discovery Via Sysctl - MacOS
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.t1497.001
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Time Machine Backup Deletion Attempt Via Tmutil - MacOS
calendar
Apr 16, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Time Machine Backup Disabled Via Tmutil - MacOS
calendar
Apr 16, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
UAC Notification Disabled
calendar
Apr 16, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Secure Desktop Prompt Disabled
calendar
Apr 16, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Uncommon File Creation By Mysql Daemon Process
calendar
Apr 16, 2025
·
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Process Access Rights For Target Image
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055.011
·
Share on:
twitter
facebook
linkedin
copy
Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted
calendar
Apr 16, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Windows Recall Feature Enabled - Registry
calendar
Apr 16, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Windows Recall Feature Enabled Via Reg.EXE
calendar
Apr 16, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Potential Adplus.EXE Abuse
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.execution
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Impersonating Sysinternals Tools
calendar
Apr 16, 2025
·
attack.execution
attack.defense-evasion
attack.t1218
attack.t1202
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
AWS New Lambda Layer Attached
calendar
Apr 7, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Conhost Spawned By Uncommon Parent Process
calendar
Apr 7, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Elevated System Shell Spawned From Uncommon Parent Location
calendar
Apr 7, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Potential WinAPI Calls Via CommandLine
calendar
Apr 7, 2025
·
attack.execution
attack.t1106
·
Share on:
twitter
facebook
linkedin
copy
Python Initiated Connection
calendar
Apr 7, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Whoami.EXE Execution Anomaly
calendar
Apr 7, 2025
·
attack.discovery
attack.t1033
car.2016-03-001
·
Share on:
twitter
facebook
linkedin
copy
Windows Processes Suspicious Parent Directory
calendar
Apr 7, 2025
·
attack.defense-evasion
attack.t1036.003
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
calendar
Apr 7, 2025
·
attack.reconnaissance
attack.discovery
attack.credential-access
attack.t1018
attack.t1558
attack.t1589.002
·
Share on:
twitter
facebook
linkedin
copy
Notepad Password Files Discovery
calendar
Mar 4, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - JavaScript Constrained File Creation
calendar
Mar 4, 2025
·
attack.defense-evasion
attack.t1562.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Unauthorized or Unauthenticated Access
calendar
Mar 4, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Pnscan Binary Data Transmission Activity
calendar
Mar 4, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - File Creation
calendar
Mar 4, 2025
·
attack.execution
cve.2024-3400
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PUA - SoftPerfect Netscan Execution
calendar
Mar 4, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
RegAsm.EXE Initiating Network Connection To Public IP
calendar
Mar 4, 2025
·
attack.defense-evasion
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
Anydesk Remote Access Software Service Installation
calendar
Mar 4, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Nslookup PowerShell Download Cradle
calendar
Mar 4, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
HTTP Request to Low Reputation TLD or Suspicious File Extension
calendar
Mar 4, 2025
·
attack.initial-access
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Backup Files Deleted
calendar
Feb 28, 2025
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
File Deleted Via Sysinternals SDelete
calendar
Feb 28, 2025
·
attack.defense-evasion
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Obfuscated Ordinal Call Via Rundll32
calendar
Feb 25, 2025
·
attack.defense-evasion
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Process Memory Dump Via Comsvcs.DLL
calendar
Feb 25, 2025
·
attack.defense-evasion
attack.credential-access
attack.t1036
attack.t1003.001
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2024-35250 Exploitation Activity
calendar
Feb 24, 2025
·
attack.privilege-escalation
attack.t1068
cve.2024-35250
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
calendar
Feb 22, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non-Browser Network Communication With Google API
calendar
Feb 22, 2025
·
attack.command-and-control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
AADInternals PowerShell Cmdlets Execution - ProccessCreation
calendar
Feb 17, 2025
·
attack.execution
attack.reconnaissance
attack.discovery
attack.credential-access
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
AADInternals PowerShell Cmdlets Execution - PsScript
calendar
Feb 17, 2025
·
attack.execution
attack.reconnaissance
attack.discovery
attack.credential-access
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
PUA - NimScan Execution
calendar
Feb 17, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Change Winevt Channel Access Permission Via Registry
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
CVE-2024-1212 Exploitation - Progress Kemp LoadMaster Unauthenticated Command Injection
calendar
Feb 3, 2025
·
attack.initial-access
cve.2024-1212
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Event Logging Via Registry
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
Displaying Hidden Files Feature Disabled
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
MaxMpxCt Registry Value Changed
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
New TimeProviders Registered With Uncommon DLL Name
calendar
Feb 3, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1547.003
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - GIT Clone Request
calendar
Feb 3, 2025
·
attack.collection
attack.t1213
