open-menu
closeme
.RDP File Created By Uncommon Application
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
A Rule Has Been Deleted From The Windows Firewall Exception List
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Abuse of Service Permissions to Hide Services Via Set-Service
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Abuse of Service Permissions to Hide Services Via Set-Service - PS
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Abused Debug Privilege by Arbitrary Parent Processes
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Abusing Print Executable
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Account Created And Deleted Within A Close Time Frame
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Account Disabled or Blocked for Sign in Attempts
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Account Tampering - Suspicious Failed Logon Reasons
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Activate Suppression of Windows Security Center Notifications
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Active Directory Certificate Services Denied Certificate Enrollment Request
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Activity From Anonymous IP Address
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
AD Object WriteDAC Access
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Add DisallowRun Execution to Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Add Insecure Download Source To Winget
calendar
Apr 28, 2026
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Add New Download Source To Winget
calendar
Apr 28, 2026
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Add or Remove Computer from DC
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1207
·
Share on:
twitter
facebook
linkedin
copy
Add Potential Suspicious New Download Source To Winget
calendar
Apr 28, 2026
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Add SafeBoot Keys Via Reg Utility
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AddinUtil.EXE Execution From Uncommon Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Addition of SID History to Active Directory Object
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1134.005
·
Share on:
twitter
facebook
linkedin
copy
Admin User Remote Logon
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.lateral-movement
attack.initial-access
attack.stealth
attack.t1078.001
attack.t1078.002
attack.t1078.003
car.2016-04-005
·
Share on:
twitter
facebook
linkedin
copy
ADS Zone.Identifier Deleted By Uncommon Application
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
AgentExecutor PowerShell Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
All Rules Have Been Deleted From The Windows Firewall Configuration
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Allow RDP Remote Assistance Feature
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Always Install Elevated MSI Spawned Cmd And Powershell
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Always Install Elevated Windows Installer
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
AMSI Bypass Pattern Assembly GetType
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
AMSI Disabled via Registry Modification
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Amsi.DLL Loaded Via LOLBIN Process
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Filter Driver Disallowed On Dev Drive - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
cve.2021-34527
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Application AppID Uri Configuration Changes
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.stealth
attack.t1552
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Application URI Configuration Changes
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1528
attack.t1078.004
attack.persistence
attack.credential-access
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Application Using Device Code Authentication Flow
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Applications That Are Using ROPC Authentication Flow
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
AppX Located in Known Staging Directory Added to Deployment Pipeline
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
AppX Located in Uncommon Directory Added to Deployment Pipeline
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
AppX Package Deployment Failed Due to Signing Requirements
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
APT PRIVATELOG Image Load Pattern
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
APT27 - Emissary Panda Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
APT29 2018 Phishing Campaign CommandLine Indicators
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
APT29 2018 Phishing Campaign File Indicators
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via IMEWDBLD.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via MSEDGE_PROXY.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via MSOHTMED.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via MSPUB.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via PresentationHost.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via Squirrel.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary MSI Download Via Devinit.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Aruba Network Service Potential DLL Sideloading
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
ASLR Disabled Via Sysctl or Direct Syscall - Linux
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1685
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
AspNetCompiler Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Assembly Loading Via CL_LoadAssembly.ps1
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Atbroker Registry Change
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1218
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Atomic MacOS Stealer - Persistence Indicators
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1564.001
attack.t1543.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Atypical Travel
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Audit CVE Event
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1203
attack.privilege-escalation
attack.t1068
attack.t1211
attack.credential-access
attack.t1212
attack.lateral-movement
attack.t1210
attack.impact
attack.t1499.004
·
Share on:
twitter
facebook
linkedin
copy
Audit Policy Tampering Via Auditpol
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Audit Policy Tampering Via NT Resource Kit Auditpol
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Audit Rules Deleted Via Auditctl
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.004
·
Share on:
twitter
facebook
linkedin
copy
Auditing Configuration Changes on Linux Host
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Authentications To Important Apps Using Single Factor Authentication
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
AWS Bucket Deleted
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
AWS CloudTrail Important Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.002
·
Share on:
twitter
facebook
linkedin
copy
AWS Config Disabling Channel/Recorder
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.002
·
Share on:
twitter
facebook
linkedin
copy
AWS Console GetSigninToken Potential Abuse
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.t1021.007
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS GuardDuty Detector Deleted Or Updated
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.t1685.002
·
Share on:
twitter
facebook
linkedin
copy
AWS GuardDuty Important Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser LoginProfile Creation
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser Templated S3 Bucket Policy Creation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.009
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser User or AccessKey Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.initial-access
attack.stealth
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Identity Center Identity Provider Change
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
AWS Key Pair Import Activity
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
AWS Root Credentials
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS SAML Provider Deletion Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078.004
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.t1531
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
AWS SecurityHub Findings Evasion
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AWS STS AssumeRole Misuse
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.privilege-escalation
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS STS GetSessionToken Misuse
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.privilege-escalation
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS Successful Console Login Without MFA
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Suspicious SAML Activity
calendar
Apr 28, 2026
·
attack.initial-access
attack.lateral-movement
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS VPC Flow Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Axios NPM Compromise Indicators - Linux
calendar
Apr 28, 2026
·
attack.initial-access
attack.t1195.002
attack.execution
attack.command-and-control
attack.t1059.006
attack.t1059.004
attack.t1105
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Axios NPM Compromise Indicators - macOS
calendar
Apr 28, 2026
·
attack.initial-access
attack.t1195.002
attack.execution
attack.command-and-control
attack.t1059.002
attack.t1059.004
attack.t1105
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Axios NPM Compromise Indicators - Windows
calendar
Apr 28, 2026
·
attack.initial-access
attack.t1195.002
attack.execution
attack.command-and-control
attack.t1059.003
attack.t1059.005
attack.t1105
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Azure Active Directory Hybrid Health AD FS New Server
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1578
·
Share on:
twitter
facebook
linkedin
copy
Azure Active Directory Hybrid Health AD FS Service Delete
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1578.003
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Only Single Factor Authentication Required
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.defense-impairment
attack.t1078.004
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Threat Intelligence
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Azure Application Deleted
calendar
Apr 28, 2026
·
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Azure Domain Federation Settings Modified
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Firewall Modified or Deleted
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
Azure Firewall Rule Collection Modified or Deleted
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Admission Controller
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Events Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Azure Login Bypassing Conditional Access Policies
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Network Firewall Policy Modified or Deleted
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
Azure Owner Removed From Application or Service Principal
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Azure Service Principal Created
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Azure Service Principal Removed
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via ActivityLogs
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via AuditLogs
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Unusual Authentication Interruption
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
BaaUpdate.exe Suspicious DLL Load
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Backup Catalog Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Base64 Encoded PowerShell Command Detected
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1140
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Binary Padding - Linux
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
Binary Padding - MacOS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
Binary Proxy Execution Via Dotnet-Trace.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Audit Log Configuration Updated
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global Secret Scanning Rule Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global SSH Settings Changed
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.defense-impairment
attack.t1685
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Project Secret Scanning Allowlist Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Exempt Repository Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Rule Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket User Login Failure
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Bitlocker Key Retrieval
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
BitLockerTogo.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Download From Direct IP
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Download From File Sharing Domains
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Download To Potential Suspicious Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Downloading File Potential Suspicious Extension
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job With Uncommon Or Suspicious Remote TLD
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
Bitsadmin to Uncommon IP Server Address
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1071.001
attack.persistence
attack.t1197
attack.s0190
·
Share on:
twitter
facebook
linkedin
copy
Bitsadmin to Uncommon TLD
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1071.001
attack.persistence
attack.t1197
attack.s0190
·
Share on:
twitter
facebook
linkedin
copy
Blackbyte Ransomware Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird - Registry
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Bpfdoor TCP Ports Redirect
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Browser Execution In Headless Mode
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1105
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using DelegateExecute
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using SilentCleanup Task
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via CMSTP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1548.002
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via Fodhelper.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via WSReset.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
C# IL Code Compilation Via Ilasm.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Removed by Non Approved Actor
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Updated by Non Approved Actor
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Certificate Exported Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Certificate-Based Authentication Enabled
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Change the Fax Dll
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Change to Authentication Method
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.defense-impairment
attack.t1556
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Change User Account Associated with the FAX Service
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Change Winevt Channel Access Permission Via Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Changes to Device Registration Policy
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484
·
Share on:
twitter
facebook
linkedin
copy
Changes To PIM Settings
calendar
Apr 28, 2026
·
attack.initial-access
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Changing Existing Service ImagePath Value Via Reg.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Chmod Targeting Sensitive Directories
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Cisco BGP Authentication Failures
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Cisco Clear Logs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Cisco Crypto Commands
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1553.004
attack.t1552.004
·
Share on:
twitter
facebook
linkedin
copy
Cisco Disabling Logging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Cisco Dot1x Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1685
attack.t1556.004
·
Share on:
twitter
facebook
linkedin
copy
Cisco Duo Successful MFA Authentication Via Bypass Code
calendar
Apr 28, 2026
·
attack.credential-access
attack.initial-access
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Cisco File Deletion
calendar
Apr 28, 2026
·
attack.impact
attack.stealth
attack.t1070.004
attack.t1561.001
attack.t1561.002
·
Share on:
twitter
facebook
linkedin
copy
Cisco LDP Authentication Failures
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
Clearing Windows Console History
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
ClickOnce Trust Prompt Tampering
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Cmd Launched with Hidden Start Flags to Suspicious Targets
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Process Access
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.003
attack.execution
attack.t1559.001
attack.g0069
attack.g0080
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Process Creation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Registry Event
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CMSTP UAC Bypass via COM Object Access
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1548.002
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Load by Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe Pattern Regex
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe Patterns
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
stp.1k
·
Share on:
twitter
facebook
linkedin
copy
Code Execution via Pcwutl.dll
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Code Injection by ld.so Preload
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
CodePage Modification Via MODE.COM To Russian Language
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL Persistence Service Creation
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Anonymous User Process Execution
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Cleanup Command Execution
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Service Persistence Execution
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COM Hijack via Sdclt
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.t1546
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
COM Object Execution via Xwizard.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.001
detection.emerging-threats
cve.2025-57788
·
Share on:
twitter
facebook
linkedin
copy
ComRAT Network Communication
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1071.001
attack.g0010
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Connection Proxy
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Control Panel Items
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1218.002
attack.persistence
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
ConvertTo-SecureString Cmdlet Usage Via CommandLine
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
CrashControl CrashDump Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1564
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Created Files by Microsoft Sync Center
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
CreateDump Process Dump
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Creation Of a Suspicious ADS File Outside a Browser Download
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Non-Existent System DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Pod In System Namespace
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Creation of WerFault.exe/Wer.dll in Unusual Folder
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Credential Dumping Attempt Via Svchost
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Csc.EXE Execution Form Potentially Suspicious Parent
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1059.007
attack.t1218.005
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Curl Download And Execute Combination
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Custom File Open Handler Executes PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
cve.2020-1048
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Decode Base64 Encoded Text
