open-menu
closeme
account_management
calendar
Nov 27, 2023
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion Deleted
calendar
Nov 15, 2023
·
attack.defense_evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion List Modified
calendar
Nov 15, 2023
·
attack.defense_evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion Reigstry Key - Write Access Requested
calendar
Nov 15, 2023
·
attack.defense_evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
ISO Image Mounted
calendar
Nov 10, 2023
·
attack.initial_access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Potential AD User Enumeration From Non-Machine Account
calendar
Nov 8, 2023
·
attack.discovery
attack.t1087.002
·
Share on:
twitter
facebook
linkedin
copy
Service Installed By Unusual Client - Security
calendar
Nov 2, 2023
·
attack.privilege_escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Win Susp Computer Name Containing Samtheadmin
calendar
Nov 2, 2023
·
cve.2021.42278
cve.2021.42287
attack.persistence
attack.privilege_escalation
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Active Directory Replication from Non Machine Account
calendar
Oct 18, 2023
·
attack.credential_access
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
AD Privileged Users or Groups Reconnaissance
calendar
Oct 18, 2023
·
attack.discovery
attack.t1087.002
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - Security
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - Security
calendar
Oct 18, 2023
·
attack.privilege_escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Possible Shadow Credentials Added
calendar
Oct 18, 2023
·
attack.credential_access
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
SCM Database Handle Failure
calendar
Oct 18, 2023
·
attack.discovery
attack.t1010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outbound Kerberos Connection - Security
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Account Tampering - Suspicious Failed Logon Reasons
calendar
Oct 17, 2023
·
attack.persistence
attack.defense_evasion
attack.privilege_escalation
attack.initial_access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Add or Remove Computer from DC
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.t1207
·
Share on:
twitter
facebook
linkedin
copy
Device Installation Blocked
calendar
Oct 17, 2023
·
attack.initial_access
attack.t1200
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - Security
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
LSASS Access from Non System Account
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Metasploit Or Impacket Service Installation Via SMB PsExec
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1021.002
attack.t1570
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Mimikatz DC Sync
calendar
Oct 17, 2023
·
attack.credential_access
attack.s0002
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened (Email Attachment)
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.initial_access
attack.t1027
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened (Suspicious Filenames)
calendar
Oct 17, 2023
·
attack.command_and_control
attack.defense_evasion
attack.t1027
attack.t1105
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
PetitPotam Suspicious Kerberos TGT Request
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Possible DC Shadow Attack
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1207
·
Share on:
twitter
facebook
linkedin
copy
Possible Impacket SecretDump Remote Activity
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1003.002
attack.t1003.004
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Possible PetitPotam Coerce Authentication Attempt
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Powerview Add-DomainObjectAcl DCSync AD Extend Right
calendar
Oct 17, 2023
·
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
RDP over Reverse SSH Tunnel WFP
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.command_and_control
attack.lateral_movement
attack.t1090.001
attack.t1090.002
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Replay Attack Detected
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1558
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Kerberos RC4 Ticket Encryption
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Logon with Explicit Credentials
calendar
Oct 17, 2023
·
attack.t1078
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation
calendar
Oct 17, 2023
·
attack.execution
attack.privilege_escalation
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Update
calendar
Oct 17, 2023
·
attack.execution
attack.privilege_escalation
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Teams Application Related ObjectAcess Event
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1528
·
Share on:
twitter
facebook
linkedin
copy
User Logoff Event
calendar
Oct 17, 2023
·
Share on:
twitter
facebook
linkedin
copy
User with Privileges Logon
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.lateral_movement
attack.credential_access
attack.t1558
attack.t1649
