open-menu
closeme
Potential SquiblyTwo Technique Execution
calendar
May 26, 2023
·
attack.defense_evasion
attack.t1047
attack.t1220
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious ODBC Driver Registered
calendar
May 26, 2023
·
attack.persistence
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Regsvr32 HTTP IP Pattern
calendar
May 26, 2023
·
attack.defense_evasion
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Regsvr32 HTTP/FTP Pattern
calendar
May 26, 2023
·
attack.defense_evasion
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Suspicious File Extension
calendar
May 26, 2023
·
attack.defense_evasion
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Cisco Clear Logs
calendar
May 26, 2023
·
attack.defense_evasion
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Driver/DLL Installation Via Odbcconf.EXE
calendar
May 23, 2023
·
attack.defense_evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
New DLL Registered Via Odbcconf.EXE
calendar
May 23, 2023
·
attack.defense_evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
New ODBC Driver Registered
calendar
May 23, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious DLL Registered Via Odbcconf.EXE
calendar
May 23, 2023
·
attack.defense_evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Response File Execution Via Odbcconf.EXE
calendar
May 23, 2023
·
attack.defense_evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Driver/DLL Installation Via Odbcconf.EXE
calendar
May 23, 2023
·
attack.defense_evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Spawned By Odbcconf.EXE
calendar
May 23, 2023
·
attack.defense_evasion
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LDAP Domain Access
calendar
May 23, 2023
·
attack.discovery
attack.t1482
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Volume Shadow Copy VSS_PS.dll Load
calendar
May 23, 2023
·
attack.defense_evasion
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Windows Shell/Scripting Processes Spawning Suspicious Programs
calendar
May 23, 2023
·
attack.execution
attack.defense_evasion
attack.t1059.005
attack.t1059.001
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Goopdate.DLL Sideloading
calendar
May 20, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Relevant File Paths Alerts
calendar
May 19, 2023
·
attack.resource_development
attack.t1588
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non-Browser Network Communication With Telegram API
calendar
May 19, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Certificate Exported From Local Certificate Store
calendar
May 18, 2023
·
attack.credential_access
attack.t1649
·
Share on:
twitter
facebook
linkedin
copy
Certificate Private Key Acquired
calendar
May 18, 2023
·
attack.credential_access
attack.t1649
·
Share on:
twitter
facebook
linkedin
copy
Certificate Exported Via PowerShell
calendar
May 18, 2023
·
Share on:
twitter
facebook
linkedin
copy
Certificate Exported Via PowerShell - ScriptBlock
calendar
May 18, 2023
·
attack.credential_access
attack.t1552.004
·
Share on:
twitter
facebook
linkedin
copy
Password Policy Enumerated
calendar
May 18, 2023
·
attack.discovery
attack.t1201
·
Share on:
twitter
facebook
linkedin
copy
APT40 Dropbox Tool User Agent
calendar
May 18, 2023
·
attack.command_and_control
attack.t1071.001
attack.exfiltration
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
Download from Suspicious Dyndns Hosts
calendar
May 18, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1105
attack.t1568
·
Share on:
twitter
facebook
linkedin
copy
Download From Suspicious TLD - Blacklist
calendar
May 18, 2023
·
attack.initial_access
attack.t1566
attack.execution
attack.t1203
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Download From Suspicious TLD - Whitelist
calendar
May 18, 2023
·
attack.initial_access
attack.t1566
attack.execution
attack.t1203
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Telegram API Access
calendar
May 18, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
attack.t1102.002
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious File Download From ZIP TLD
calendar
May 18, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Memory Dump Files
calendar
May 18, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Websites
calendar
May 18, 2023
·
attack.defense_evasion
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potential WWlib.DLL Sideloading
calendar
May 18, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Download From File Sharing Websites
calendar
May 18, 2023
·
attack.defense_evasion
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GrantedAccess Flags on LSASS Access
calendar
May 18, 2023
·
attack.credential_access
attack.t1003.001
attack.s0002
·
Share on:
twitter
facebook
linkedin
copy
Cscript/Wscript Suspicious Child Process
calendar
May 17, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Cscript/Wscript Uncommon Script Extension Execution
calendar
May 17, 2023
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Eventlog Cleared
calendar
May 17, 2023
·
attack.defense_evasion
attack.t1070.001
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
File Encoded To Base64 Via Certutil.EXE
calendar
May 17, 2023
·
attack.defense_evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Eventlog Cleared
calendar
May 17, 2023
·
attack.defense_evasion
attack.t1070.001
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Internet Explorer DisableFirstRunCustomize Enabled
calendar
May 17, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Kernel Memory Dump Via LiveKD
calendar
May 17, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation
calendar
May 17, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation By Uncommon Process
calendar
May 17, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Kernel Memory Dump File Created
calendar
May 17, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential Memory Dumping Activity Via LiveKD
calendar
May 17, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Obfuscated Ordinal Call Via Rundll32
calendar
May 17, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Rundll32 Activity
calendar
May 17, 2023
·
attack.defense_evasion
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Process Memory Dump Via Comsvcs.DLL
calendar
May 17, 2023
·
attack.defense_evasion
attack.credential_access
attack.t1036
attack.t1003.001
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executed Uncommon LOLBIN
calendar
May 17, 2023
·
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
««
«
1
2
3
4
5
»
»»
to-top