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Decode Base64 Encoded Text -MacOs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Delete Defender Scan ShellEx Context Menu Registry Key
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Deployment AppX Package Was Blocked By AppLocker
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Deployment Of The AppX Package Was Blocked By The Policy
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Detection of PowerShell Execution via Sqlps.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Devcon Execution Disabling VMware VMCI Device
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1543.003
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Device Registration or Join Without MFA
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
DeviceCredentialDeployment Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Devtoolslauncher.exe Executes Specified Binary
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DHCP Callout DLL Installation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Error Failed Loading the CallOut DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Loaded the CallOut DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
cve.2022-30190
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT DLL Sideloading Indicators
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT Scheduled Task Creation - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Directory Removal Via Rmdir
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Directory Service Restore Mode(DSRM) Registry Value Tampering
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Disable Administrative Share Creation at Startup
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Disable Exploit Guard Network Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Internal Tools or Feature in Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Disable Macro Runtime Scan Scope
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Disable Microsoft Defender Firewall via Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Disable of ETW Trace - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Disable Or Stop Services
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Disable Powershell Command History
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Disable Privacy Settings Experience in Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable PUA Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Security Events Logging Adding Reg Key MiniNt
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Disable Security Tools
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable System Firewall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Disable Tamper Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Defender AV Security Monitoring
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Defender Functionalities Via Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Event Logging Via Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Firewall by Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows IIS HTTP Logging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Security Center Notifications
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Disable-WindowsOptionalFeature Command PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled IE Security Features
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled MFA to Bypass Authentication Mechanisms
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Disabled Volume Snapshots
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled Windows Defender Eventlog
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabling Multi Factor Authentication
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Disabling Security Tools
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Disabling Security Tools - Builtin
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Disabling Windows Defender WMI Autologger Session via Reg.exe
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Diskshadow Script Mode - Execution From Potential Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Diskshadow Script Mode - Uncommon Script Extension Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Dism Remove Online Package
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Displaying Hidden Files Feature Disabled
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Execution via Rasautou.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DLL Execution Via Register-cimprovider.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
DLL Load By System Process From Suspicious Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
DLL Loaded From Suspicious Location Via Cmspt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
DLL Loaded via CertOC.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DLL Names Used By SVR For GraphicalProton Backdoor
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DLL Search Order Hijackig Via Additional Space in Path
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading by VMware Xfer Utility
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading Of ShellChromeAPI.DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Dllhost.EXE Execution Anomaly
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
DllUnregisterServer Function Call Via Msiexec.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
DMSA Link Attributes Modified
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.002
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
DMSA Service Account Created in Specific OUs - PowerShell
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.002
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
DNS Query Request By Regsvr32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1559.001
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
DNS Server Error Failed Loading the ServerLevelPluginDLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DNS-over-HTTPS Enabled by Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1140
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DotNet CLR DLL Loaded By Scripting Applications
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Download from Suspicious Dyndns Hosts
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1105
attack.t1568
·
Share on:
twitter
facebook
linkedin
copy
Driver Added To Disallowed Images In HVCI - Registry
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Driver/DLL Installation Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Drop Binaries Into Spool Drivers Color Folder
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Dropping Of Password Filter DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.002
·
Share on:
twitter
facebook
linkedin
copy
DumpMinitool Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
DumpStack.log Defender Evasion
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Dynamic .NET Compilation Via Csc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Dynamic CSharp Compile Artefact
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Elevated System Shell Spawned From Uncommon Parent Location
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Enable BPF Kprobes Tracing
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage - ProcCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enable Local Manifest Installation With Winget
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Enabling COR Profiler Environment Variables
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.012
·
Share on:
twitter
facebook
linkedin
copy
Equation Group DLL_U Export Function Load
calendar
Apr 28, 2026
·
attack.stealth
attack.g0020
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ESXi Syslog Configuration Change Via ESXCLI
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
attack.t1690
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For rpcrt4.dll
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For SCM
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Sysmon Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Tamper In .NET Processes Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging/Processing Option Disabled On IIS Server
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
ETW Trace Evasion Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Eventlog Cleared
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
EventLog EVTX File Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
EvilNum APT Golden Chickens Deployment Via OCX Files
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
EVTX Created In Uncommon Location
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Exchange PowerShell Cmdlet History Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Execute Code with Pester.bat
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Execute Code with Pester.bat as Parent
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Execute Files with Msdeploy.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Execute From Alternate Data Streams
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Execute Pcwrun.EXE To Leverage Follina
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Execution DLL of Choice Using WAB.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Execution Of Non-Existing File
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Execution of Suspicious File Type Extension
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Execution via stordiag.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Execution via WorkFolders.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Exploit for CVE-2015-1641
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
cve.2015-1641
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exploiting SetupComplete.cmd CVE-2019-1378
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1068
attack.execution
attack.t1059.003
attack.t1574
cve.2019-1378
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Explorer NOUACCHECK Flag
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Explorer Process Tree Break
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Exports Registry Key To an Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
External Remote RDP Logon from Public IP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
External Remote SMB Logon from Public IP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Authentications From Countries You Do Not Operate Out Of
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Code Integrity Checks
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
Failed Logon From Public IP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.t1190
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Fax Service DLL Search Order Hijack
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
File Decoded From Base64/Hex Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File Deleted Via Sysinternals SDelete
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
File Deletion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
File Deletion Via Del
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
File Download Using ProtocolHandler.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Bitsadmin To A Suspicious Target Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download Via InstallUtil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Nscurl - MacOS
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Windows Defender MpCmpRun.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download with Headless Browser
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1105
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
File Encoded To Base64 Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File In Suspicious Location Encoded To Base64 Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File or Folder Permissions Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
File Time Attribute Change
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
File Time Attribute Change - Linux
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
File With Suspicious Extension Downloaded Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Files With System DLL Name In Unsuspected Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Files With System Process Name In Unsuspected Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Filter Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Findstr Launching .lnk File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1202
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Fireball Archer Install
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Firewall Disabled via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
attack.s0108
·
Share on:
twitter
facebook
linkedin
copy
Firewall Rule Deleted Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Firewall Rule Update Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Flash Player Update from Suspicious Location
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1189
attack.execution
attack.t1204.002
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
FlowCloud Registry Markers
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Flush Iptables Ufw Chain
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Folder Removed From Exploit Guard ProtectedFolders List - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - File Creation Activity
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - JavaScript Constrained File Creation
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - Process Creation Activity
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Forfiles.EXE Child Process Masquerading
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - Firewall Address Object Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - New Firewall Policy Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Fsutil Suspicious Invocation
calendar
Apr 28, 2026
·
attack.impact
attack.stealth
attack.t1070
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Function Call From Undocumented COM Interface EditionUpgradeManager
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Gatekeeper Bypass via Xattr
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.001
·
Share on:
twitter
facebook
linkedin
copy
GCP Break-glass Container Workload Deployed
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Github High Risk Configuration Disabled
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Github New Secret Created
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Bypass Detected
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
GitHub Repository Archive Status Changed
calendar
Apr 28, 2026
·
attack.persistence
attack.impact
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Github Secret Scanning Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Github Self Hosted Runner Changes Detected
calendar
Apr 28, 2026
·
attack.impact
attack.discovery
attack.collection
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1526
attack.t1213.003
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Github SSH Certificate Configuration Changed
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Goofy Guineapig Backdoor IOC
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Firewall Modified or Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Kubernetes Admission Controller
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Government Attack Warning
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.impact
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Gpscript Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Greedy File Deletion Using Del
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Greenbug Espionage Group Indicators
calendar
Apr 28, 2026
·
attack.stealth
attack.g0049
attack.execution
attack.t1059.001
attack.command-and-control
attack.t1105
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Group Policy Abuse for Privilege Addition
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Guest Account Enabled Via Sysadminctl
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
attack.t1078.001
·
Share on:
twitter
facebook
linkedin
copy
Guest User Invited By Non Approved Inviters
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Guest Users Invited To Tenant By Non Approved Inviters
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CACTUSTORCH Remote Thread Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1055.012
attack.t1059.005
attack.t1059.007
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CobaltStrike BOF Injection Pattern
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1106
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CobaltStrike Malleable Profile Patterns - Proxy
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CoercedPotato Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CoercedPotato Named Pipe Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Covenant PowerShell Launcher
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec PowerShell Obfuscation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - DInjector PowerShell Cradle Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Hacktool - EDR-Freeze Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EDRSilencer Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EDRSilencer Execution - Filter Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EfsPotato Named Pipe Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Empire PowerShell UAC Bypass
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Empire UserAgent URI Combo
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - F-Secure C3 Load by Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
HackTool - GMER Rootkit Detector and Remover Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
HackTool - HandleKatz Duplicating LSASS Handle
calendar
Apr 28, 2026
·
attack.execution
attack.t1106
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
HackTool - HollowReaper Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Impersonate Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Koh Default Named Pipe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.stealth
attack.t1528
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - KrbRelayUp Execution
calendar
Apr 28, 2026
·
attack.credential-access
attack.t1558.003
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LittleCorporal Generated Maldoc Injection
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1204.002
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LocalPotato Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
cve.2023-21746
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
HackTool - NoFilter Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential CobaltStrike Process Injection
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - PowerTool Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Powerup Write Hijack DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - PPID Spoofing SelectMyParent Tool Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.004
·
Share on:
twitter
facebook
linkedin
copy
HackTool - RedMimicry Winnti Playbook Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1106
attack.t1059.003
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Rubeus Execution
calendar
Apr 28, 2026
·
attack.credential-access
attack.t1003
attack.t1558.003
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Rubeus Execution - ScriptBlock
calendar
Apr 28, 2026
·
attack.credential-access
attack.t1003
attack.t1558.003
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpDPAPI Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpEvtMute DLL Load
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpEvtMute Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpImpersonation Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpUp PrivEsc Tool Execution
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.discovery
attack.execution
attack.stealth
attack.t1615
attack.t1569.002
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Stracciatella Execution
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SysmonEnte Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - UACMe Akagi Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - WinPwn Execution
calendar
Apr 28, 2026
·
attack.credential-access
attack.discovery
attack.execution
attack.privilege-escalation
attack.t1046
attack.t1082
attack.t1106
attack.t1518
attack.t1548.002
attack.t1552.001
attack.t1555
attack.t1555.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - WinPwn Execution - ScriptBlock
calendar
Apr 28, 2026
·
attack.credential-access
attack.discovery
attack.execution
attack.privilege-escalation