attack.t1550
·
Share on:
twitter
facebook
linkedin
copy
VSSAudit Security Event Source Registration
calendar
Oct 17, 2023
·
attack.credential_access
attack.t1003.002
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious AccessMask Requested From LSASS
calendar
Oct 12, 2023
·
attack.credential_access
car.2019-04-004
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Key Read Access Request
calendar
Sep 29, 2023
·
attack.defense_evasion
attack.persistence
attack.privilege_escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Credential Dumping Tools Service Execution - Security
calendar
Aug 7, 2023
·
attack.credential_access
attack.execution
attack.t1003.001
attack.t1003.002
attack.t1003.004
attack.t1003.005
attack.t1003.006
attack.t1569.002
attack.s0005
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Event Auditing Disabled
calendar
Jul 13, 2023
·
attack.defense_evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Auditing Disabled
calendar
Jul 13, 2023
·
attack.defense_evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
Enabled User Right in AD to Control User Objects
calendar
Jun 26, 2023
·
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
SMB Create Remote File Admin Share
calendar
Jun 26, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Weak Encryption Enabled and Kerberoast
calendar
Jun 26, 2023
·
attack.defense_evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool Services Have Been Installed - Security
calendar
Jun 21, 2023
·
attack.persistence
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
External Disk Drive Or USB Storage Device
calendar
Jun 21, 2023
·
attack.t1091
attack.t1200
attack.lateral_movement
attack.initial_access
·
Share on:
twitter
facebook
linkedin
copy
Local User Creation
calendar
Jun 21, 2023
·
attack.persistence
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
Password Policy Enumerated
calendar
May 18, 2023
·
attack.discovery
attack.t1201
·
Share on:
twitter
facebook
linkedin
copy
Hidden Local User Creation
calendar
May 2, 2023
·
attack.persistence
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Pcap Drivers
calendar
Apr 14, 2023
·
attack.discovery
attack.credential_access
attack.t1040
·
Share on:
twitter
facebook
linkedin
copy
DPAPI Domain Master Key Backup Attempt
calendar
Mar 15, 2023
·
attack.credential_access
attack.t1003.004
·
Share on:
twitter
facebook
linkedin
copy
First Time Seen Remote Named Pipe
calendar
Mar 14, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Important Scheduled Task Deleted/Disabled
calendar
Mar 14, 2023
·
attack.execution
attack.privilege_escalation
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Privileged System Service Operation - SeLoadDriverPrivilege
calendar
Feb 27, 2023
·
attack.defense_evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
T1047 Wmiprvse Wbemcomn DLL Hijack
calendar
Feb 27, 2023
·
attack.execution
attack.t1047
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Transferring Files with Credential Data via Network Shares
calendar
Feb 27, 2023
·
attack.credential_access
attack.t1003.002
attack.t1003.001
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
User Added to Local Administrators
calendar
Feb 27, 2023
·
attack.privilege_escalation
attack.t1078
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
AD Object WriteDAC Access
calendar
Feb 7, 2023
·
attack.defense_evasion
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
DCOM InternetExplorer.Application Iertutil DLL Hijack - Security
calendar
Feb 7, 2023
·
attack.lateral_movement
attack.t1021.002
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
DPAPI Domain Backup Key Extraction
calendar
Feb 7, 2023
·
attack.credential_access
attack.t1003.004
·
Share on:
twitter
facebook
linkedin
copy
Protected Storage Service Access
calendar
Feb 7, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Remote PowerShell Sessions Network Connections (WinRM)
calendar
Feb 7, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
SAM Registry Hive Handle Request
calendar
Feb 7, 2023
·
attack.discovery
attack.t1012
attack.credential_access
attack.t1552.002
·
Share on:
twitter
facebook
linkedin
copy
SCM Database Privileged Operation
calendar
Feb 7, 2023
·
attack.privilege_escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
SysKey Registry Keys Access
calendar
Feb 7, 2023
·
attack.discovery
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Access to ADMIN$ Share
calendar
Feb 1, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations - Security
calendar
Feb 1, 2023
·
attack.execution
attack.privilege_escalation
attack.lateral_movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Hacktool Ruler
calendar
Feb 1, 2023
·
attack.discovery
attack.execution
attack.t1087
attack.t1114
attack.t1059
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Kerberos Manipulation
calendar
Feb 1, 2023
·
attack.credential_access
attack.t1212
·
Share on:
twitter
facebook
linkedin
copy
Malicious Service Installations
calendar
Feb 1, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1003
car.2013-09-005
