open-menu
closeme
ESXi Syslog Configuration Change Via ESXCLI
calendar
Sep 7, 2023
·
attack.defense_evasion
attack.t1562.001
attack.t1562.003
·
Share on:
twitter
facebook
linkedin
copy
ESXi Account Creation Via ESXCLI
calendar
Sep 6, 2023
·
attack.persistence
attack.t1136
·
Share on:
twitter
facebook
linkedin
copy
ESXi Admin Permission Assigned To Account Via ESXCLI
calendar
Sep 6, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
ESXi Network Configuration Discovery Via ESXCLI
calendar
Sep 6, 2023
·
attack.discovery
attack.t1033
attack.t1007
·
Share on:
twitter
facebook
linkedin
copy
ESXi Storage Information Discovery Via ESXCLI
calendar
Sep 6, 2023
·
attack.discovery
attack.t1033
attack.t1007
·
Share on:
twitter
facebook
linkedin
copy
ESXi System Information Discovery Via ESXCLI
calendar
Sep 6, 2023
·
attack.discovery
attack.t1033
attack.t1007
·
Share on:
twitter
facebook
linkedin
copy
ESXi VM Kill Via ESXCLI
calendar
Sep 6, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
ESXi VM List Discovery Via ESXCLI
calendar
Sep 6, 2023
·
attack.discovery
attack.t1033
attack.t1007
·
Share on:
twitter
facebook
linkedin
copy
ESXi VSAN Information Discovery Via ESXCLI
calendar
Sep 6, 2023
·
attack.discovery
attack.t1033
attack.t1007
·
Share on:
twitter
facebook
linkedin
copy
Interactive Bash Suspicious Children
calendar
Aug 28, 2023
·
attack.execution
attack.defense_evasion
attack.t1059.004
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Linux Crypto Mining Indicators
calendar
Aug 28, 2023
·
attack.impact
attack.t1496
·
Share on:
twitter
facebook
linkedin
copy
Nohup Execution
calendar
Aug 28, 2023
·
attack.execution
attack.t1059.004
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution From Tmp Folder
calendar
Aug 28, 2023
·
attack.defense_evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Container Residence Discovery Via Proc Virtual FS
calendar
Aug 24, 2023
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Docker Container Discovery Via Dockerenv Listing
calendar
Aug 24, 2023
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Container Discovery Via Inodes Listing
calendar
Aug 24, 2023
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Amazon SSM Agent Hijacking
calendar
Aug 3, 2023
·
attack.command_and_control
attack.persistence
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Named Pipe Created Via Mkfifo
calendar
Jun 19, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Linux Base64 Encoded Pipe to Shell
calendar
Jun 18, 2023
·
attack.defense_evasion
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Named Pipe Created Via Mkfifo
calendar
Jun 18, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Python Spawning Pretty TTY
calendar
Jun 18, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Crontab Enumeration
calendar
Jun 2, 2023
·
attack.discovery
attack.t1007
·
Share on:
twitter
facebook
linkedin
copy
Download File To Potentially Suspicious Directory Via Wget
calendar
Jun 2, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Execution Of Script Located In Potentially Suspicious Directory
calendar
Jun 2, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
OS Architecture Discovery Via Grep
calendar
Jun 2, 2023
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential GobRAT File Discovery Via Grep
calendar
Jun 2, 2023
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Shell Execution Of Process Located In Tmp Directory
calendar
Jun 2, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Nohup Execution
calendar
Jun 2, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Change To Sensitive/Critical Files
calendar
May 30, 2023
·
attack.impact
attack.t1565.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Curl File Upload - Linux
calendar
May 3, 2023
·
attack.exfiltration
attack.t1567
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Bash Interactive Shell
calendar
Apr 25, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Netcat Reverse Shell Execution
calendar
Apr 25, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Potential Perl Reverse Shell Execution
calendar
Apr 25, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential PHP Reverse Shell
calendar
Apr 25, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Python Reverse Shell
calendar
Apr 25, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Ruby Reverse Shell
calendar
Apr 25, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Potential Xterm Reverse Shell
calendar
Apr 25, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
System Network Discovery - Linux
calendar
Apr 5, 2023
·
attack.discovery
attack.t1016
·
Share on:
twitter
facebook
linkedin
copy
Terminate Linux Process Via Kill
calendar
Mar 20, 2023
·
attack.defense_evasion
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Linux Package Uninstall
calendar
Mar 12, 2023
·
attack.defense_evasion
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Linux Network Service Scanning
calendar
Mar 5, 2023
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Vim GTFOBin Abuse - Linux
calendar
Feb 6, 2023
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Apache Spark Shell Command Injection - ProcessCreation
calendar
Feb 1, 2023
·
attack.initial_access
attack.t1190
cve.2022.33891
·
Share on:
twitter
facebook
linkedin
copy
Apt GTFOBin Abuse - Linux
calendar
Feb 1, 2023
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Atlassian Confluence CVE-2022-26134
calendar
Feb 1, 2023
·
attack.initial_access
attack.execution
attack.t1190
attack.t1059
cve.2022.26134
·
Share on:
twitter
facebook
linkedin
copy
Capabilities Discovery - Linux
calendar
Feb 1, 2023
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Cat Sudoers
calendar
Feb 1, 2023
·
attack.reconnaissance
attack.t1592.004
·
Share on:
twitter
facebook
linkedin
copy
Commands to Clear or Remove the Syslog
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1070.002
·
Share on:
twitter
facebook
linkedin
copy
Curl Usage on Linux
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Disable Or Stop Services