attack.t1046
attack.t1082
attack.t1106
attack.t1518
attack.t1548.002
attack.t1552.001
attack.t1555
attack.t1555.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Wmiexec Default Powershell Command
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
HackTool - XORDump Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
HackTool Named File Stream Created
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Hacktool Ruler
calendar
Apr 28, 2026
·
attack.discovery
attack.execution
attack.collection
attack.lateral-movement
attack.t1087
attack.t1114
attack.t1059
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
HH.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.001
·
Share on:
twitter
facebook
linkedin
copy
Hidden Executable In NTFS Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Hidden Files and Directories
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Hidden Flag Set On File/Directory Via Chflags - MacOS
calendar
Apr 28, 2026
·
attack.credential-access
attack.command-and-control
attack.stealth
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Hidden User Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
Hide Schedule Task Via Index Value Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hiding Files with Attrib.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Hiding User Account Via SpecialAccounts Registry Key
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
Hiding User Account Via SpecialAccounts Registry Key - CommandLine
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
HTML Help HH.EXE Suspicious Child Process
calendar
Apr 28, 2026
·
attack.execution
attack.initial-access
attack.stealth
attack.t1047
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.007
attack.t1218
attack.t1218.001
attack.t1218.010
attack.t1218.011
attack.t1566
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
HTTP Logging Disabled On IIS Server
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
HTTP Request With Empty User Agent
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Huawei BGP Authentication Failures
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor Enforced Paging Translation Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Ie4uinit Lolbin Use From Invalid Path
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
IIS WebServer Access Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
IIS WebServer Log Deletion via CommandLine Utilities
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
ImagingDevices Unusual Parent/Child Processes
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Import LDAP Data Interchange Format File Via Ldifde.EXE
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1218
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Event Auditing Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Eventlog Cleared
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Service Terminated Unexpectedly
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Service Terminated With Error
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From a File
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From an ADS
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Impossible Travel
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Increased Failed Authentications Of Any Type
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Indicator Removal on Host - Clear Mac System Logs
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
Indirect Command Execution By Program Compatibility Wizard
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Indirect Command Execution From Script File Via Bash.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Indirect Command Execution via SFTP ProxyCommand
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Indirect Inline Command Execution Via Bash.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
InfDefaultInstall.exe .inf Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Injected Browser Process Spawning Rundll32 - GuLoader Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Insensitive Subfolder Search Via Findstr.EXE
calendar
Apr 28, 2026
·
attack.credential-access
attack.command-and-control
attack.stealth
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Install New Package Via Winget Local Manifest
calendar
Apr 28, 2026
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Install Root Certificate
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Interactive Bash Suspicious Children
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.004
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Internet Explorer DisableFirstRunCustomize Enabled
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Invalid PIM License
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
JScript Compiler Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Juniper BGP Missing MD5
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Configuration Persistence
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1553.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Execution Via RunDLL32.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Loaded Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.002
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kaspersky Endpoint Security Stopped Via CommandLine - Linux
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Kavremover Dropped Binary LOLBIN Usage
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Kernel Memory Dump Via LiveKD
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Admission Controller Modification
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Events Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Launch-VsDevShell.PS1 Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216.001
·
Share on:
twitter
facebook
linkedin
copy
Lazarus APT DLL Sideloading Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0032
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Lazarus System Binary Masquerading
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Archive
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Executable
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Script
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Writing Files In Uncommon Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Linux Base64 Encoded Pipe to Shell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Linux Base64 Encoded Shebang In CLI
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Linux Capabilities Discovery
calendar
Apr 28, 2026
·
attack.discovery
attack.privilege-escalation
attack.t1083
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Command History Tampering
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Linux Doas Conf File Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Doas Tool Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Logs Clearing Attempts
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
Linux Package Uninstall
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Linux Setgid Capability Set on a Binary via Setcap Utility
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1548
attack.t1554
·
Share on:
twitter
facebook
linkedin
copy
Linux Setuid Capability Set on a Binary via Setcap Utility
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1548
attack.t1554
·
Share on:
twitter
facebook
linkedin
copy
Linux Shell Pipe to Shell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation By Uncommon Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Kernel Memory Dump File Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Load Of RstrtMgr.DLL By A Suspicious Process
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1486
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Load Of RstrtMgr.DLL By An Uncommon Process
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1486
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Logging Configuration Changes on Linux Host
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Login to Disabled Account
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Logon from a Risky IP Address
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
LOL-Binary Copied From System Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
LOLBIN Execution From Abnormal Drive
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Lolbin Runexehelper Use As Proxy
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Lolbin Unregmp2.exe Use As Proxy
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
LSA PPL Protection Setting Modification via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1689
·
Share on:
twitter
facebook
linkedin
copy
Lummac Stealer Activity - Execution Of More.com And Vbc.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Macro Enabled In A Potentially Suspicious Document
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL File Dropped in the Teams or OneDrive Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL Load By Compromised 3CXDesktopApp
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Malicious Named Pipe Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Malicious PE Execution by Microsoft Visual Studio Debugger
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.t1078.002
·
Share on:
twitter
facebook
linkedin
copy
Malicious Windows Script Components File Execution by TAEF Detection
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Malware Shellcode in Verclsid Target Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ManageEngine Endpoint Central Dctask64.EXE Potential Abuse
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Masquerading as Linux Crond Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Mavinject Inject DLL Into Running Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
attack.t1218.013
·
Share on:
twitter
facebook
linkedin
copy
MaxMpxCt Registry Value Changed
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Measurable Increase Of Successful Authentications
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - Security
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - System
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Microsoft 365 - Impossible Travel Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Defender Blocked from Loading Unsigned DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Defender Tamper Protection Trigger
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash - WER
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Office DLL Sideload
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Office Protected View Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Sync Center Suspicious Network Connections
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
MMC Executing Files with Reversed Extensions Using RTLO Abuse
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.002
attack.t1218.014
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
MMC Loading Script Engines DLLs
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218.014
·
Share on:
twitter
facebook
linkedin
copy
Modification of IE Registry Settings
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Modification of ld.so.preload
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
Modify Group Policy Settings
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Modify Group Policy Settings - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Modify System Firewall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Monitoring For Persistence Via BITS
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
Mount Execution With Hidepid Parameter
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
MpiExec Lolbin
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
MSDT Execution Via Answer File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
MSHTA Execution with Suspicious File Extensions
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
attack.t1218.005
attack.execution
attack.t1059.007
cve.2020-1599
·
Share on:
twitter
facebook
linkedin
copy
Mshtml.DLL RunHTMLApplication Suspicious Usage
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
MSI Installation From Web
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Msiexec Quiet Installation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
MsiExec Web Install
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
MSSQL Disable Audit Settings
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Msxsl.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Denied
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Interrupted
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
NET NGenAssemblyUsageLog Registry Key Tamper
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Netsh Allow Group Policy on Microsoft Defender Firewall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated By AddinUtil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated By Regsvr32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1559.001
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated Via Notepad.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.command-and-control
attack.execution
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom DB Path Registry Configuration
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom VBScript Registry Configuration
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom WMI Query Registry Configuration
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BITS Job Created Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
New BITS Job Created Via PowerShell
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
New CA Policy by Non-approved Actor
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
New Capture Session Launched Via DXCap.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
New Country
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
New DLL Registered Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
New DMSA Service Account Created in Specific OUs
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.002
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New Federated Domain Added
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.002
·
Share on:
twitter
facebook
linkedin
copy
New File Association Using Exefile
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
attack.s0246
·
Share on:
twitter
facebook
linkedin
copy
New Module Module Added To IIS Server
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
New Network ACL Entry Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
New Network Route Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
New or Renamed User Account with '$' Character
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
New Port Forwarding Rule Added Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.command-and-control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
New PortProxy Registry Entry Added
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.command-and-control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
New Process Created Via Taskmgr.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Authority Added
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Installed Via CertMgr.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Installed Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Node Process Executions
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Non-privileged Usage of Reg or Powershell
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NotPetya Ransomware Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1218.011
attack.t1685.005
attack.credential-access
attack.t1003.001
car.2016-04-002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Nslookup PowerShell Download Cradle - ProcessCreation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
NtdllPipe Like Activity Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
NTFS Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
NTLM Logon
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
NTLMv1 Logon Between Client and Server
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated PowerShell MSI Install via WindowsInstaller COM
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.010
attack.t1218.007
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated PowerShell OneLiner Execution
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059.001
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
OceanLotus Registry Activity
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Odbcconf.EXE Suspicious DLL Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Office Application Initiated Network Connection Over Uncommon Ports
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Office Macros Warning Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Registry Persistence
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - Security
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - System
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Okta MFA Reset or Deactivated
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Okta New Admin Console Behaviours
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Okta User Session Start Via An Anonymising Proxy Service
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Old TLS1.0/TLS1.1 Protocol Version Enabled
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
OneNote Attachment File Dropped In Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
OneNote.EXE Execution of Malicious Embedded Scripts
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.001
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - HTTPPROXY Login Attempt
calendar
Apr 28, 2026
·
attack.initial-access
attack.command-and-control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH Login Attempt
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.lateral-movement
attack.persistence
attack.stealth
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH New Connection Attempt
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.lateral-movement
attack.persistence
attack.stealth
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - Telnet Login Attempt
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.command-and-control
attack.stealth
attack.t1133
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenWith.exe Executes Specified Binary
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.stealth
attack.t1012
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity - Security
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.stealth
attack.t1012
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Outbound Network Connection Initiated By Cmstp.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
Outbound Network Connection To Public IP Via Winlogon
calendar
Apr 28, 2026
·
attack.execution
attack.command-and-control
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Outgoing Logon with New Credentials
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.t1550
·
Share on:
twitter
facebook
linkedin
copy
Outlook EnableUnsafeClientMailRules Setting Enabled
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Pass the Hash Activity 2
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened (Email Attachment)
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1027
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened (Suspicious Filenames)
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1027
attack.t1105
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Password Provided In Command Line Of Net.EXE
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.lateral-movement
attack.stealth
attack.t1021.002
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Password Reset By User Account
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.credential-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Payload Decoded and Decrypted via Built-in Utilities
calendar
Apr 28, 2026
·
attack.stealth
attack.t1059
attack.t1204
attack.execution
attack.t1140
attack.s0482
attack.s0402
·
Share on:
twitter
facebook
linkedin
copy
PDF File Created By RegEdit.EXE
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via New SIP Provider
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1553.003
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via Sudoers.d Files
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1548.003
·
Share on:
twitter
facebook
linkedin
copy
Pikabot Fake DLL Extension Execution Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PIM Alert Setting Changes To Disabled
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
PIM Approvals And Deny Elevation
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Ping Hex IP
