open-menu
closeme
7Zip Compressing Dump Files
calendar
Sep 7, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Copy from Admin Share
calendar
Sep 7, 2023
·
attack.lateral_movement
attack.collection
attack.exfiltration
attack.t1039
attack.t1048
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Winrar Compressing Dump Files
calendar
Sep 7, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Winrar Execution in Non-Standard Folder
calendar
Sep 7, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
CredUI.DLL Loaded By Uncommon Process
calendar
Jul 31, 2023
·
attack.credential_access
attack.collection
attack.t1056.002
·
Share on:
twitter
facebook
linkedin
copy
Psr.exe Capture Screenshots
calendar
Jun 26, 2023
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Conti NTDS Exfiltration Command
calendar
Jun 20, 2023
·
attack.collection
attack.t1560
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Conti Ransomware Database Dumping Activity Via SQLCmd
calendar
Jun 20, 2023
·
attack.collection
attack.t1005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Get Clipboard
calendar
May 15, 2023
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
calendar
May 15, 2023
·
attack.collection
attack.t1074.001
·
Share on:
twitter
facebook
linkedin
copy
Veeam Backup Database Suspicious Query
calendar
May 9, 2023
·
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
ADFS Database Named Pipe Connection
calendar
Apr 20, 2023
·
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
Audio Capture via PowerShell
calendar
Apr 11, 2023
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
Exchange PowerShell Snap-Ins Usage
calendar
Mar 24, 2023
·
attack.execution
attack.t1059.001
attack.collection
attack.t1114
·
Share on:
twitter
facebook
linkedin
copy
Compress Data and Lock With Password for Exfiltration With 7-ZIP
calendar
Mar 13, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Password Protected Compressed File Extraction Via 7Zip
calendar
Mar 11, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Audio Capture via SoundRecorder
calendar
Mar 5, 2023
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
Compress Data and Lock With Password for Exfiltration With WINZIP
calendar
Mar 2, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Rar Usage with Password and Compression Level
calendar
Mar 2, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Zip A Folder With PowerShell For Staging In Temp
calendar
Mar 2, 2023
·
attack.collection
attack.t1074.001
·
Share on:
twitter
facebook
linkedin
copy
System Drawing DLL Load
calendar
Feb 23, 2023
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Data Copied To Clipboard Via Clip.EXE
calendar
Feb 22, 2023
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Automated Collection Command Prompt
calendar
Feb 21, 2023
·
attack.collection
attack.t1119
attack.credential_access
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
PUA - Mouse Lock Execution
calendar
Feb 21, 2023
·
attack.credential_access
attack.collection
attack.t1056.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Manipulation Of Default Accounts Via Net.EXE
calendar
Feb 21, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
VeeamBackup Database Credentials Dump Via Sqlcmd.EXE
calendar
Feb 13, 2023
·
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Get-Clipboard Cmdlet Via CLI
calendar
Feb 7, 2023
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Github Self Hosted Runner Changes Detected
calendar
Feb 6, 2023
·
attack.impact
attack.discovery
attack.collection
attack.defense_evasion
attack.persistence
attack.privilege_escalation
attack.initial_access
attack.t1526
attack.t1213.003
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Files Added To An Archive Using Rar.EXE
calendar
Feb 6, 2023
·
attack.collection
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Renamed Remote Utilities RAT (RURAT) Execution
calendar
Feb 3, 2023
·
attack.defense_evasion
attack.collection
attack.command_and_control
attack.discovery
attack.s0592
·
Share on:
twitter
facebook
linkedin
copy
iOS Implant URL Pattern
calendar
Feb 1, 2023
·
attack.execution
attack.t1203
attack.collection
attack.t1005
attack.t1119
attack.credential_access
attack.t1528
attack.t1552.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Keylogger Activity
calendar
Feb 1, 2023
·
attack.collection
attack.credential_access
attack.t1056.001
·
Share on:
twitter
facebook
linkedin
copy
WinDivert Driver Load
calendar
Feb 1, 2023
·
attack.collection
attack.defense_evasion
attack.t1599.001
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Data Collection Via OSAScript
calendar
Jan 31, 2023
·
attack.collection
attack.execution
attack.t1115
attack.t1059.002
·
Share on:
twitter
facebook
linkedin
copy
Github Delete Action Invoked
calendar
Jan 30, 2023
·
attack.impact
attack.collection
attack.t1213.003
·
Share on:
twitter
facebook
linkedin
copy
Github Outside Collaborator Detected
calendar
Jan 30, 2023
·
attack.persistence
attack.collection