calendar
Feb 1, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Enable BPF Kprobes Tracing
calendar
Feb 1, 2023
·
attack.execution
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
History File Deletion
calendar
Feb 1, 2023
·
attack.impact
attack.t1565.001
·
Share on:
twitter
facebook
linkedin
copy
Linux Base64 Encoded Shebang In CLI
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Linux HackTool Execution
calendar
Feb 1, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Linux Recon Indicators
calendar
Feb 1, 2023
·
attack.reconnaissance
attack.t1592.004
attack.credential_access
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Linux Shell Pipe to Shell
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Linux Webshell Indicators
calendar
Feb 1, 2023
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Discovery Activity Using Find - Linux
calendar
Feb 1, 2023
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Print History File Contents
calendar
Feb 1, 2023
·
attack.reconnaissance
attack.t1592.004
·
Share on:
twitter
facebook
linkedin
copy
Remove Immutable File Attribute
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Remove Scheduled Cron Task/Job
calendar
Feb 1, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1068
attack.t1548.003
cve.2019.14287
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Curl Change User Agents - Linux
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Git Clone - Linux
calendar
Feb 1, 2023
·
attack.reconnaissance
attack.t1593.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Java Children Processes
calendar
Feb 1, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Package Installed - Linux
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Execve Hijack
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Install Commands
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1014
·
Share on:
twitter
facebook
linkedin
copy
Copy Passwd Or Shadow From TMP Path
calendar
Jan 31, 2023
·
attack.credential_access
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Mount Execution With Hidepid Parameter
calendar
Jan 31, 2023
·
attack.credential_access
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Touch Suspicious Service File
calendar
Jan 31, 2023
·
attack.defense_evasion
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
Flush Iptables Ufw Chain
calendar
Jan 30, 2023
·
attack.defense_evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
Ufw Force Stop Using Ufw-Init
calendar
Jan 30, 2023
·
attack.defense_evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
BPFtrace Unsafe Option Usage
calendar
Jan 27, 2023
·
attack.execution
attack.t1059.004
·
Share on:
twitter
facebook
linkedin
copy
System Network Connections Discovery - Linux
calendar
Jan 17, 2023
·
attack.discovery
attack.t1049
·
Share on:
twitter
facebook
linkedin
copy
Setuid and Setgid
calendar
Jan 10, 2023
·
attack.persistence
attack.t1548.001
·
Share on:
twitter
facebook
linkedin
copy
Decode Base64 Encoded Text
calendar
Dec 29, 2022
·
attack.defense_evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Group Has Been Deleted Via Groupdel
calendar
Dec 27, 2022
·
attack.impact
attack.t1531
·
Share on:
twitter
facebook
linkedin
copy
User Has Been Deleted Via Userdel
calendar
Dec 27, 2022
·
attack.impact
attack.t1531
·
Share on:
twitter
facebook
linkedin
copy
User Added To Root/Sudoers Group Using Usermod
calendar
Dec 21, 2022
·
attack.privilege_escalation
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Local Groups Discovery - Linux
calendar
Nov 28, 2022
·
attack.discovery
attack.t1069.001
·
Share on:
twitter
facebook
linkedin
copy
Local System Accounts Discovery - Linux
calendar
Nov 28, 2022
·
attack.discovery
attack.t1087.001
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Cron Task/Job - Linux
calendar
Nov 28, 2022
·
attack.execution
attack.persistence
attack.privilege_escalation
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Security Software Discovery - Linux
calendar
Nov 28, 2022
·
attack.discovery
attack.t1518.001
·
Share on:
twitter
facebook
linkedin
copy
File and Directory Discovery - Linux
calendar
Nov 25, 2022
·
attack.discovery
attack.t1083
·
Share on:
twitter
facebook
linkedin
copy
Chmod Suspicious Directory
calendar
Oct 25, 2022
·
attack.defense_evasion
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Clear Linux Logs
calendar
Oct 25, 2022
·
attack.defense_evasion
attack.t1070.002
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection with Xclip Tool
calendar
Oct 25, 2022
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Connection Proxy
calendar
Oct 25, 2022
·
attack.defense_evasion
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
DD File Overwrite
calendar
Oct 25, 2022
·
attack.impact
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
File Deletion
calendar
Oct 25, 2022
·
attack.defense_evasion
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Install Root Certificate
calendar
Oct 25, 2022
·
attack.defense_evasion
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Linux Remote System Discovery
calendar
Oct 25, 2022
·
attack.discovery
attack.t1018
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteScript
calendar
Oct 25, 2022
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteShellCommand
calendar
Oct 25, 2022
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Process Discovery
calendar
Oct 25, 2022
·
attack.discovery
attack.t1057
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task/Job At
calendar
Oct 25, 2022
·
attack.persistence
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
System Information Discovery
calendar
Oct 25, 2022
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Disabling Security Tools
calendar
Oct 9, 2022
·
attack.defense_evasion
attack.t1562.004
·
Share on:
twitter
facebook
linkedin
copy
Linux Doas Tool Execution
calendar
Sep 16, 2022
·
attack.privilege_escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
to-top