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor DLL Loading Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor File Indicators
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Possible DC Shadow Attack
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1207
·
Share on:
twitter
facebook
linkedin
copy
Possible Privilege Escalation via Weak Service Permissions
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Possible Shadow Credentials Added
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Potential 7za.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Access Token Abuse
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
stp.4u
·
Share on:
twitter
facebook
linkedin
copy
Potential Adplus.EXE Abuse
calendar
Apr 28, 2026
·
attack.execution
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Script Using NULL Bits
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Using NULL Bits
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Via .NET Reflection
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI COM Server Hijacking
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Antivirus Software DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Application Whitelisting Bypass via Dnx.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Potential appverifUI.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Code Execution Via Node.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Command Execution Using Msdt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Command Execution Via FTP.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary DLL Load Using Winword
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary File Download Using Office Application
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary File Download Via Cmdl32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Attachment Manager Settings Associations Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential Attachment Manager Settings Attachments Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential AutoLogger Sessions Tampering
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Potential AVKkid.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Azure Browser SSO Abuse
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Baby Shark Malware Activity
calendar
Apr 28, 2026
·
attack.execution
attack.discovery
attack.stealth
attack.t1012
attack.t1059.003
attack.t1059.001
attack.t1218.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Base64 Decoded From Images
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Impersonating Sysinternals Tools
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Proxy Execution Via Cdb.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1106
attack.t1218
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Proxy Execution Via VSDiagnostics.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential BlackByte Ransomware Activity
calendar
Apr 28, 2026
·
attack.execution
attack.impact
attack.stealth
attack.t1485
attack.t1498
attack.t1059.001
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Bumblebee Remote Thread Creation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerDU.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerReactivator.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Chrome Frame Helper DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL Persistence Service DLL Creation
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL Persistence Service DLL Load
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL RAT File Indicators
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Command Line Path Traversal Evasion Attempt
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potential Commandline Obfuscation Using Escape Characters
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Update Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36884 Exploitation Dropped File
calendar
Apr 28, 2026
·
attack.persistence
cve.2023-36884
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
cve.2024-3400
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Data Stealing Via Chromium Headless Debugging
calendar
Apr 28, 2026
·
attack.credential-access
attack.collection
attack.stealth
attack.t1185
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Binary Rename
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
calendar
Apr 28, 2026
·
attack.stealth
attack.t1006
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Right-to-Left Override
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Devil Bait Malware Reconnaissance
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Devil Bait Related Indicator
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Injection Or Execution Using Tracker.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGCORE.DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGHELP.DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DbgModel.DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MpSvc.DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MsCorSvc.DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Non-Existent DLLs From System Folders
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Using Coregen.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1218
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via ClassicExplorer32.dll
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via comctl32.dll
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via DeviceEnroller.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via JsSchHlp
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via VMware Xfer
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Dridex Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.discovery
attack.t1135
attack.t1033
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential EACore.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Edputil.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Emotet Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Emotet Rundll32 Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential EmpireMonkey Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Encoded PowerShell Patterns In CommandLine
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential EventLog File Location Tampering
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation Attempt From Office Application
calendar
Apr 28, 2026
·
attack.execution
cve.2021-40444
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CVE-2025-5054 or CVE-2025-4598
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.t1548
attack.t1003
cve.2025-5054
cve.2025-4598
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Fake Instance Of Hxtsr.EXE Executed
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potential File Download Via MS-AppInstaller Protocol Handler
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential File Extension Spoofing Using Right-to-Left Override
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Goofy Guineapig GoolgeUpdate Process Anomaly
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Goopdate.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Homoglyph Attack Using Lookalike Characters
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Homoglyph Attack Using Lookalike Characters in Filename
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential In-Memory Execution Using Reflection.Assembly
calendar
Apr 28, 2026
·
attack.stealth
attack.t1620
·
Share on:
twitter
facebook
linkedin
copy
Potential Initial Access via DLL Search Order Hijacking
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1566
attack.t1566.001
attack.initial-access
attack.t1574
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Iviewers.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential JLI.dll Side-Loading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Kapeka Decrypted Backdoor Indicator
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Ke3chang/TidePool Malware Activity
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.g0004
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential LethalHTA Technique Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Libvlc.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Process Code Injection Via DD Utility
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
Potential LSASS Process Dump Via Procdump
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.credential-access
attack.t1003.001
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Potential Malicious AppX Package Installation Attempts
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Manage-bde.wsf Abuse To Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Potential Memory Dumping Activity Via LiveKD
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Meterpreter/CobaltStrike Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Potential MFA Bypass Using Legacy Client Authentication
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Potential Mfdetours.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mftrace.EXE Abuse
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading Via Defender Binaries
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential MsiExec Masquerading
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Potential MuddyWater APT Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.g0069
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential NetWire RAT Activity - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Notepad++ CVE-2025-49144 Exploitation
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.008
cve.2025-49144
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential NTLM Coercion Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Obfuscated Ordinal Call Via Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Potential Password Spraying Attempt Using Dsacls.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential PendingFileRenameOperations Tampering
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Attempt Via Existing Service Tampering
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1543.003
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Custom Protocol Handler
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Event Viewer Events.asp
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via GlobalFlags
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1546.012
car.2013-01-002
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Home Page
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Today Page
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Security Descriptors - ScriptBlock
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential Pikabot Hollowing Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.012
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1059.003
attack.t1105
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential PlugX Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.s0013
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Command Line Obfuscation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1027
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Downgrade Attack
calendar
Apr 28, 2026
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Execution Policy Tampering
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Execution Policy Tampering - ProcCreation
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Execution Via DLL
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Using Alias Cmdlets
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1027
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Using Character Join
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1027
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Via Reversed Commands
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Via WCHAR/CHAR
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Potential PrintNightmare Exploitation Attempt
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574
cve.2021-1675
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation Attempt Via .Exe.Local Technique
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Local Kerberos Relay over LDAP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Service Permissions Weakness
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Privileged System Service Operation - SeLoadDriverPrivilege
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Execution Proxy Via CL_Invocation.ps1
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Hollowing Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Injection Via Msra.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential Provisioning Registry Key Abuse For Binary Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Provlaunch.EXE Binary Proxy Execution Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Python DLL SideLoading
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Qakbot Registry Activity
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Qakbot Rundll32 Execution
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
attack.persistence
attack.t1542.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Aclui Dll SideLoading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin CPL Execution Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Rcdll.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential ReflectDebugger Content Execution Via WerFault.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potential Register_App.Vbs LOLScript Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Registry Persistence Attempt Via DbgManagedDebugger
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
Potential Regsvr32 Commandline Flag Anomaly
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote SquiblyTwo Technique Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1047
attack.t1220
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potential RemoteFXvGPUDisablement.EXE Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Default Location
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Non-Default Location
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RoboForm.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Rundll32 Execution With DLL Stored In ADS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Potential Secure Deletion with SDelete
calendar
Apr 28, 2026
·
attack.impact
attack.stealth
attack.defense-impairment
attack.t1070.004
attack.t1027.005
attack.t1485
attack.t1553.002
attack.s0195
·
Share on:
twitter
facebook
linkedin
copy
Potential ShellDispatch.DLL Functionality Abuse
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential ShellDispatch.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Signing Bypass Via Windows Developer Features
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Signing Bypass Via Windows Developer Features - Registry
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential SmadHook.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SolidPDFCreator.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Activity Using SeCEdit
calendar
Apr 28, 2026
·
attack.collection
attack.discovery
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.execution
attack.stealth
attack.defense-impairment
attack.t1685.001
attack.t1547.001
attack.t1505.005
attack.t1556.002
attack.t1685
attack.t1574.007
attack.t1564.002
attack.t1546.008
attack.t1546.007
attack.t1547.014
attack.t1547.010
attack.t1547.002
attack.t1557
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious BPF Activity - Linux
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Child Process Of 3CXDesktopApp
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Mofcomp Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Registry File Imported Via Reg.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Windows Feature Enabled
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Windows Feature Enabled - ProcCreation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Winget Package Installation
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential SysInternals ProcDump Evasion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Potential System DLL Sideloading From Non System Locations
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.lateral-movement
attack.defense-impairment
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With Security Products Via WMIC
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential UAC Bypass Via Sdclt.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Ursnif Malware Activity - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Vcruntime140 DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Vivaldi_elf.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Waveedit.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Wazuh Security Platform DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential WerFault ReflectDebugger Registry Value Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Windows Defender Tampering Via Wmic.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1047
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Winnti Dropper Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Potential WWlib.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Over Permissive Permissions Granted Using Dsacls.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious ASP.NET Compilation Via AspNetCompiler
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Cabinet File Expansion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Call To Win32_NTEventlogFile Class
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of ClickOnce Application
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of DiskShadow.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process of KeyScrambler.exe
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1203
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of Regsvr32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of VsCode
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Processes Spawned by ConHost
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious CMD Shell Output Redirect
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Using Reg.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.impact
attack.defense-impairment
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Via Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.impact
attack.defense-impairment
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious DLL Registered Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious DMP/HDMP File Creation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Event Viewer Child Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution From Parent Process In Public Folder
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1564
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution From Tmp Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious File Download From ZIP TLD
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious GoogleUpdate Child Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious NTFS Symlink Behavior Modification
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Office Document Executed From Trusted Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Ping/Copy Command Combination
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Regsvr32 HTTP IP Pattern
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Regsvr32 HTTP/FTP Pattern
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Rundll32 Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Rundll32.EXE Execution of UDL File
calendar
Apr 28, 2026
·
attack.execution
attack.command-and-control
attack.stealth
attack.t1218.011
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Self Extraction Directive File Created
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load
calendar
Apr 28, 2026
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious WDAC Policy File Creation
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Windows App Activity
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Wuauclt Network Connection
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded FromBase64String Cmdlet
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded Invoke Keyword
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Powershell Base64 Encoded MpPreference Cmdlet
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded Reflective Assembly Load
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
attack.t1620
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded WMI Classes
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Called from an Executable Version Mismatch