attack.t1098.001
attack.t1098.003
attack.t1213.003
·
Share on:
twitter
facebook
linkedin
copy
Cisco BGP Authentication Failures
calendar
Jan 23, 2023
·
attack.initial_access
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.credential_access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Huawei BGP Authentication Failures
calendar
Jan 23, 2023
·
attack.initial_access
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.credential_access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Juniper BGP Missing MD5
calendar
Jan 23, 2023
·
attack.initial_access
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.credential_access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
SQLite Firefox Profile Data DB Access
calendar
Jan 20, 2023
·
attack.credential_access
attack.t1539
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
SQLite Chromium Profile Data DB Access
calendar
Jan 20, 2023
·
attack.credential_access
attack.t1539
attack.t1555.003
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
Recon Information for Export with Command Prompt
calendar
Jan 19, 2023
·
attack.collection
attack.t1119
·
Share on:
twitter
facebook
linkedin
copy
Cisco LDP Authentication Failures
calendar
Jan 12, 2023
·
attack.initial_access
attack.persistence
attack.privilege_escalation
attack.defense_evasion
attack.credential_access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Audio Capture
calendar
Jan 10, 2023
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection of Image Data with Xclip Tool
calendar
Jan 10, 2023
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection with Xclip Tool - Auditd
calendar
Jan 10, 2023
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
Screen Capture with Import Tool
calendar
Jan 10, 2023
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Screen Capture with Xwd
calendar
Jan 10, 2023
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Cisco Collect Data
calendar
Jan 4, 2023
·
attack.discovery
attack.credential_access
attack.collection
attack.t1087.001
attack.t1552.001
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
Cisco Stage Data
calendar
Jan 4, 2023
·
attack.collection
attack.lateral_movement
attack.command_and_control
attack.exfiltration
attack.t1074
attack.t1105
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Automated Collection Command PowerShell
calendar
Jan 4, 2023
·
attack.collection
attack.t1119
·
Share on:
twitter
facebook
linkedin
copy
Powershell Keylogging
calendar
Jan 4, 2023
·
attack.collection
attack.t1056.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Local Email Collection
calendar
Jan 4, 2023
·
attack.collection
attack.t1114.001
·
Share on:
twitter
facebook
linkedin
copy
Recon Information for Export with PowerShell
calendar
Jan 4, 2023
·
attack.collection
attack.t1119
·
Share on:
twitter
facebook
linkedin
copy
Windows Screen Capture with CopyFromScreen
calendar
Jan 4, 2023
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Zip A Folder With PowerShell For Staging In Temp - PowerShell Script
calendar
Jan 4, 2023
·
attack.collection
attack.t1074.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Access to Sensitive File Extensions
calendar
Dec 27, 2022
·
attack.collection
attack.t1039
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Access to Sensitive File Extensions - Zeek
calendar
Dec 27, 2022
·
attack.collection
·
Share on:
twitter
facebook
linkedin
copy
Linux Capabilities Discovery
calendar
Dec 27, 2022
·
attack.collection
attack.privilege_escalation
attack.t1123
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Zip A Folder With PowerShell For Staging In Temp - PowerShell
calendar
Dec 2, 2022
·
attack.collection
attack.t1074.001
·
Share on:
twitter
facebook
linkedin
copy
PST Export Alert Using eDiscovery Alert
calendar
Nov 18, 2022
·
attack.collection
attack.t1114
·
Share on:
twitter
facebook
linkedin
copy
PST Export Alert Using New-ComplianceSearchAction
calendar
Nov 18, 2022
·
attack.collection
attack.t1114
·
Share on:
twitter
facebook
linkedin
copy
Esentutl Steals Browser Information
calendar
Oct 31, 2022
·
attack.collection
attack.t1005
·
Share on:
twitter
facebook
linkedin
copy
Processes Accessing the Microphone and Webcam
calendar
Oct 25, 2022
·
attack.collection
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
Screen Capture - macOS
calendar
Oct 25, 2022
·
attack.collection
attack.t1113
·
Share on:
twitter
facebook
linkedin
copy
Clipboard Collection with Xclip Tool
calendar
Oct 25, 2022
·
attack.collection
attack.t1115
·
Share on:
twitter
facebook
linkedin
copy
AWS EC2 VM Export Failure
calendar
Oct 25, 2022
·
attack.collection
attack.t1005
attack.exfiltration
attack.t1537
·
Share on:
twitter
facebook
linkedin
copy
Google Full Network Traffic Packet Capture
calendar
Oct 9, 2022
·
attack.collection
attack.t1074
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Camera and Microphone Access
calendar
Oct 9, 2022
·
attack.collection
attack.t1125
attack.t1123
·
Share on:
twitter
facebook
linkedin
copy
to-top