open-menu
closeme
SCR File Write Event
calendar
Sep 18, 2023
·
attack.defense_evasion
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Memory Dump Files
calendar
Sep 13, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
ISO or Image Mount Indicator in Recent Files
calendar
Aug 28, 2023
·
attack.initial_access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Interactive PowerShell as SYSTEM
calendar
Aug 28, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Binaries Write Suspicious Extensions
calendar
Aug 28, 2023
·
attack.defense_evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Windows Shell/Scripting Application File Write to Suspicious Folder
calendar
Aug 28, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
WScript or CScript Dropper - File
calendar
Aug 28, 2023
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Assembly DLL Creation Via AspNetCompiler
calendar
Aug 18, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
calendar
Aug 15, 2023
·
attack.defense_evasion
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
RemCom Service File Creation
calendar
Aug 10, 2023
·
attack.execution
attack.t1569.002
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
Cred Dump Tools Dropped Files
calendar
Aug 7, 2023
·
attack.credential_access
attack.t1003.001
attack.t1003.002
attack.t1003.003
attack.t1003.004
attack.t1003.005
·
Share on:
twitter
facebook
linkedin
copy
CSExec Service File Creation
calendar
Aug 7, 2023
·
attack.execution
attack.t1569.002
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
PsExec Service File Creation
calendar
Aug 7, 2023
·
attack.execution
attack.t1569.002
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
New Shim Database Created in the Default Directory
calendar
Aug 1, 2023
·
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation Activity From Fake Recycle.Bin Folder
calendar
Jul 24, 2023
·
attack.persistence
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Windows Terminal Profile Settings Modification By Uncommon Process
calendar
Jul 24, 2023
·
attack.persistence
attack.t1547.015
·
Share on:
twitter
facebook
linkedin
copy
EVTX Created In Uncommon Location
calendar
Jul 13, 2023
·
attack.defense_evasion
attack.t1562.002
·
Share on:
twitter
facebook
linkedin
copy
Typical HiveNightmare SAM File Export
calendar
Jul 13, 2023
·
attack.credential_access
attack.t1552.001
cve.2021.36934
·
Share on:
twitter
facebook
linkedin
copy
File With Uncommon Extension Created By An Office Application
calendar
Jul 13, 2023
·
attack.t1204.002
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Archive
calendar
Jul 13, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Executable
calendar
Jul 13, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Script
calendar
Jul 13, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Microsoft Office Startup Folder
calendar
Jul 13, 2023
·
attack.persistence
attack.t1137
·
Share on:
twitter
facebook
linkedin
copy
Uncommon File Created In Office Startup Folder
calendar
Jul 13, 2023
·
attack.resource_development
attack.t1587.001
·
Share on:
twitter
facebook
linkedin
copy
ISO File Created Within Temp Folders
calendar
Jun 22, 2023
·
attack.initial_access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Double Extension Files
calendar
Jun 21, 2023
·
attack.defense_evasion
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
PSScriptPolicyTest Creation By Uncommon Process
calendar
Jun 1, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation
calendar
May 17, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation By Uncommon Process
calendar
May 17, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Kernel Memory Dump File Created
calendar
May 17, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Dumpert Process Dumper Default File
calendar
May 15, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Or Script Dropper Via PowerShell
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Attempt Via ErrorHandler.Cmd
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote Credential Dumping Activity
calendar
May 15, 2023
·
attack.credential_access
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious PowerShell Module File Created
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Module File Created
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Module File Created By Non-PowerShell Process
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script Dropped Via PowerShell.EXE
calendar
May 15, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PSEXEC Remote Execution File Artefact
calendar
May 15, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.execution
attack.persistence
attack.t1136.002
attack.t1543.003
attack.t1570
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
Rclone Config File Creation
calendar
May 15, 2023
·
attack.exfiltration
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect Temporary Installation Artefact
calendar
May 15, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation In Uncommon AppData Folder
calendar
May 15, 2023
·
attack.defense_evasion
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LNK Double Extension File
calendar
May 15, 2023
·
attack.defense_evasion
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
WinSxS Executable File Creation By Non-System Process
calendar
May 12, 2023
·
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
NTDS.DIT Creation By Uncommon Parent Process
calendar
May 9, 2023
·
attack.credential_access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Homoglyph Attack Using Lookalike Characters in Filename
calendar
May 8, 2023
·
attack.defense_evasion
attack.t1036
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Process Explorer Driver Creation By Non-Sysinternals Binary
calendar
May 5, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Process Monitor Driver Creation By Non-Sysinternals Binary
calendar
May 5, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
NTDS Exfiltration Filename Patterns
calendar
May 5, 2023
·
attack.credential_access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
NTDS.DIT Created
calendar
May 5, 2023
·
attack.credential_access
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