calendar
Apr 28, 2026
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Console History Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Core DLL Loaded Via Office Application
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Decompress Commands
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Powershell Defender Disable Scan Feature
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Powershell Defender Exclusion
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Deleted Mounted Share
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Powershell Detect Virtualization Environment
calendar
Apr 28, 2026
·
attack.discovery
attack.stealth
attack.t1497.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Downgrade Attack - PowerShell
calendar
Apr 28, 2026
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Executed From Headless ConHost Process
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1059.003
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Powershell Install a DLL in System Directory
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.002
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Logging Disabled Via Registry Key Tampering
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1564.001
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell MSI Install via WindowsInstaller COM From Remote Location
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script Change Permission Via Set-Acl
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script Change Permission Via Set-Acl - PsScript
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Set-Acl On Windows Folder
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Set-Acl On Windows Folder - PsScript
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222
·
Share on:
twitter
facebook
linkedin
copy
PowerShell ShellCode
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Store File In Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Powershell Timestomp
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
Powershell Token Obfuscation - Process Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.009
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Web Access Feature Enabled Via DISM
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
PowerShell WMI Win32_Product Install MSI
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Write-EventLog Usage
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
PPL Tampering Via WerFaultSecure
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Prefetch File Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Previously Installed IIS Module Was Removed
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
PrintBrm ZIP Creation of Extraction
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1105
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Privileged Account Creation
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Procdump Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Process Access via TrolleyExpress Exclusion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Process Creation Using Sysnative Folder
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Process Deletion of Its Own Executable
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Process Execution From A Potentially Suspicious Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Process Launched Without Image Name
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Process Memory Dump Via Comsvcs.DLL
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1036
attack.t1003.001
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Process Memory Dump Via Dotnet-Dump
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Process Proxy Execution Via Squirrel.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Program Executed Using Proxy/Local Command Via SSH.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Proxy Execution via Vshadow
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Proxy Execution Via Wuauclt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Ps.exe Renamed SysInternals Tool
calendar
Apr 28, 2026
·
attack.stealth
attack.g0035
attack.t1036.003
car.2013-05-009
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PSScriptPolicyTest Creation By Uncommon Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Execution
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1564.003
attack.t1134.002
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Suspicious Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - CleanWipe Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
PUA - DefenderCheck Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.005
·
Share on:
twitter
facebook
linkedin
copy
PUA - Potential PE Metadata Tamper Using Rcedit
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
attack.t1036
attack.t1027.005
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
PUA - Process Hacker Execution
calendar
Apr 28, 2026
·
attack.discovery
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1622
attack.t1564
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PUA - System Informer Execution
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.discovery
attack.stealth
attack.t1082
attack.t1564
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Publisher Attachment File Dropped In Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Pubprn.vbs Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216.001
·
Share on:
twitter
facebook
linkedin
copy
PwnKit Local Privilege Escalation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.001
detection.emerging-threats
cve.2021-4034
·
Share on:
twitter
facebook
linkedin
copy
Python Function Execution Security Warning Disabled In Excel
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Python Function Execution Security Warning Disabled In Excel - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Python Image Load By Non-Python Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.002
·
Share on:
twitter
facebook
linkedin
copy
Python One-Liners with Base64 Decoding
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.006
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Python One-Liners with Base64 Decoding - Linux
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.006
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Regsvr32 Calc Pattern
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Rundll32 Exports Execution
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Rundll32 Fake DLL Extension Execution
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Raccine Uninstall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Rare Remote Thread Creation By Uncommon Source Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Raw Paste Service Access
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1071.001
attack.t1102.001
attack.t1102.003
·
Share on:
twitter
facebook
linkedin
copy
RDP Connection Allowed Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
RDP over Reverse SSH Tunnel WFP
calendar
Apr 28, 2026
·
attack.command-and-control
attack.lateral-movement
attack.t1090.001
attack.t1090.002
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
RDP Port Forwarding Rule Added Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.command-and-control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed to Zero
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RedMimicry Winnti Playbook Registry Manipulation
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RedSun - Conhost.exe Spawned by TieringEngineService.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.002
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - Named Pipe Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1055
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - TieringEngineService.exe Detected as EICAR Test File
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1036.005
attack.t1685
attack.privilege-escalation
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Reg Add Suspicious Paths
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
RegAsm.EXE Execution Without CommandLine Flags or Files
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
RegAsm.EXE Initiating Network Connection To Public IP
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
Regedit as Trusted Installer
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
REGISTER_APP.VBS Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Registry Entries For Azorult Malware
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Explorer Policy Modification
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Hide Function from User
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Manipulation via WMI Stdregprov
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.discovery
attack.defense-impairment
attack.t1047
attack.t1112
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript - PowerShell
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification for OCI DLL Redirection
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.defense-impairment
attack.t1112
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification of MS-settings Protocol Handler
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.defense-impairment
attack.t1548.002
attack.t1546.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Via Regini.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Persistence via Service in Safe Mode
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Registry Tampering by Potentially Suspicious Processes
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry-Free Process Scope COR_PROFILER
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.012
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Suspicious File Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Uncommon Extension
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1574
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 Execution From Highly Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 Execution From Potential Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - NetSupport Execution From Unusual Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Renamed MeshAgent Execution - MacOS
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1219.002
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Renamed MeshAgent Execution - Windows
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1219.002
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - RURAT Execution From Unusual Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Remote AppX Package Downloaded from File Sharing or CDN Domain
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Remote CHM File Download/Execution Via HH.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.001
·
Share on:
twitter
facebook
linkedin
copy
Remote Code Execute via Winrm.vbs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Remote File Download Via Findstr.EXE
calendar
Apr 28, 2026
·
attack.credential-access
attack.command-and-control
attack.stealth
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Remote Registry Lateral Movement
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.defense-impairment
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation By Uncommon Source Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation In Uncommon Target Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation Ttdinject.exe Proxy
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation Via PowerShell In Uncommon Target
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Remote XSL Execution Via Msxsl.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Remotely Hosted HTA File Executed Via Mshta.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
Removal Of AMSI Provider Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Removal Of Index Value to Hide Schedule Task - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Removal of Potential COM Hijacking Registry Keys
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Removal Of SD Value to Hide Schedule Task - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Remove Exported Mailbox from Exchange Webserver
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Remove Immutable File Attribute
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Remove Immutable File Attribute - Auditd
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Remove Scheduled Cron Task/Job
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed AutoHotkey.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed AutoIt Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Renamed BOINC Client Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553
·
Share on:
twitter
facebook
linkedin
copy
Renamed BrowserCore.EXE Execution
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1528
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed CreateDump Utility Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Renamed CURL.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed FTP.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed Jusched.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed Mavinject.EXE Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
attack.t1218.013
·
Share on:
twitter
facebook
linkedin
copy
Renamed MegaSync Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Renamed Microsoft Teams Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed Msdt.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed NetSupport RAT Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed NirCmd.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed Office Binary Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed PAExec Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed PingCastle Binary Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed Plink Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Renamed Powershell Under Powershell Channel
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed ProcDump Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed Remote Utilities RAT (RURAT) Execution
calendar
Apr 28, 2026
·
attack.collection
attack.command-and-control
attack.discovery
attack.stealth
attack.s0592
·
Share on:
twitter
facebook
linkedin
copy
Renamed Schtasks Execution
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1036.003
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Renamed Vmnat.exe Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Renamed ZOHO Dctask64 Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1036
attack.t1055.001
attack.t1202
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Response File Execution Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Restricted Software Access By SRP
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.execution
attack.t1072
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering - ProcCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Rhadamanthys Stealer Module Launch Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Roles Activated Too Frequently
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Activation Doesn't Require MFA
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Are Not Being Used
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Assigned Outside PIM
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Root Account Enable Via Dsenableroot
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1078
attack.t1078.001
attack.t1078.003
attack.initial-access
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Root Certificate Installed - PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Root Certificate Installed From Susp Locations
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Rorschach Ransomware Execution Activity
calendar
Apr 28, 2026
·
attack.execution
attack.t1059.003
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Configuration in Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Execution as Configured in Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Run PowerShell Script from ADS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Run PowerShell Script from Redirected Input Stream
calendar
Apr 28, 2026
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Execution With Uncommon DLL Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Execution Without CommandLine Parameters
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 InstallScreenSaver Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Internet Connection
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Spawned Via Explorer.EXE
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
RunDLL32 Spawning Explorer
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 UNC Path Execution
calendar
Apr 28, 2026
·
attack.execution
attack.lateral-movement
attack.stealth
attack.t1021.002
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
RunMRU Registry Key Deletion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
RunMRU Registry Key Deletion - Registry
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
SafeBoot Registry Key Deleted Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation Masquerading as System Processes
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.stealth
attack.t1053.005
attack.t1036.004
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation with Curl and PowerShell Execution Combo
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.stealth
attack.t1053.005
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
SCM Database Privileged Operation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
SCR File Write Event
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect - SlashAndGrab Exploitation Indicators
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect User Database Modification - Security
calendar
Apr 28, 2026
·
cve.2024-1709
detection.emerging-threats
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
ScreenSaver Registry Key Set
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Scripted Diagnostics Turn Off Check Enabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Scripting/CommandLine Process Spawned Regsvr32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Sdclt Child Processes
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Sdiagnhost Calling Suspicious Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Process
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Registry Set
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Security Eventlog Cleared
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Security Service Disabled Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Self Extraction Directive File Created In Potentially Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Sensitive File Dump Via Print.EXE
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1003.003
attack.t1003.002
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Server Side Template Injection Strings
calendar
Apr 28, 2026
·
attack.stealth
attack.t1221
·
Share on:
twitter
facebook
linkedin
copy
Service Binary in Suspicious Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Service DACL Abuse To Hide Services Via Sc.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Key Deleted Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Key Read Access Request
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Permissions Weakness Check
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.011
stp.2a
·
Share on:
twitter
facebook
linkedin
copy
Service Security Descriptor Tampering Via Sc.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Service Startup Type Change Via Wmic.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1047
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service StartupType Change Via PowerShell Set-Service
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service StartupType Change Via Sc.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
SES Identity Has Been Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Set Suspicious Files as System Files Using Attrib.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Setuid and Setgid
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.t1548.001
·
Share on:
twitter
facebook
linkedin
copy
Setup16.EXE Execution With Custom .Lst File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
Shell Open Registry Keys Manipulation
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.t1548.002
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Shell32 DLL Execution in Suspicious Directory
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
ShimCache Flush
