open-menu
closeme
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious PowerShell Module File Created
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potential SysInternals ProcDump Evasion
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1036
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Wazuh Security Platform DLL Sideloading
calendar
May 15, 2023
·
attack.defense_evasion
attack.persistence
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Decompress Commands
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Get Clipboard
calendar
May 15, 2023
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Module File Created
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Module File Created By Non-PowerShell Process
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script Dropped Via PowerShell.EXE
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PSEXEC Remote Execution File Artefact
calendar
May 15, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.execution
attack.persistence
attack.t1136.002
attack.t1543.003
attack.t1570
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
PUA - Process Hacker Driver Load
calendar
May 15, 2023
·
attack.privilege_escalation
cve.2021.21551
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PUA - Process Hacker Execution
calendar
May 15, 2023
·
Share on:
twitter
facebook
linkedin
copy
PUA - System Informer Driver Load
calendar
May 15, 2023
·
attack.privilege_escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PUA - System Informer Execution
calendar
May 15, 2023
·
Share on:
twitter
facebook
linkedin
copy
Rclone Config File Creation
calendar
May 15, 2023
·
attack.exfiltration
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
Remote PowerShell Session (PS Module)
calendar
May 15, 2023
·
attack.execution
attack.t1059.001
attack.lateral_movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Rename Common File to DLL File
calendar
May 15, 2023
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect Temporary Installation Artefact
calendar
May 15, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Appended Extension
calendar
May 15, 2023
·
attack.impact
attack.t1486
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Machine Password by PowerShell
calendar
May 15, 2023
·
attack.initial_access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DNS Query for IP Lookup Service APIs
calendar
May 15, 2023
·
attack.reconnaissance
attack.t1590
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Double Extension Files
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation In Uncommon AppData Folder
calendar
May 15, 2023
·
attack.defense_evasion
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get Information for SMB Share - PowerShell Module
calendar
May 15, 2023
·
attack.discovery
attack.t1069.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get Local Groups Information
calendar
May 15, 2023
·
attack.discovery
attack.t1069.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get-ADDBAccount Usage
calendar
May 15, 2023
·
attack.credential_access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LNK Double Extension File
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Network Connection to IP Lookup Service APIs
calendar
May 15, 2023
·
attack.discovery
attack.t1016
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Download - PoshModule
calendar
May 15, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Invocations - Generic - PowerShell Module
calendar
May 15, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Invocations - Specific - PowerShell Module
calendar
May 15, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Usage Of Web Request Commands And Cmdlets
calendar
May 15, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Usage Of Web Request Commands And Cmdlets - ScriptBlock
calendar
May 15, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Use Get-NetTCPConnection - PowerShell Module
calendar
May 15, 2023
·
attack.discovery
attack.t1049
·
Share on:
twitter
facebook
linkedin
copy
Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
calendar
May 15, 2023
·
attack.collection
attack.t1074.001
·
Share on:
twitter
facebook
linkedin
copy
WinSxS Executable File Creation By Non-System Process
calendar
May 12, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Ransomware Activity Using LegalNotice Message
calendar
May 11, 2023
·
attack.impact
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Okta FastPass Phishing Detection
calendar
May 10, 2023
·
attack.initial_access
attack.t1566
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Network Connection To Notion API
calendar
May 9, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
LSASS Access From Program in Potentially Suspicious Folder
calendar
May 9, 2023
·
attack.credential_access
attack.t1003.001
attack.s0002
·
Share on:
twitter
facebook
linkedin
copy
NTDS.DIT Creation By Uncommon Parent Process
calendar
May 9, 2023
·
attack.credential_access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Base64 Encoded User-Agent
calendar
May 9, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
calendar
May 9, 2023
·
attack.defense_evasion
attack.persistence
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via PowerShell User Profile Using Add-Content
calendar
May 9, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1546.013
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Download and Execution Cradles
calendar
May 9, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script With File Hostname Resolving Capabilities
calendar
May 9, 2023
·
attack.exfiltration
attack.t1020
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script With File Upload Capabilities
calendar
May 9, 2023
·
attack.exfiltration
attack.t1020
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of SQL Server
calendar
May 9, 2023
·
attack.t1505.003
attack.t1190
attack.initial_access
attack.persistence
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
««
«
2
3
4
5
6
»
»»
to-top