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1562.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Reconnaissance Activity
calendar
Feb 1, 2023
·
attack.discovery
attack.t1087.002
attack.t1069.002
attack.s0039
·
Share on:
twitter
facebook
linkedin
copy
Security Eventlog Cleared
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1070.001
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Security
calendar
Feb 1, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Access to Sensitive File Extensions
calendar
Dec 27, 2022
·
attack.collection
attack.t1039
·
Share on:
twitter
facebook
linkedin
copy
ADCS Certificate Template Configuration Vulnerability
calendar
Dec 27, 2022
·
attack.privilege_escalation
attack.credential_access
·
Share on:
twitter
facebook
linkedin
copy
ADCS Certificate Template Configuration Vulnerability with Risky EKU
calendar
Dec 27, 2022
·
attack.privilege_escalation
attack.credential_access
·
Share on:
twitter
facebook
linkedin
copy
Security Event Log Cleared
calendar
Dec 27, 2022
·
attack.t1070.001
·
Share on:
twitter
facebook
linkedin
copy
Locked Workstation
calendar
Dec 23, 2022
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Registry
calendar
Dec 20, 2022
·
attack.defense_evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Failed Code Integrity Checks
calendar
Dec 7, 2022
·
attack.defense_evasion
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Scripts Installed as Services - Security
calendar
Nov 30, 2022
·
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Tap Driver Installation - Security
calendar
Nov 30, 2022
·
attack.exfiltration
attack.t1048
·
Share on:
twitter
facebook
linkedin
copy
New or Renamed User Account with '$' in Attribute 'SamAccountName'
calendar
Nov 22, 2022
·
attack.defense_evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
DCERPC SMB Spoolss Named Pipe
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Denied Access To Remote Desktop
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
HybridConnectionManager Service Installation
calendar
Oct 25, 2022
·
attack.persistence
attack.t1554
·
Share on:
twitter
facebook
linkedin
copy
Impacket PsExec Execution
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Persistence and Execution at Scale via GPO Scheduled Task
calendar
Oct 25, 2022
·
attack.persistence
attack.lateral_movement
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Processes Accessing the Microphone and Webcam
calendar
Oct 25, 2022
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
Remote Service Activity via SVCCTL Named Pipe
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.persistence
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Task Creation via ATSVC Named Pipe
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.persistence
car.2013-05-004
car.2015-04-001
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Secure Deletion with SDelete
calendar
Oct 25, 2022
·
attack.impact
attack.defense_evasion
attack.t1070.004
attack.t1027.005
attack.t1485
attack.t1553.002
attack.s0195
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LDAP-Attributes Used
calendar
Oct 25, 2022
·
attack.t1001.003
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PsExec Execution
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Channel Reference Deletion
calendar
Oct 25, 2022
·
attack.defense_evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Unauthorized System Time Modification
calendar
Oct 25, 2022
·
attack.defense_evasion
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
WCE wceaux.dll Access
calendar
Oct 25, 2022
·
attack.credential_access
attack.t1003
attack.s0005
·
Share on:
twitter
facebook
linkedin
copy
Windows Network Access Suspicious desktop.ini Action
calendar
Oct 25, 2022
·
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Addition of Domain Trusts
calendar
Oct 14, 2022
·
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Addition of SID History to Active Directory Object
calendar
Oct 14, 2022
·
attack.persistence
attack.privilege_escalation
attack.t1134.005
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Health Monitoring Agent Registry Keys Access
calendar
Oct 14, 2022
·
attack.discovery
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Health Service Agents Registry Keys Access
calendar
Oct 14, 2022
·
attack.discovery
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Metasploit SMB Authentication
calendar
Oct 14, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Password Change on Directory Service Restore Mode (DSRM) Account
calendar
Oct 14, 2022
·
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Password Dumper Activity on LSASS
calendar
Oct 14, 2022
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Register new Logon Process by Rubeus
calendar
Oct 14, 2022
·
attack.lateral_movement
attack.privilege_escalation
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows ANONYMOUS LOGON Local Account Created
calendar
Oct 14, 2022
·
attack.persistence
attack.t1136.001
attack.t1136.002
·
Share on:
twitter
facebook
linkedin
copy
to-top