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Sign-in Failure Due to Conditional Access Requirements Not Met
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins by Unknown Devices
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins from Non-Compliant Devices
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Silenttrinity Stager Msbuild Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127.001
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware CommandLine Indicator
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware File Indicator Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Sofacy Trojan Loader Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.g0007
attack.t1059.003
attack.t1218.011
car.2013-10-002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Space After Filename - macOS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.006
·
Share on:
twitter
facebook
linkedin
copy
SQL Client Tools PowerShell Session Detection
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Stale Accounts In A Privileged Role
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Start of NT Virtual DOS Machine
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Startup/Logon Script Added to Group Policy Object
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Steganography Extract Files with Steghide
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Hide Files with Steghide
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Hide Zip Information in Picture File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Unzip Hidden Information From Picture File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Successful Authentications From Countries You Do Not Operate Out Of
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Successful Overpass the Hash Attempt
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.s0002
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1068
attack.t1548.003
cve.2019-14287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287 - Builtin
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1068
attack.t1548.003
cve.2019-14287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspect Svchost Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Advpack Call Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious AgentExecutor PowerShell Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Application Allowed Through Exploit Guard
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious BitLocker Access Agent Update Utility Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Browser Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Cabinet File Execution Via Msdt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Calculator Usage
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Created as System
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process of AspNetCompiler
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of BgInfo.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of Wermgr.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CodePage Switch Via CHCP
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Account Name Change CVE-2021-42287
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1036
attack.t1098
cve.2021-42287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Machine Password by PowerShell
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Control Panel DLL Load
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Copy From or To System Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Creation with Colorcpl
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Csi.exe Usage
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.execution
attack.stealth
attack.t1072
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CustomShellHost Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Diantz Alternate Data Stream Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Digital Signature Of AppX Package
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DLL Loaded via CertOC.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DotNET CLR Usage Log Artifact
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Double Extension Files
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download From Direct IP Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download From File-Sharing Website Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Driver/DLL Installation Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DumpMinitool Execution
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1036
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Environment Variable Has Been Registered
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Eventlog Clear
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Eventlog Clearing or Configuration Change Activity
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
attack.t1685.001
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Executable File Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Execution of InstallUtil Without Log
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Execution via macOS Script Editor
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1566
attack.t1566.002
attack.initial-access
attack.t1059
attack.t1059.002
attack.t1204
attack.t1204.001
attack.execution
attack.persistence
attack.t1553
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.004
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Extrac32 Alternate Data Stream Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created by ArcSOC.exe
calendar
Apr 28, 2026
·
attack.command-and-control
attack.persistence
attack.initial-access
attack.execution
attack.stealth
attack.t1127
attack.t1105
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created Via OneNote Application
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation Activity From Fake Recycle.Bin Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation In Uncommon AppData Folder
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Websites - File Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Downloaded From Direct IP Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Encoded To Base64 Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Filename with Embedded Base64 Commands
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.004
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Files in Default GPO Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get-Variable.exe Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1546
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GUP Usage
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious HH.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.initial-access
attack.stealth
attack.t1047
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.007
attack.t1218
attack.t1218.001
attack.t1218.010
attack.t1218.011
attack.t1566
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious High IntegrityLevel Conhost Legacy Option
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Hyper-V Cmdlets
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.006
·
Share on:
twitter
facebook
linkedin
copy
Suspicious IIS URL GlobalRules Rewrite Via AppCmd
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Inbox Manipulation Rules
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invoke-Item From Mount-DiskImage
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious IO.FileStream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious JavaScript Execution Via Mshta.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LNK Double Extension File Created
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1003
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Login Activity Classified By Google
calendar
Apr 28, 2026
·
attack.initial-access
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Microsoft Office Child Process
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1047
attack.t1204.002
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Mount-DiskImage
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msbuild Execution By Uncommon Parent Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious MSDT Parent Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious MSHTA Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.005
car.2013-02-003
car.2013-03-001
car.2014-04-003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious MsiExec Embedding Parent
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msiexec Execute Arbitrary DLL
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msiexec Quiet Install From Remote Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Network Connection Binary No CommandLine
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Obfuscated PowerShell Code
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Package Installed - Linux
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Parent Double Extension File Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Path In Keyboard Layout IME File Registry Value
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Ping/Del Command Combination
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Powercfg Execution To Change Lock Screen Timeout
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Invocations - Specific - ProcessCreation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell WindowStyle Option
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Printer Driver Empty Manufacturer
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1003.001
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Execution From Fake Recycle.Bin Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Masquerading As SvcHost.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Parents
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Start Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
car.2013-05-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PROCEXP152.sys File Created In TMP
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Provlaunch.EXE Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RASdial Activity
calendar
Apr 28, 2026
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RazerInstaller Explorer Subprocess
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1553
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Recursive Takeown
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Registry Modification From ADS Via Regini.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Regsvr32 Execution From Remote Share
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Child Process From Outlook
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Logon with Explicit Credentials
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Renamed Comsvcs DLL Loaded By Rundll32
calendar
Apr 28, 2026
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Response File Execution Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Activity Invoking Sys File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Execution With Image Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Invoking Inline VBScript
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Setupapi.dll Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Runscripthelper.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation via Masqueraded XML File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.stealth
attack.t1036.005
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Binary Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service DACL Modification Via Set-Service Cmdlet - PS
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Installed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Set Value of MSDT in Registry (CVE-2022-30190)
calendar
Apr 28, 2026
·
attack.stealth
attack.t1221
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Shell Open Command Registry Modification
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1548.002
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ShellExec_RunDLL Call Via Ordinal
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SignIns From A Non Registered Device
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Space Characters in RunMRU Registry Path - ClickFix
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.004
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Space Characters in TypedPaths Registry Path - FileFix
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.004
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Speech Runtime Binary Child Process
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.stealth
attack.t1021.003
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Splwow64 Without Params
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Start-Process PassThru
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Svchost Process Access
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SYSTEM User Process Creation
calendar
Apr 28, 2026
·
attack.credential-access
attack.privilege-escalation
attack.stealth
attack.t1134
attack.t1003
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Unblock-File
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Uninstall of Windows Defender Feature via PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Unsigned Thor Scanner Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Usage of For Loop with Recursive Directory Search in CMD
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.003
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Usage Of ShellExec_RunDLL
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Use of CSharp Interactive Console
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Userinit Child Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious VBoxDrvInst.exe Parameters
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Velociraptor Child Process
calendar
Apr 28, 2026
·
attack.command-and-control
attack.persistence
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Volume Shadow Copy VSS_PS.dll Load
calendar
Apr 28, 2026
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Volume Shadow Copy Vssapi.dll Load
calendar
Apr 28, 2026
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Vsls-Agent Command With AgentExtensionPath Load
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Service Tampering
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1489
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.t1685.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Update Agent Empty Cmdline
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious WMIC Execution Via Office Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1204.002
attack.t1047
attack.t1218.010
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious WmiPrvSE Child Process
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1047
attack.t1204.002
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Wordpad Outbound Connections
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Workstation Locking via Rundll32
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious X509Enrollment - Process Creation
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious X509Enrollment - Ps Script
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious XOR Encoded PowerShell Command
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1140
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ZipExec Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Execute Arbitrary PowerShell Code
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Execution to Bypass Powershell Restriction
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals PsSuspend Suspicious Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals Tools AppX Versions Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Syslog Clearing or Removal Via System Utilities
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Application Crashed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Blocked Executable
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Blocked File Shredding
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Channel Reference Deletion
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Change
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Error
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Modification
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Update
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Altitude Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Sysmon File Executable Creation Detected
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
System Control Panel Item Loaded From Uncommon Location
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
System File Execution Location Anomaly
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
System Information Discovery Using System_Profiler
calendar
Apr 28, 2026
·
attack.discovery
attack.stealth
attack.t1082
attack.t1497.001
·
Share on:
twitter
facebook
linkedin
copy
System Information Discovery Via Sysctl - MacOS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1497.001
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
TAIDOOR RAT DLL Load
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1055.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender - PSClassic
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender Remove-MpPreference
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper With Sophos AV Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Taskkill Symantec Endpoint Protection
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Taskmgr as LOCAL_SYSTEM
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Tasks Folder Evasion
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Log File Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Telegram API Access
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1071.001
attack.t1102.002
·
Share on:
twitter
facebook
linkedin
copy
Temporary Access Pass Added To An Account
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Terminal Server Client Connection History Cleared - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
The Windows Defender Firewall Service Failed To Load Group Policy
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Third Party Software DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Time Travel Debugging Utility Usage
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1218
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Time Travel Debugging Utility Usage - Image
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1218
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Tomcat WebServer Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Too Many Global Admins
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Touch Suspicious Service File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Default LockFile
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Default Persistence
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Execve Hijack
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Install Commands
calendar
Apr 28, 2026
·
attack.stealth
attack.t1014
·
Share on:
twitter
facebook
linkedin
copy
Troubleshooting Pack Cmdlet Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Trust Access Disable For VBApplications
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Trusted Path Bypass via Windows Directory Spoofing
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.007
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
TrustedPath UAC Bypass Pattern
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Commands May 2020
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.g0010
attack.execution
attack.t1059.001
attack.t1053.005
attack.t1027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - Registry
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Tools Using ComputerDefaults
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using .NET Code Profiler on MMC
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using ChangePK and SLUI
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Consent and Comctl32 - File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Consent and Comctl32 - Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Disk Cleanup
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using DismHost
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Event Viewer RecentViews
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using EventVwr
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IDiagnostic Profile
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IDiagnostic Profile - File