NTDS.DIT Creation By Uncommon Process
calendar
May 5, 2023
·
attack.credential_access
attack.t1003.002
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DotNET CLR Usage Log Artifact
calendar
May 5, 2023
·
attack.defense_evasion
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created In PerfLogs
calendar
May 5, 2023
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
VHD Image Download Via Browser
calendar
May 5, 2023
·
attack.resource_development
attack.t1587.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious PowerShell Scripts - FileCreation
calendar
Apr 21, 2023
·
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
RDP File Creation From Suspicious Application
calendar
Apr 19, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Office Macro File Download
calendar
Apr 18, 2023
·
attack.initial_access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
BloodHound Collection Files
calendar
Apr 11, 2023
·
attack.discovery
attack.t1087.001
attack.t1087.002
attack.t1482
attack.t1069.001
attack.t1069.002
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Files With System Process Name In Unsuspected Locations
calendar
Mar 23, 2023
·
attack.defense_evasion
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Wmiexec Default Output File
calendar
Mar 9, 2023
·
attack.lateral_movement
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created Via OneNote Application
calendar
Mar 1, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Office Macro File Creation
calendar
Feb 24, 2023
·
attack.initial_access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Office Macro File Creation From Suspicious Process
calendar
Feb 24, 2023
·
attack.initial_access
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
File Creation In Suspicious Directory By Msdt.EXE
calendar
Feb 23, 2023
·
attack.persistence
attack.t1547.001
cve.2022.30190
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Microsoft Office Add-In
calendar
Feb 23, 2023
·
attack.persistence
attack.t1137.006
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Notepad++ Plugins
calendar
Feb 23, 2023
·
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Form
calendar
Feb 23, 2023
·
attack.persistence
attack.t1137.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Startup Shortcut Persistence Via PowerShell.EXE
calendar
Feb 23, 2023
·
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Binary Writes Via AnyDesk
calendar
Feb 20, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Dynamic CSharp Compile Artefact
calendar
Feb 17, 2023
·
attack.defense_evasion
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Inveigh Execution Artefacts
calendar
Feb 17, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Mimikatz Kirbi File Creation
calendar
Feb 17, 2023
·
attack.credential_access
attack.t1558
·
Share on:
twitter
facebook
linkedin
copy
Powerup Write Hijack DLL
calendar
Feb 17, 2023
·
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
QuarksPwDump Dump File
calendar
Feb 17, 2023
·
attack.credential_access
attack.t1003.002
·
Share on:
twitter
facebook
linkedin
copy
SafetyKatz Default Dump Filename
calendar
Feb 17, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Non-Existent System DLL
calendar
Feb 15, 2023
·
attack.defense_evasion
attack.persistence
attack.privilege_escalation
attack.t1574.001
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
OneNote Attachment File Dropped In Suspicious Location
calendar
Feb 9, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
GatherNetworkInfo.VBS Reconnaissance Script Output
calendar
Feb 9, 2023
·
attack.discovery
·
Share on:
twitter
facebook
linkedin
copy
New Outlook Macro Created
calendar
Feb 8, 2023
·
attack.persistence
attack.command_and_control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Publisher Attachment File Dropped In Suspicious Location
calendar
Feb 8, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outlook Macro Created
calendar
Feb 8, 2023
·
attack.persistence
attack.command_and_control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Startup Folder File Write
calendar
Feb 7, 2023
·
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PFX File Creation
calendar
Feb 7, 2023
·
attack.credential_access
attack.t1552.004
·
Share on:
twitter
facebook
linkedin
copy
Wmiprvse Wbemcomn DLL Hijack - File
calendar
Feb 7, 2023
·
attack.execution
attack.t1047
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Adwind RAT / JRAT File Artifact
calendar
Feb 1, 2023
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
CrackMapExec File Creation Patterns
calendar
Feb 1, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-1675 Print Spooler Exploitation Filename Pattern
calendar
Feb 1, 2023
·
attack.execution
attack.privilege_escalation
attack.resource_development
attack.t1587
cve.2021.1675
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-44077 POC Default Dropped File
calendar
Feb 1, 2023
·
attack.execution
cve.2021.44077
·
Share on:
twitter
facebook
linkedin
copy
CVE-2022-24527 Microsoft Connected Cache LPE
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1059.001
cve.2022.24527
·
Share on:
twitter
facebook
linkedin
copy
Drop Binaries Into Spool Drivers Color Folder
calendar
Feb 1, 2023
·
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
NPPSpy Hacktool Usage
calendar
Feb 1, 2023
·
attack.credential_access
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation Attempt Via .Exe.Local Technique
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.persistence
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential SAM Database Dump
calendar
Feb 1, 2023
·
attack.credential_access
attack.t1003.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ASPX File Drop by Exchange
calendar
Feb 1, 2023
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Desktopimgdownldr Target File
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Drop by Exchange
calendar
Feb 1, 2023
·
attack.persistence
attack.t1190
attack.initial_access
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious MSExchangeMailboxReplication ASPX Write
calendar
Feb 1, 2023
·
attack.initial_access
attack.t1190
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Write to System32 Tasks