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - HTTP GET Request
calendar
Feb 3, 2025
·
attack.initial-access
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - HTTP POST Login Attempt
calendar
Feb 3, 2025
·
attack.initial-access
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - MSSQL Login Attempt Via SQLAuth
calendar
Feb 3, 2025
·
attack.credential-access
attack.collection
attack.t1003
attack.t1213
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - MSSQL Login Attempt Via Windows Authentication
calendar
Feb 3, 2025
·
attack.credential-access
attack.collection
attack.t1003
attack.t1213
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - MySQL Login Attempt
calendar
Feb 3, 2025
·
attack.credential-access
attack.collection
attack.t1003
attack.t1213
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - NTP Monlist Request
calendar
Feb 3, 2025
·
attack.impact
attack.t1498
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - REDIS Action Command Attempt
calendar
Feb 3, 2025
·
attack.credential-access
attack.collection
attack.t1003
attack.t1213
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SIP Request
calendar
Feb 3, 2025
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SMB File Open Request
calendar
Feb 3, 2025
·
attack.lateral-movement
attack.collection
attack.t1021
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SNMP OID Request
calendar
Feb 3, 2025
·
attack.discovery
attack.lateral-movement
attack.t1016
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - TFTP Request
calendar
Feb 3, 2025
·
attack.exfiltration
attack.t1041
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - VNC Connection Attempt
calendar
Feb 3, 2025
·
attack.lateral-movement
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
Potential KamiKakaBot Activity - Lure Document Execution
calendar
Feb 3, 2025
·
attack.execution
attack.t1059
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential KamiKakaBot Activity - Shutdown Schedule Task Creation
calendar
Feb 3, 2025
·
attack.persistence
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious CMD Shell Output Redirect
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Register New IFiltre For Persistence
calendar
Feb 3, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Renamed NirCmd.EXE Execution
calendar
Feb 3, 2025
·
attack.execution
attack.t1059
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Execution With Uncommon DLL Extension
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
ServiceDll Hijack
calendar
Feb 3, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Network Connection to IP Lookup Service APIs
calendar
Feb 3, 2025
·
attack.discovery
attack.t1016
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Altitude Change
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Service Disabled - Registry
calendar
Feb 3, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
WCE wceaux.dll Access
calendar
Jan 31, 2025
·
attack.credential-access
attack.t1003
attack.s0005
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
calendar
Jan 30, 2025
·
attack.execution
attack.t1059
attack.initial-access
attack.t1190
cve.2023-22518
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
calendar
Jan 30, 2025
·
attack.execution
attack.t1059
attack.initial-access
attack.t1190
cve.2023-22518
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-22518
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-22518
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-46747 Exploitation Activity - Proxy
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-46747
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-46747 Exploitation Activity - Webserver
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-46747
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-4966
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-4966
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-4966
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-4966
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2024-1708 - ScreenConnect Path Traversal Exploitation
calendar
Jan 30, 2025
·
attack.persistence
cve.2024-1708
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security
calendar
Jan 30, 2025
·
attack.initial-access
attack.persistence
cve.2024-1708
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2024-1709 - ScreenConnect Authentication Bypass Exploitation
calendar
Jan 30, 2025
·
attack.initial-access
attack.persistence
cve.2024-1709
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exploitation Attempt Of CVE-2023-46214 Using Public POC Code
calendar
Jan 30, 2025
·
attack.lateral-movement
attack.t1210
cve.2023-46214
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
File Creation Related To RAT Clients
calendar
Jan 30, 2025
·
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - Process Creation Activity
calendar
Jan 30, 2025
·
attack.defense-evasion
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request
calendar
Jan 30, 2025
·
attack.persistence
attack.t1505.003
cve.2023-34362
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OWASSRF Exploitation Attempt Using Public POC - Proxy
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pikabot Fake DLL Extension Execution Via Rundll32.EXE
calendar
Jan 30, 2025
·
attack.defense-evasion
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential BlackByte Ransomware Activity
calendar
Jan 30, 2025
·
attack.execution
attack.defense-evasion
attack.impact
attack.t1485
attack.t1498
attack.t1059.001
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-27997 Exploitation Indicators
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
cve.2023-27997
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation Attempt Of Undocumented WindowsServer RCE
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential OWASSRF Exploitation Attempt - Proxy
calendar
Jan 30, 2025
·
attack.initial-access
attack.t1190
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin CPL Execution Activity
calendar
Jan 30, 2025
·
attack.defense-evasion
attack.execution