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IEInstal - File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IEInstal - Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Iscsicpl - ImageLoad
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using MSConfig Token Modification - File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using MSConfig Token Modification - Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using NTFS Reparse Point - File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using NTFS Reparse Point - Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using PkgMgr and DISM
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Windows Media Player - File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Windows Media Player - Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Windows Media Player - Registry
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using WOW64 Logger DLL Hijack
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via Event Viewer
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via ICMLuaUtil
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via Sdclt
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via Windows Firewall Snap-In Hijack
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Via Wsreset
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass With Fake DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1548.002
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass WSReset
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Disabled
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Notification Disabled
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Secure Desktop Prompt Disabled
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UEFI Persistence Via Wpbbin - FileCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.t1542.001
·
Share on:
twitter
facebook
linkedin
copy
UEFI Persistence Via Wpbbin - ProcessCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.t1542.001
·
Share on:
twitter
facebook
linkedin
copy
Ufw Force Stop Using Ufw-Init
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Unauthorized System Time Modification
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Barracuda ESG Exploitation Indicators
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Download Compressed Files From Temp.sh Using Wget
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Download Tar File From Untrusted Direct IP Via Wget
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Email Exfiltration File Pattern
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - SSL Certificate Exfiltration Via Openssl
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon AddinUtil.EXE CommandLine Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of AddinUtil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Appvlp.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of BgInfo.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Conhost.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Defaultpack.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Setres.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Spawned By Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Extension In Keyboard Layout IME File Registry Value
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Uncommon File Creation By Mysql Daemon Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Uncommon FileSystem Load Attempt By Format.com
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Link.EXE Parent Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Microsoft Office Trusted Location Added
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Uncommon New Firewall Rule Added In Windows Firewall Exception List
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Outbound Kerberos Connection
calendar
Apr 28, 2026
·
attack.credential-access
attack.t1558
attack.lateral-movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Process Access Rights For Target Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.011
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Sigverif.EXE Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Svchost Command Line Parameter
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1036.005
attack.t1055
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Svchost Parent Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Unfamiliar Sign-In Properties
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Crowdstrike Falcon Sensor
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Sysinternals Sysmon
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Unmount Share Via Net.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Unsigned .node File Loaded
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1129
attack.t1574.001
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Unsigned AppX Installation Attempt Using Add-AppxPackage
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Binary Loaded From Suspicious Location
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned DLL Loaded by Windows Utility
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Mfdetours.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Module Loaded by ClickOnce Application
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Download from Direct IP Address
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Download From File Sharing Websites - File Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Use Icacls to Hide File to Everyone
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Use NTFS Short Name in Command Line
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Use NTFS Short Name in Image
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Use Of Hidden Paths Or Files
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Use of Legacy Authentication Protocols
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Use of Remote.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use of Scriptrunner.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Use Of The SFTP.EXE Binary As A LOLBIN
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Use of TTDInject.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use of VisualUiaVerifyNative.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Use of VSIISExeLauncher.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use of Wfc.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use Short Name Path in Image
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
User Access Blocked by Azure Conditional Access
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.credential-access
attack.initial-access
attack.stealth
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Dscl
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via DseditGroup
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Sysadminctl
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added to an Administrator's Azure AD Role
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1098.003
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
User Added To Group With CA Policy Modification Access
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User Added to Local Administrator Group
calendar
Apr 28, 2026
·
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added To Privilege Role
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User Removed From Group With CA Policy Modification Access
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User Shell Folders Registry Modification via CommandLine
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1547.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
User State Changed From Guest To Member
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Added to Global or Device Admin Roles
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Authenticating To Other Azure AD Tenants
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Using SettingSyncHost.exe as LOLBin
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.008
·
Share on:
twitter
facebook
linkedin
copy
UtilityFunctions.ps1 Proxy Dll
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Verclsid.exe Runs COM Object
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Virtualbox Driver Installation or Starting of VMs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.006
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Visual Basic Command Line Compiler Usage
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Visual Studio NodejsTools PressAnyKey Renamed Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
VMGuestLib DLL Sideload
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Signed Dbghelp.DLL Potential Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Unsigned Dbghelp.DLL Potential Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Blocklist Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Netlogon Secure Channel Connection Allowed
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Wab Execution From Non Default Location
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Wab/Wabmig Unusual Parent Or Child Processes
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
WannaCry Ransomware Activity
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.defense-impairment
attack.t1210
attack.discovery
attack.t1083
attack.t1222.001
attack.impact
attack.t1486
attack.t1490
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Wdigest CredGuard Registry Modification
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Wdigest Enable UseLogonCredential
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Weak Encryption Enabled and Kerberoast
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Weak or Abused Passwords In CLI
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
WFP Filter Added via Registry
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Win Defender Restored Quarantine File
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Win Susp Computer Name Containing Samtheadmin
calendar
Apr 28, 2026
·
attack.initial-access
cve.2021-42278
cve.2021-42287
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
WinDivert Driver Load
calendar
Apr 28, 2026
·
attack.credential-access
attack.collection
attack.defense-impairment
attack.t1599.001
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Windows AMSI Related Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows AppX Deployment Full Trust Package Installation
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1204.002
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Windows AppX Deployment Unsigned Package Installation
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1204.002
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Windows Binaries Write Suspicious Extensions
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Windows Binary Executed From WSL
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Disabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Related Registry Value Deleted - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Default Domain GPO Modification
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Default Domain GPO Modification via GPME
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Configuration Changes
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Context Menu Removed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Definition Files Removed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion List Modified
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion Registry Key - Write Access Requested
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added - PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exploit Guard Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Firewall Has Been Reset To Its Default Configuration
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Grace Period Expired
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Malware And PUA Scanning Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Malware Detection History Deletion
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Real-time Protection Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Real-Time Protection Failure/Restart
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Service Disabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Submit Sample Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Threat Detection Service Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Threat Severity Default Action Modified
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Virus Scanning Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Auditing Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Log Access Tampering Via Registry
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.defense-impairment
attack.t1547.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Windows EventLog Autologger Session Registry Modification Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Filtering Platform Blocked Connection From EDR Agent Binary
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Firewall Disabled via PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Firewall Profile Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Windows Firewall Settings Have Been Changed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Windows Hypervisor Enforced Code Integrity Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Kernel Debugger Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Windows MSIX Package Support Framework AI_STUBS Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.defense-impairment
attack.t1218
attack.t1553.005
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Windows PowerShell User Agent
calendar
Apr 28, 2026
·
attack.command-and-control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Processes Suspicious Parent Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Windows Service Terminated With Error
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Windows Shell/Scripting Processes Spawning Suspicious Programs
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1059.001
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Windows Spooler Service Suspicious Binary Load
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574
cve.2021-1675
cve.2021-34527
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Windows Vulnerable Driver Blocklist Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Winget Admin Settings Modification
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Winlogon AllowMultipleTSSessions Enable
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Winnti Malware HK University Campaign
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Winnti Pipemon Characteristics
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Winrs Local Command Execution
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.stealth
attack.t1021.006
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Wlrmdr.EXE Uncommon Argument Or Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
WMIC Loading Scripting Libraries
calendar
Apr 28, 2026
·
attack.stealth
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
Write Protect For Storage Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Writing Of Malicious Files To The Fonts Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1211
attack.t1059
attack.persistence
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
WSL Child Process Anomaly
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
WSL Kali-Linux Usage
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
XBAP Execution From Uncommon Locations Via PresentationHost.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
XSL Script Execution Via WMIC.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1047
attack.t1220
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Xwizard.EXE Execution From Non-Default Location
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
ZxShell Malware
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.003
attack.t1218.011
attack.s0412
attack.g0001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated IP Download Activity
calendar
Apr 28, 2026
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated IP Via CLI
calendar
Apr 28, 2026
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
Delete Important Scheduled Task
calendar
Apr 28, 2026
·
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Disable Important Scheduled Task
calendar
Apr 28, 2026
·
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Important Scheduled Task Deleted or Disabled
calendar
Apr 28, 2026
·
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Important Scheduled Task Deleted/Disabled
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Disable System Restore
calendar
Apr 28, 2026
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
System Restore Registry Modification via CommandLine
calendar
Apr 28, 2026
·
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Application Access Level Modified
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Application Removed
calendar
Apr 28, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Granted Domain API Access
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace MFA Disabled
calendar
Apr 28, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Out Of Domain Email Forwarding
calendar
Apr 28, 2026
·
attack.t1114.003
attack.collection
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Role Modified or Deleted
calendar
Apr 28, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Role Privilege Deleted
calendar
Apr 28, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace User Granted Admin Privileges
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Potential Dropper Script Execution Via WScript/CScript/MSHTA
calendar
Apr 27, 2026
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Powershell Script Execution From Temp Folder
calendar
Apr 27, 2026
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Script Interpreter Execution From Suspicious Folder
calendar
Apr 27, 2026
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
WScript or CScript Dropper - File
calendar
Apr 27, 2026
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Change To Sensitive/Critical Files
calendar
Apr 27, 2026
·
attack.impact
attack.t1565.001
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI
calendar
Apr 27, 2026
·
attack.credential-access
attack.t1187
detection.emerging-threats
cve.2026-33829
·
Share on:
twitter
facebook
linkedin
copy
Github Delete Action Invoked
calendar
Apr 27, 2026
·
attack.impact
attack.collection
attack.t1213.003
·
Share on:
twitter
facebook
linkedin
copy
New Cron File Created
calendar
Apr 27, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Potential Enumeration Activity
calendar
Apr 27, 2026
·
attack.execution
attack.discovery
attack.t1609
attack.t1613
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Email Delivered In Microsoft 365
calendar
Apr 27, 2026
·
attack.initial-access
attack.t1566.001
attack.t1566.002
·
Share on:
twitter
facebook
linkedin
copy
Shell Invocation via Env Command - Linux
calendar
Apr 27, 2026
·
attack.execution
attack.t1059.004
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Download Via Net.WebClient - PowerShell Classic
calendar
Apr 27, 2026
·
attack.execution
attack.command-and-control
attack.t1059.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Netcat The Powershell Version
calendar
Apr 27, 2026
·
attack.command-and-control
attack.execution
attack.t1095
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Classes Autorun Keys Modification
calendar
Apr 27, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Office Autorun Keys Modification
calendar
Apr 27, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Office Macro File Creation
calendar
Apr 27, 2026
·
attack.initial-access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Outlook Security Settings Updated - Registry
calendar
Apr 27, 2026
·
attack.persistence
attack.t1137
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Visual Studio Tools for Office
calendar
Apr 27, 2026
·
attack.t1137.006
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Service Reconnaissance Via Wmic.EXE
calendar
Apr 27, 2026
·
attack.execution
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
PUA - Memory Dump Mount Via MemProcFS
calendar
Apr 27, 2026
·
attack.credential-access
attack.t1003
attack.t1003.001
attack.t1003.004
attack.t1003.002
·
Share on:
twitter
facebook
linkedin
copy
New Okta User Created
calendar
Apr 27, 2026
·
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Okta 2023 Breach Indicator Of Compromise
calendar
Apr 27, 2026