calendar
Feb 1, 2023
·
attack.persistence
attack.execution
attack.t1053
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Startup Folder Persistence
calendar
Feb 1, 2023
·
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Remote Session
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - File
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using .NET Code Profiler on MMC
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Consent and Comctl32 - File
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using EventVwr
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IDiagnostic Profile - File
calendar
Feb 1, 2023
·
attack.execution
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IEInstal - File
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using MSConfig Token Modification - File
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using NTFS Reparse Point - File
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Windows Media Player - File
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UEFI Persistence Via Wpbbin - FileCreation
calendar
Feb 1, 2023
·
attack.persistence
attack.defense_evasion
attack.t1542.001
·
Share on:
twitter
facebook
linkedin
copy
VsCode Powershell Profile Modification
calendar
Feb 1, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1546.013
·
Share on:
twitter
facebook
linkedin
copy
WerFault LSASS Process Memory Dump
calendar
Feb 1, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Anydesk Temporary Artefact
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Creation Exe for Service with Unquoted Path
calendar
Jan 27, 2023
·
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
GoToAssist Temporary Installation Artefact
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Installation of TeamViewer Desktop
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Creation TXT File in User Desktop
calendar
Jan 27, 2023
·
attack.impact
attack.t1486
·
Share on:
twitter
facebook
linkedin
copy
Creation of an Executable by an Executable
calendar
Jan 26, 2023
·
attack.resource_development
attack.t1587.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ADSI-Cache Usage By Unknown Tool
calendar
Jan 17, 2023
·
attack.t1001.003
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Potential RipZip Attack on Startup Folder
calendar
Jan 6, 2023
·
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Potential Winnti Dropper Activity
calendar
Jan 6, 2023
·
attack.defense_evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Creation with Colorcpl
calendar
Jan 6, 2023
·
attack.defense_evasion
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Unattend.xml File Access
calendar
Dec 27, 2022
·
attack.credential_access
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Profile Modification
calendar
Dec 19, 2022
·
attack.persistence
attack.privilege_escalation
attack.t1546.013
·
Share on:
twitter
facebook
linkedin
copy
Potential DCOM InternetExplorer.Application DLL Hijack
calendar
Dec 18, 2022
·
attack.lateral_movement
attack.t1021.002
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
LSASS Process Dump Artefact In CrashDumps Folder
calendar
Dec 16, 2022
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Advanced IP Scanner - File Event
calendar
Nov 30, 2022
·
attack.discovery
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PROCEXP152.sys File Created In TMP
calendar
Nov 22, 2022
·
attack.t1562.001
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Screensaver Binary File Creation
calendar
Nov 8, 2022
·
attack.persistence
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Initial Access via DLL Search Order Hijacking
calendar
Oct 28, 2022
·
attack.t1566
attack.t1566.001
attack.initial_access
attack.t1574
attack.t1574.001
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Created Files by Microsoft Sync Center
calendar
Oct 26, 2022
·
attack.t1055
attack.t1218
attack.execution
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Creation of a Diagcab
calendar
Oct 26, 2022
·
attack.resource_development
·
Share on:
twitter
facebook
linkedin
copy
Creation of an WerFault.exe in Unusual Folder
calendar
Oct 26, 2022
·
attack.persistence
attack.defense_evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-26858 Exchange Exploitation
calendar
Oct 26, 2022
·
attack.t1203
attack.execution
cve.2021.26858
·
Share on:
twitter
facebook
linkedin
copy
DLL Search Order Hijackig Via Additional Space in Path
calendar
Oct 26, 2022
·
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Hijack Legit RDP Session to Move Laterally
calendar
Oct 26, 2022
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL File Dropped in the Teams or OneDrive Folder
calendar
Oct 26, 2022
·
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.t1574.002
·
Share on:
twitter
facebook
linkedin
copy
Octopus Scanner Malware
calendar
Oct 26, 2022
·
attack.t1195
attack.t1195.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious desktop.ini Action
calendar
Oct 26, 2022
·
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Executable File Creation
calendar
Oct 26, 2022
·
attack.defense_evasion
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Event With Teams Objects
calendar
Oct 26, 2022
·
attack.credential_access
attack.t1528
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Files in Default GPO Folder
calendar
Oct 26, 2022
·
attack.t1036.005
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get-Variable.exe Creation
calendar
Oct 26, 2022
·
attack.persistence
attack.t1546
attack.defense_evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Windows Webshell Creation
calendar
Oct 26, 2022
·
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Script Event Consumer File Write
calendar
Oct 26, 2022
·
attack.t1546.003
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Writing Local Admin Share
calendar
Oct 26, 2022
·
attack.lateral_movement
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
calendar
Oct 13, 2022
·
attack.credential_access
attack.t1566
attack.t1203
cve.2021.33771
cve.2021.31979
·
Share on:
twitter
facebook
linkedin
copy
PCRE.NET Package Temp Files
calendar
Oct 13, 2022
·
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
to-top