open-menu
closeme
Suspicious Child Process Of Veeam Dabatase
calendar
May 9, 2023
·
attack.initial_access
attack.persistence
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Domain Via Curl.EXE
calendar
May 9, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Veeam Backup Database Suspicious Query
calendar
May 9, 2023
·
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
Veeam Backup Servers Credential Dumping Script Execution
calendar
May 9, 2023
·
attack.credential_access
·
Share on:
twitter
facebook
linkedin
copy
Potential Homoglyph Attack Using Lookalike Characters
calendar
May 8, 2023
·
attack.defense_evasion
attack.t1036
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Homoglyph Attack Using Lookalike Characters in Filename
calendar
May 8, 2023
·
attack.defense_evasion
attack.t1036
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential SolidPDFCreator.DLL Sideloading
calendar
May 8, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Nginx Core Dump
calendar
May 8, 2023
·
attack.impact
attack.t1499.004
·
Share on:
twitter
facebook
linkedin
copy
Potential System Information Discovery Via Wmic.EXE
calendar
May 5, 2023
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Private Keys Reconnaissance Via CommandLine Tools
calendar
May 5, 2023
·
attack.credential_access
attack.t1552.004
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation By Uncommon Source Image
calendar
May 5, 2023
·
attack.privilege_escalation
attack.defense_evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Process Explorer Driver Creation By Non-Sysinternals Binary
calendar
May 5, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Process Monitor Driver Creation By Non-Sysinternals Binary
calendar
May 5, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CACTUSTORCH Remote Thread Creation
calendar
May 5, 2023
·
attack.defense_evasion
attack.execution
attack.t1055.012
attack.t1059.005
attack.t1059.007
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential CobaltStrike Process Injection
calendar
May 5, 2023
·
attack.defense_evasion
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
NTDS Exfiltration Filename Patterns
calendar
May 5, 2023
·
attack.credential_access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
NTDS.DIT Created
calendar
May 5, 2023
·
attack.credential_access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
NTDS.DIT Creation By Uncommon Process
calendar
May 5, 2023
·
attack.credential_access
attack.t1003.002
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Credential Dumping Attempt Via PowerShell Remote Thread
calendar
May 5, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGCORE.DLL
calendar
May 5, 2023
·
attack.defense_evasion
attack.persistence
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGHELP.DLL
calendar
May 5, 2023
·
attack.defense_evasion
attack.persistence
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Created In KeePass.EXE
calendar
May 5, 2023
·
attack.credential_access
attack.t1555.005
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation In Uncommon Target Image
calendar
May 5, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation Via PowerShell
calendar
May 5, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation Via PowerShell In Rundll32
calendar
May 5, 2023
·
attack.defense_evasion
attack.execution
attack.t1218.011
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DotNET CLR Usage Log Artifact
calendar
May 5, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created In PerfLogs
calendar
May 5, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
VHD Image Download Via Browser
calendar
May 5, 2023
·
attack.resource_development
attack.t1587.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Real-Time Protection Failure/Restart
calendar
May 5, 2023
·
attack.defense_evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Hacktool Download
calendar
May 5, 2023
·
attack.defense_evasion
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Console CodePage Lookup Via CHCP
calendar
May 5, 2023
·
attack.discovery
attack.t1614.001
·
Share on:
twitter
facebook
linkedin
copy
Standard User In High Privileged Group
calendar
May 5, 2023
·
attack.credential_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Program Names
calendar
May 5, 2023
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Base64 Encoded User-Agent
calendar
May 4, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Volume Shadow Copy Vssapi.dll Load
calendar
May 3, 2023
·
attack.defense_evasion
attack.impact
attack.t1490
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non-Browser Network Communication With Google API
calendar
May 3, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Curl File Upload - Linux
calendar
May 3, 2023
·
attack.exfiltration
attack.t1567
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Chromium Browser Instance Executed With Custom Extensions
calendar
May 3, 2023
·
attack.persistence
attack.t1176
·
Share on:
twitter
facebook
linkedin
copy
Binary Padding - Linux
calendar
May 2, 2023
·
attack.defense_evasion
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
A Member Was Added to a Security-Enabled Global Group
calendar
May 2, 2023
·
Share on:
twitter
facebook
linkedin
copy
A Member Was Removed From a Security-Enabled Global Group
calendar
May 2, 2023
·
Share on:
twitter
facebook
linkedin
copy
A Security-Enabled Global Group Was Deleted
calendar
May 2, 2023
·
Share on:
twitter
facebook
linkedin
copy
Admin User Remote Logon
calendar
May 2, 2023
·
attack.lateral_movement
attack.t1078.001
attack.t1078.002
attack.t1078.003
car.2016-04-005
·
Share on:
twitter
facebook
linkedin
copy
DiagTrackEoP Default Login Username
calendar
May 2, 2023
·
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
External Remote RDP Logon from Public IP
calendar
May 2, 2023
·
attack.initial_access
attack.credential_access
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
External Remote SMB Logon from Public IP
calendar
May 2, 2023
·
attack.initial_access
attack.credential_access
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Logon From Public IP
calendar
May 2, 2023
·
attack.initial_access
attack.persistence
attack.t1078
attack.t1190
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Hidden Local User Creation
calendar
May 2, 2023
·
attack.persistence
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
KDC RC4-HMAC Downgrade CVE-2022-37966
calendar
May 2, 2023
·
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
KrbRelayUp Attack Pattern
calendar
May 2, 2023
·
attack.privilege_escalation
attack.credential_access
·
Share on:
twitter
facebook
linkedin
copy
««
«
3
4
5
6
7
»
»»
to-top