·
attack.credential-access
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Okta Admin Role Assigned to an User or Group
calendar
Apr 27, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Okta Admin Role Assignment Created
calendar
Apr 27, 2026
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Okta API Token Created
calendar
Apr 27, 2026
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Okta API Token Revoked
calendar
Apr 27, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Application Modified or Deleted
calendar
Apr 27, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Application Sign-On Policy Modified or Deleted
calendar
Apr 27, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta FastPass Phishing Detection
calendar
Apr 27, 2026
·
attack.initial-access
attack.t1566
·
Share on:
twitter
facebook
linkedin
copy
Okta Identity Provider Created
calendar
Apr 27, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1098.001
·
Share on:
twitter
facebook
linkedin
copy
Okta Network Zone Deactivated or Deleted
calendar
Apr 27, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Policy Modified or Deleted
calendar
Apr 27, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Policy Rule Modified or Deleted
calendar
Apr 27, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta Security Threat Detected
calendar
Apr 27, 2026
·
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Okta Suspicious Activity Reported by End-user
calendar
Apr 27, 2026
·
attack.resource-development
attack.t1586.003
·
Share on:
twitter
facebook
linkedin
copy
Okta Unauthorized Access to App
calendar
Apr 27, 2026
·
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
Okta User Account Locked Out
calendar
Apr 27, 2026
·
attack.impact
attack.t1531
·
Share on:
twitter
facebook
linkedin
copy
Potential Okta Password in AlternateID Field
calendar
Apr 27, 2026
·
attack.credential-access
attack.t1552
·
Share on:
twitter
facebook
linkedin
copy
HackTool - NetExec Execution
calendar
Apr 23, 2026
·
attack.discovery
attack.t1018
attack.lateral-movement
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
HackTool - NetExec File Indicators
calendar
Apr 23, 2026
·
attack.execution
attack.lateral-movement
attack.discovery
attack.t1021.002
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Notepad++ Updater DNS Query to Uncommon Domains
calendar
Apr 21, 2026
·
attack.collection
attack.credential-access
attack.t1195.002
attack.initial-access
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Uncommon File Created by Notepad++ Updater Gup.EXE
calendar
Apr 21, 2026
·
attack.collection
attack.credential-access
attack.t1195.002
attack.initial-access
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - Host Port Scan (SYN Scan)
calendar
Apr 20, 2026
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - NMAP FIN Scan
calendar
Apr 20, 2026
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - NMAP NULL Scan
calendar
Apr 20, 2026
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - NMAP OS Scan
calendar
Apr 20, 2026
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - NMAP XMAS Scan
calendar
Apr 20, 2026
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - RDP New Connection Attempt
calendar
Apr 20, 2026
·
attack.initial-access
attack.lateral-movement
attack.persistence
attack.t1133
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
calendar
Apr 1, 2026
·
attack.privilege-escalation
attack.t1068
cve.2025-32463
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
BPFDoor Abnormal Process ID or Lock File Accessed
calendar
Apr 1, 2026
·
attack.execution
attack.t1106
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
LiteLLM / TeamPCP Supply Chain Attack Indicators
calendar
Apr 1, 2026
·
attack.initial-access
attack.t1195.002
attack.collection
attack.t1560.001
attack.persistence
attack.privilege-escalation
attack.t1543.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
TeamPCP LiteLLM Supply Chain Attack Persistence Indicators
calendar
Apr 1, 2026
·
attack.persistence
attack.privilege-escalation
attack.t1543.002
attack.initial-access
attack.t1195.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Security Support Provider (SSP) Added to LSA Configuration
calendar
Apr 1, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1547.005
·
Share on:
twitter
facebook
linkedin
copy
Axios NPM Compromise File Creation Indicators - Linux
calendar
Apr 1, 2026
·
attack.initial-access
attack.t1195.002
attack.command-and-control
attack.t1105
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Axios NPM Compromise File Creation Indicators - MacOS
calendar
Apr 1, 2026
·
attack.initial-access
attack.t1195.002
attack.command-and-control
attack.t1105
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Axios NPM Compromise File Creation Indicators - Windows
calendar
Apr 1, 2026
·
attack.initial-access
attack.t1195.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Axios NPM Compromise Malicious C2 Domain DNS Query
calendar
Apr 1, 2026
·
attack.command-and-control
attack.t1071.001
attack.t1568
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PUA - TruffleHog Execution
calendar
Mar 29, 2026
·
attack.discovery
attack.credential-access
attack.t1083
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Script Interpreter Spawning Credential Scanner - Linux
calendar
Mar 29, 2026
·
attack.credential-access
attack.t1552
attack.execution
attack.collection
attack.t1005
attack.t1059.004
·
Share on:
twitter
facebook
linkedin
copy
Script Interpreter Spawning Credential Scanner - Windows
calendar
Mar 29, 2026
·
attack.credential-access
attack.t1552
attack.collection
attack.execution
attack.t1005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud 2.0 Malicious NPM Package Installation
calendar
Mar 29, 2026
·
attack.initial-access
attack.execution
attack.t1195.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud 2.0 Malicious NPM Package Installation - Linux
calendar
Mar 29, 2026
·
attack.initial-access
attack.execution
attack.t1195.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud Malicious Bun Execution
calendar
Mar 29, 2026
·
attack.t1195.002
attack.t1203
attack.execution
attack.initial-access
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud Malicious Bun Execution - Linux
calendar
Mar 29, 2026
·
attack.t1195.002
attack.t1203
attack.execution
attack.initial-access
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud Malicious GitHub Workflow Creation
calendar
Mar 29, 2026
·
attack.persistence
attack.credential-access
attack.t1552.001
attack.collection
attack.t1119
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud Malware Indicators - Linux
calendar
Mar 29, 2026
·
attack.execution
attack.t1059
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Shai-Hulud Malware Indicators - Windows
calendar
Mar 29, 2026
·
attack.execution
attack.t1059
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
HackTool - WSASS Execution
calendar
Mar 19, 2026
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
System Language Discovery via Reg.Exe
calendar
Mar 1, 2026
·
attack.discovery
attack.t1614.001
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Unmet Signing Level Requirements By File Under Validation
calendar
Mar 1, 2026
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Non Interactive PowerShell Process Spawned
calendar
Mar 1, 2026
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
OpenEDR Spawning Command Shell
calendar
Feb 28, 2026
·
attack.execution
attack.t1059.003
attack.lateral-movement
attack.t1021.004
attack.command-and-control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious File Creation by OpenEDR's ITSMService
calendar
Feb 28, 2026
·
attack.command-and-control
attack.t1105
attack.lateral-movement
attack.t1570
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
BloodHound Collection Files
calendar
Feb 28, 2026
·
attack.discovery
attack.t1087.001
attack.t1087.002
attack.t1482
attack.t1069.001
attack.t1069.002
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process of SolarWinds WebHelpDesk
calendar
Feb 13, 2026
·
attack.initial-access
attack.t1190
cve.2025-26399
cve.2025-40536
cve.2025-40551
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process of Notepad++ Updater - GUP.Exe
calendar
Feb 4, 2026
·
attack.collection
attack.credential-access
attack.t1195.002
attack.initial-access
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Direct Autorun Keys Modification
calendar
Jan 29, 2026
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Modify User Shell Folders Startup Value
calendar
Jan 29, 2026
·
attack.persistence
attack.privilege-escalation
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
DNS Query to External Service Interaction Domains
calendar
Jan 24, 2026
·
attack.initial-access
attack.t1190
attack.reconnaissance
attack.t1595.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Kernel Driver Utility (KDU) Execution
calendar
Jan 24, 2026
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Capabilities Discovery - Linux
calendar
Jan 24, 2026
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Local System Accounts Discovery - Linux
calendar
Jan 5, 2026
·
attack.discovery
attack.t1087.001
·
Share on:
twitter
facebook
linkedin
copy
Curl Web Request With Potential Custom User-Agent
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
File Download From IP URL Via Curl.EXE
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Insecure Proxy/DOH Transfer Via Curl.EXE
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Insecure Transfer Via Curl.EXE
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Local File Read Using Curl.EXE
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Cookies Session Hijacking
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Domain Via Curl.EXE
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From IP Via Curl.EXE
calendar
Dec 25, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
AppLocker Prevented Application or Script from Running
calendar
Dec 24, 2025
·
attack.execution
attack.t1204.002
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.006
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Crashed - Application
calendar
Dec 24, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ArcSOC.exe Child Process
calendar
Dec 21, 2025
·
attack.execution
attack.t1059
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder
calendar
Dec 12, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location
calendar
Dec 12, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious File Download From File Sharing Domain Via PowerShell.EXE
calendar
Dec 12, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Domain Via Wget.EXE
calendar
Dec 12, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Commandlets - PoshModule
calendar
Dec 10, 2025
·
attack.execution
attack.discovery
attack.t1482
attack.t1087
attack.t1087.001
attack.t1087.002
attack.t1069.001
attack.t1069.002
attack.t1069
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Commandlets - ProcessCreation
calendar
Dec 10, 2025
·
attack.execution
attack.discovery
attack.t1482
attack.t1087
attack.t1087.001
attack.t1087.002
attack.t1069.001
attack.t1069.002
attack.t1069
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Commandlets - ScriptBlock
calendar
Dec 10, 2025
·
attack.execution
attack.discovery
attack.t1482
attack.t1087
attack.t1087.001
attack.t1087.002
attack.t1069.001
attack.t1069.002
attack.t1069
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Scripts - FileCreation
calendar
Dec 10, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Scripts - PoshModule
calendar
Dec 10, 2025
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Linux Suspicious Child Process from Node.js - React2Shell
calendar
Dec 10, 2025
·
attack.execution
attack.t1059
attack.initial-access
attack.t1190
detection.emerging-threats
cve.2025-55182
·
Share on:
twitter
facebook
linkedin
copy
Windows Suspicious Child Process from Node.js - React2Shell
calendar
Dec 10, 2025
·
attack.execution
attack.t1059
attack.initial-access
attack.t1190
detection.emerging-threats
cve.2025-55182
·
Share on:
twitter
facebook
linkedin
copy
Potential Malicious Usage of CloudTrail System Manager
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.initial-access
attack.t1566
attack.t1566.002
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
calendar
Dec 9, 2025
·
attack.credential-access
attack.discovery
attack.t1552
attack.t1087
·
Share on:
twitter
facebook
linkedin
copy
Startup Folder File Write
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Wow6432Node CurrentVersion Autorun Keys Modification
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CredUI.DLL Loaded By Uncommon Process
calendar
Dec 9, 2025
·
attack.credential-access
attack.collection
attack.t1056.002
·
Share on:
twitter
facebook
linkedin
copy
Desktop.INI Created by Uncommon Process
calendar
Dec 9, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
GUI Input Capture - macOS
calendar
Dec 9, 2025
·
attack.collection
attack.credential-access
attack.t1056.002
·
Share on:
twitter
facebook
linkedin
copy
Audio Capture
calendar
Dec 8, 2025
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection of Image Data with Xclip Tool
calendar
Dec 8, 2025
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection with Xclip Tool - Auditd
calendar
Dec 8, 2025
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Creation Of An User Account
calendar
Dec 8, 2025
·
attack.t1136.001
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Credentials In Files - Linux
calendar
Dec 8, 2025
·
attack.credential-access
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Data Compressed
calendar
Dec 8, 2025
·
attack.exfiltration
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Data Exfiltration with Wget
calendar
Dec 8, 2025
·
attack.exfiltration
attack.t1048.003
·
Share on:
twitter
facebook
linkedin
copy
Linux Network Service Scanning - Auditd
calendar
Dec 8, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Loading of Kernel Module via Insmod
calendar
Dec 8, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1547.006
·
Share on:
twitter
facebook
linkedin
copy
Network Sniffing - Linux
calendar
Dec 8, 2025
·
attack.credential-access
attack.discovery
attack.t1040
·
Share on:
twitter
facebook
linkedin
copy
Overwriting the File with Dev Zero or Null
calendar
Dec 8, 2025
·
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Possible Coin Miner CPU Priority Param
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Potential Abuse of Linux Magic System Request Key
calendar
Dec 8, 2025
·
attack.execution
attack.t1059.004
attack.impact
attack.t1529
attack.t1489
attack.t1499
·
Share on:
twitter
facebook
linkedin
copy
Program Executions in Suspicious Folders
calendar
Dec 8, 2025
·
attack.t1587
attack.t1584
attack.resource-development
·
Share on:
twitter
facebook
linkedin
copy
Screen Capture with Import Tool
calendar
Dec 8, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Screen Capture with Xwd
calendar
Dec 8, 2025
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Service Reload or Start - Linux
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.002
·
Share on:
twitter
facebook
linkedin
copy
Special File Creation via Mknod Syscall
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Split A File Into Pieces - Linux
calendar
Dec 8, 2025
·
attack.exfiltration
attack.t1030
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Commands Linux
calendar
Dec 8, 2025
·
attack.execution
attack.t1059.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious History File Operations - Linux
calendar
Dec 8, 2025
·
attack.credential-access
attack.t1552.003
·
Share on:
twitter
facebook
linkedin
copy
System and Hardware Information Discovery
calendar
Dec 8, 2025
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
System Info Discovery via Sysinfo Syscall
calendar
Dec 8, 2025
·
attack.discovery
attack.t1057
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
System Owner or User Discovery - Linux
calendar
Dec 8, 2025
·
attack.discovery
attack.t1033
·
Share on:
twitter
facebook
linkedin
copy
System Shutdown/Reboot - Linux
calendar
Dec 8, 2025
·
attack.impact
attack.t1529
·
Share on:
twitter
facebook
linkedin
copy
Systemd Service Creation
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.002
·
Share on:
twitter
facebook
linkedin
copy
Unix Shell Configuration Modification
calendar
Dec 8, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.004
·
Share on:
twitter
facebook
linkedin
copy
Webshell Remote Command Execution
calendar
Dec 8, 2025
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Github Self-Hosted Runner Execution
calendar
Dec 3, 2025
·
attack.command-and-control
attack.t1102.002
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
DNS Query by Finger Utility
calendar
Nov 27, 2025
·
attack.command-and-control
attack.t1071.004
attack.execution
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
FileFix - Command Evidence in TypedPaths
calendar
Nov 27, 2025
·
attack.execution
attack.t1204.004
·
Share on:
twitter
facebook
linkedin
copy
Finger.EXE Execution
calendar
Nov 27, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated via Finger.EXE
calendar
Nov 27, 2025
·
attack.command-and-control
attack.t1071.004
attack.execution
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
Potential ClickFix Execution Pattern - Registry
calendar
Nov 27, 2025
·
attack.execution
attack.t1204.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious FileFix Execution Pattern
calendar
Nov 27, 2025
·
attack.execution
attack.t1204.004
·
Share on:
twitter
facebook
linkedin
copy
Grixba Malware Reconnaissance Activity
calendar
Nov 27, 2025
·
attack.reconnaissance
attack.t1595.001
attack.discovery
attack.t1046
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Add Port Monitor Persistence in Registry
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Advanced IP Scanner - File Event
calendar
Nov 26, 2025
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Anydesk Temporary Artefact
calendar
Nov 26, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using Event Viewer
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Change Default File Association Via Assoc
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Chromium Browser Headless Execution To Mockbin Like Site
calendar
Nov 26, 2025
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Chromium Browser Instance Executed With Custom Extension
calendar
Nov 26, 2025
·
attack.persistence
attack.t1176.001
·
Share on:
twitter
facebook
linkedin
copy
Console CodePage Lookup Via CHCP
calendar
Nov 26, 2025
·
attack.discovery
attack.t1614.001
·
Share on:
twitter
facebook
linkedin
copy
Creation of a Local Hidden User Account by Registry
calendar
Nov 26, 2025
·
attack.persistence
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
Cred Dump Tools Dropped Files
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1003.001
attack.t1003.002
attack.t1003.003
attack.t1003.004
attack.t1003.005
·
Share on:
twitter
facebook
linkedin
copy
Data Copied To Clipboard Via Clip.EXE
calendar
Nov 26, 2025
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Default RDP Port Changed to Non Standard Port
calendar
Nov 26, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Deleted Data Overwritten Via Cipher.EXE
calendar
Nov 26, 2025
·
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
DirLister Execution
calendar
Nov 26, 2025
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Domain Trust Discovery Via Dsquery
calendar
Nov 26, 2025
·
attack.discovery
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
DriverQuery.EXE Execution
calendar
Nov 26, 2025
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
File And SubFolder Enumeration Via Dir Command
calendar
Nov 26, 2025
·
attack.discovery
attack.t1217
·
Share on:
twitter
facebook
linkedin
copy
File Download From Browser Process Via Inline URL
calendar
Nov 26, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
calendar
Nov 26, 2025
·
attack.discovery
attack.t1135
·
Share on:
twitter
facebook
linkedin
copy
Findstr GPP Passwords
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1552.006
·
Share on:
twitter
facebook
linkedin
copy
Gpresult Display Group Policy Information
calendar
Nov 26, 2025
·
attack.discovery
attack.t1615
·
Share on:
twitter
facebook
linkedin
copy
IE Change Domain Zone
calendar
Nov 26, 2025
·
attack.persistence
attack.t1137
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Memory Dump Creation Via Taskmgr.EXE
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Reconnaissance Via Findstr.EXE
calendar
Nov 26, 2025
·
attack.credential-access
attack.t1552.006
·
Share on:
twitter