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Uninstaller Execution
calendar
Jan 30, 2025
·
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor
calendar
Jan 30, 2025
·
attack.persistence
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor - Task Scheduler
calendar
Jan 30, 2025
·
attack.persistence
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect - SlashAndGrab Exploitation Indicators
calendar
Jan 30, 2025
·
attack.defense-evasion
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect User Database Modification
calendar
Jan 30, 2025
·
attack.persistence
cve.2024-1709
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect User Database Modification - Security
calendar
Jan 30, 2025
·
attack.defense-evasion
cve.2024-1709
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Set Value of MSDT in Registry (CVE-2022-30190)
calendar
Jan 30, 2025
·
attack.defense-evasion
attack.t1221
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Failed Code Integrity Checks
calendar
Jan 30, 2025
·
attack.defense-evasion
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
Using explorer.exe to open a file explorer folder via command prompt
calendar
Jan 29, 2025
·
attack.Discovery
attack.T1135
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Dumpert Process Dumper Execution
calendar
Jan 22, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Shell Execution via Rsync - Linux
calendar
Jan 19, 2025
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invocation of Shell via Rsync
calendar
Jan 19, 2025
·
attack.execution
attack.t1059
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36874 Exploitation - Fake Wermgr.Exe Creation
calendar
Jan 15, 2025
·
attack.execution
cve.2023-36874
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2024-49113 Exploitation Attempt - LDAP Nightmare
calendar
Jan 8, 2025
·
attack.impact
attack.t1499
cve.2024-49113
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DPRK Threat Actor - C2 Communication DNS Indicators
calendar
Jan 6, 2025
·
attack.command-and-control
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exploitation Indicator Of CVE-2022-42475
calendar
Jan 6, 2025
·
attack.initial-access
cve.2022-42475
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Evil-WinRm Execution - PowerShell Module
calendar
Jan 6, 2025
·
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Potential Credential Dumping Activity Via LSASS
calendar
Jan 6, 2025
·
attack.credential-access
attack.t1003.001
attack.s0002
·
Share on:
twitter
facebook
linkedin
copy
Potential SentinelOne Shell Context Menu Scan Command Tampering
calendar
Jan 6, 2025
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Execution With Known Revoked Signing Certificate
calendar
Jan 6, 2025
·
attack.execution
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Remote Command Execution
calendar
Jan 6, 2025
·
attack.execution
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Server Web Shell Execution
calendar
Jan 6, 2025
·
attack.initial-access
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From IP Via Wget.EXE - Paths
calendar
Jan 6, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job With Uncommon Or Suspicious Remote TLD
calendar
Dec 27, 2024
·
attack.defense-evasion
attack.persistence
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Unmet Signing Level Requirements By File Under Validation
calendar
Dec 27, 2024
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Relevant Anti-Virus Signature Keywords In Application Log
calendar
Dec 27, 2024
·
attack.resource-development
attack.t1588
·
Share on:
twitter
facebook
linkedin
copy
New AWS Lambda Function URL Configuration Created
calendar
Dec 19, 2024
·
attack.initial-access
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Register new Logon Process by Rubeus
calendar
Dec 19, 2024
·
attack.lateral-movement
attack.privilege-escalation
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Secure Deletion with SDelete
calendar
Dec 14, 2024
·
attack.impact
attack.defense-evasion
attack.t1070.004
attack.t1027.005
attack.t1485
attack.t1553.002
attack.s0195
·
Share on:
twitter
facebook
linkedin
copy
Local System Accounts Discovery - Linux
calendar
Dec 14, 2024
·
attack.discovery
attack.t1087.001
·
Share on:
twitter
facebook
linkedin
copy
Modification or Deletion of an AWS RDS Cluster
calendar
Dec 6, 2024
·
attack.exfiltration
attack.t1020
·
Share on:
twitter
facebook
linkedin
copy
CMSTP UAC Bypass via COM Object Access
calendar
Dec 1, 2024
·
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
Exploiting CVE-2019-1388
calendar
Dec 1, 2024
·
attack.privilege-escalation
attack.t1068
cve.2019-1388
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Permission Check Via Accesschk.EXE
calendar
Dec 1, 2024
·
attack.discovery
attack.t1069.001
·
Share on:
twitter
facebook
linkedin
copy
Possible Privilege Escalation via Weak Service Permissions
calendar
Dec 1, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-41379 Exploitation Attempt
calendar
Dec 1, 2024
·
attack.privilege-escalation
attack.t1068
cve.2021-41379
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential RDP Session Hijacking Activity
calendar
Dec 1, 2024
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential UAC Bypass Via Sdclt.EXE
calendar
Dec 1, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious High IntegrityLevel Conhost Legacy Option
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Tools Using ComputerDefaults
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using ChangePK and SLUI
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Consent and Comctl32 - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Disk Cleanup
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using DismHost
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IDiagnostic Profile
calendar
Dec 1, 2024
·
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IEInstal - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using MSConfig Token Modification - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using NTFS Reparse Point - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin