open-menu
closeme
Malicious IP Address Sign-In Failure Rate
calendar
Sep 11, 2023
·
attack.t1090
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Malicious IP Address Sign-In Suspicious
calendar
Sep 11, 2023
·
attack.t1090
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Potential Dead Drop Resolvers
calendar
Sep 8, 2023
·
attack.command_and_control
attack.t1102
attack.t1102.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of Manage Engine ServiceDesk
calendar
Sep 7, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Sign-In From Malware Infected IP
calendar
Sep 6, 2023
·
attack.t1090
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
New Port Forwarding Rule Added Via Netsh.EXE
calendar
Sep 1, 2023
·
attack.lateral_movement
attack.defense_evasion
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Abusing IEExec To Download Payloads
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Gzip Archive Decode Via PowerShell
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1132.001
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened (Suspicious Filenames)
calendar
Aug 28, 2023
·
attack.command_and_control
attack.defense_evasion
attack.t1027
attack.t1105
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potential COM Objects Download Cradles Usage - Process Creation
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Potential COM Objects Download Cradles Usage - PS Script
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL File Download Via PowerShell Invoke-WebRequest
calendar
Aug 28, 2023
·
attack.command_and_control
attack.execution
attack.t1059.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Web Download
calendar
Aug 28, 2023
·
attack.command_and_control
attack.execution
attack.t1059.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download from Office Domain
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1105
attack.t1608
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Dropbox API Usage
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious FromBase64String Usage On Gzip Archive - Process Creation
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1132.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious FromBase64String Usage On Gzip Archive - Ps Script
calendar
Aug 28, 2023
·
attack.command_and_control
attack.t1132.001
·
Share on:
twitter
facebook
linkedin
copy
Devil Bait Potential C2 Communication Traffic
calendar
Aug 23, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential In-Memory Download And Compile Of Payloads
calendar
Aug 22, 2023
·
attack.command_and_control
attack.execution
attack.t1059.007
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Lolbas OneDriveStandaloneUpdater.exe Proxy Download
calendar
Aug 17, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Outlook Macro Execution Without Warning Setting Enabled
calendar
Aug 17, 2023
·
attack.persistence
attack.command_and_control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
calendar
Aug 17, 2023
·
attack.persistence
attack.command_and_control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Amazon SSM Agent Hijacking
calendar
Aug 3, 2023
·
attack.command_and_control
attack.persistence
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Potential Amazon SSM Agent Hijacking
calendar
Aug 3, 2023
·
attack.command_and_control
attack.persistence
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Malware User Agent
calendar
Jul 17, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Office Outbound Connections
calendar
Jul 17, 2023
·
attack.defense_evasion
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36884 Exploitation - Share Access
calendar
Jul 17, 2023
·
attack.command_and_control
cve.2023.36884
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36884 Exploitation - URL Marker
calendar
Jul 17, 2023
·
attack.command_and_control
cve.2023.36884
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36884 Exploitation Pattern
calendar
Jul 17, 2023
·
attack.command_and_control
cve.2023.36884
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2303-36884 URL Request Pattern Traffic
calendar
Jul 17, 2023
·
attack.command_and_control
cve.2023.36884
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36884 Exploitation - File Downloads
calendar
Jul 13, 2023
·
attack.command_and_control
cve.2023.36884
·
Share on:
twitter
facebook
linkedin
copy
Wannacry Killswitch Domain
calendar
Jun 26, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
GfxDownloadWrapper.exe Downloads File from Suspicious URL
calendar
Jun 26, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Curl.EXE Download
calendar
Jun 22, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
GALLIUM IOCs
calendar
Jun 20, 2023
·
attack.credential_access
attack.command_and_control
attack.t1212
attack.t1071
attack.g0093
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Goofy Guineapig Backdoor Potential C2 Communication
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Greenbug Espionage Group Indicators
calendar
Jun 20, 2023
·
attack.g0049
attack.execution
attack.t1059.001
attack.command_and_control
attack.t1105
attack.defense_evasion
attack.t1036.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Activity
calendar
Jun 20, 2023
·
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense_evasion
attack.t1112
attack.command_and_control
attack.t1071.004
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - Security
calendar
Jun 20, 2023
·
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense_evasion
attack.t1112
attack.command_and_control
attack.t1071.004
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - System
calendar
Jun 20, 2023
·
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense_evasion
attack.t1112
attack.command_and_control
attack.t1071.004
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Beaconing Activity - DNS
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Beaconing Activity - Proxy
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp ICO C2 File Download
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Operation Triangulation C2 Beaconing Activity - DNS
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Operation Triangulation C2 Beaconing Activity - Proxy
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Child Process Of 3CXDesktopApp
calendar
Jun 20, 2023
·
attack.command_and_control
attack.execution
attack.t1218
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware Potential C2 Communication
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Remote Access Software Domain
calendar
Jun 15, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Download File To Potentially Suspicious Directory Via Wget
calendar
Jun 2, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Wget Creating Files in Tmp Directory
calendar
Jun 2, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non-Browser Network Communication With Telegram API
calendar
May 19, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
APT40 Dropbox Tool User Agent
calendar
May 18, 2023
·
attack.command_and_control
attack.t1071.001
attack.exfiltration
attack.t1567.002
·
Share on:
twitter
facebook
linkedin
copy
Download from Suspicious Dyndns Hosts
calendar
May 18, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1105
attack.t1568
·
Share on:
twitter
facebook
linkedin
copy
Telegram API Access
calendar
May 18, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
attack.t1102.002
·
Share on:
twitter
facebook
linkedin
copy
Cloudflared Tunnel Connections Cleanup
calendar
May 17, 2023
·
attack.command_and_control
attack.t1102
attack.t1090
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Cloudflared Tunnel Execution
calendar
May 17, 2023
·
attack.command_and_control
attack.t1102
attack.t1090
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
BITSAdmin Downloading Malicious Binaries (RedCanary Threat Detection Report)
calendar
May 17, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Certutil Downloading Malicious Binaries (RedCanary Threat Detection Report)
calendar
May 17, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Bitsadmin to Uncommon TLD
calendar
May 17, 2023
·
attack.command_and_control
attack.t1071.001
attack.defense_evasion
attack.persistence
attack.t1197
attack.s0190
·
Share on:
twitter
facebook
linkedin
copy
File Download with Headless Browser
calendar
May 15, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect Temporary Installation Artefact
calendar
May 15, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Possible Raspberry Robin DLL Download Using msiexec (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Network Connection To Notion API
calendar
May 9, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Potential Base64 Encoded User-Agent
calendar
May 9, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Base64 Encoded User-Agent
calendar
May 4, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non-Browser Network Communication With Google API
calendar
May 3, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Typical Malware Back Connect Ports
calendar
May 2, 2023
·
attack.persistence
attack.command_and_control
attack.t1571
·
Share on:
twitter
facebook
linkedin
copy
Mstsc.EXE Execution With Local RDP File
calendar
Apr 30, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Mstsc.EXE Execution With Local RDP File
calendar
Apr 30, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Outbound Network Connection To Public IP Via Winlogon
calendar
Apr 28, 2023
·
attack.defense_evasion
attack.execution
attack.command_and_control
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invoke-WebRequest Execution With DirectIP
calendar
Apr 24, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invoke-WebRequest Execution
calendar
Apr 21, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
DNSCat2 Powershell Implementation Detection Via Process Creation
calendar
Apr 21, 2023
·
attack.command_and_control
attack.t1071
attack.t1071.004
attack.t1001.003
attack.t1041
·
Share on:
twitter
facebook
linkedin
copy
High DNS Requests Rate
calendar
Apr 21, 2023
·
attack.exfiltration
attack.t1048.003
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
High DNS Requests Rate - Firewall
calendar
Apr 21, 2023
·
attack.exfiltration
attack.t1048.003
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
High NULL Records Requests Rate
calendar
Apr 21, 2023
·
attack.exfiltration
attack.t1048.003
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
High TXT Records Requests Rate
calendar
Apr 21, 2023
·
attack.exfiltration
attack.t1048.003
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Possible DNS Rebinding
calendar
Apr 21, 2023
·
attack.command_and_control
attack.t1043
·
Share on:
twitter
facebook
linkedin
copy
Possible DNS Tunneling
calendar
Apr 21, 2023
·
attack.command_and_control
attack.t1071.004
attack.exfiltration
attack.t1048.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Werfault.exe Network Connection Outbound
calendar
Apr 21, 2023
·
attack.command_and_control
attack.t1571
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non-Browser Network Communication With Reddit API
calendar
Apr 19, 2023
·
attack.command_and_control
attack.t1102
·
Share on:
twitter
facebook
linkedin
copy
Connection Initiated Via Certutil.EXE
calendar
Apr 18, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Mesh Agent Service Installation
calendar
Apr 14, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
TacticalRMM Service Installation
calendar
Apr 14, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary File Download Via MSEdge.EXE
calendar
Apr 14, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Silence.EDA Detection
calendar
Apr 11, 2023
·
attack.execution
attack.t1059.001
attack.command_and_control
attack.t1071.004
attack.t1572
attack.impact
attack.t1529
attack.g0091
attack.s0363
·
Share on:
twitter
facebook
linkedin
copy
Import LDAP Data Interchange Format File Via Ldifde.EXE
calendar
Mar 15, 2023
·
attack.command_and_control
attack.defense_evasion
attack.t1218
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Registry Persistence
calendar
Mar 9, 2023
·
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense_evasion
attack.t1112
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Use of UltraViewer Remote Access Software
calendar
Mar 9, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Command Line Execution with Suspicious URL and AppData Strings
calendar
Mar 7, 2023
·
attack.execution
attack.command_and_control
attack.t1059.003
attack.t1059.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Curl Download And Execute Combination
calendar
Mar 7, 2023
·
attack.execution
attack.t1218
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Anydesk Execution From Suspicious Folder
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Execution
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Piped Password Via CLI
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Silent Installation
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - GoToAssist Execution
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - LogMeIn Execution
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - NetSupport Execution
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Backstage Mode Anomaly
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Execution
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Remote File Download via Desktopimgdownldr Utility
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Desktopimgdownldr Command
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious TSCON Start as SYSTEM
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Tor Client/Browser Execution
calendar
Mar 5, 2023
·
attack.command_and_control
attack.t1090.003
·
Share on:
twitter
facebook
linkedin
copy
File Download Using Notepad++ GUP Utility
calendar
Mar 2, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Windows Update Client LOLBIN
calendar
Mar 2, 2023
·
attack.command_and_control
attack.execution
attack.t1105
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential SocGholish Second Stage C2 DNS Query
calendar
Feb 27, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Installer Package Child Process
calendar
Feb 21, 2023
·
attack.t1059
attack.t1059.007
attack.t1071
attack.t1071.001
attack.execution
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
DNS Exfiltration and Tunneling Tools Execution
calendar
Feb 21, 2023
·
attack.exfiltration
attack.t1048.001
attack.command_and_control
attack.t1071.004
attack.t1132.001
·
Share on:
twitter
facebook
linkedin
copy
Finger.exe Suspicious Invocation
calendar
Feb 21, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
MsiExec Web Install
calendar
Feb 21, 2023
·
attack.defense_evasion
attack.t1218.007
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
PowerShell DownloadFile
calendar
Feb 21, 2023
·
attack.execution
attack.t1059.001
attack.command_and_control
attack.t1104
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
PUA - 3Proxy Execution
calendar
Feb 21, 2023
·
attack.command_and_control
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
PUA - Ngrok Execution
calendar
Feb 21, 2023
·
attack.command_and_control
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Binary Writes Via AnyDesk
calendar
Feb 20, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SILENTTRINITY Stager DLL Load
calendar
Feb 17, 2023
·
attack.command_and_control
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SILENTTRINITY Stager Execution
calendar
Feb 17, 2023
·
attack.command_and_control
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
Inveigh Execution Artefacts
calendar
Feb 17, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
RDP Port Forwarding Rule Added Via Netsh.EXE
calendar
Feb 16, 2023
·
attack.lateral_movement
attack.defense_evasion
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpChisel Execution
calendar
Feb 13, 2023
·
attack.command_and_control
attack.t1090.001
·
Share on:
twitter
facebook
linkedin
copy
PUA - Chisel Tunneling Tool Execution
calendar
Feb 13, 2023
·
attack.command_and_control
attack.t1090.001
·
Share on:
twitter
facebook
linkedin
copy
PUA - Nimgrab Execution
calendar
Feb 13, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
PUA - Netcat Suspicious Execution
calendar
Feb 8, 2023
·
attack.command_and_control
attack.t1095
·
Share on:
twitter
facebook
linkedin
copy
PUA- IOX Tunneling Tool Execution
calendar
Feb 8, 2023
·
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
New Outlook Macro Created
calendar
Feb 8, 2023
·
attack.persistence
attack.command_and_control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outlook Macro Created
calendar
Feb 8, 2023
·
attack.persistence
attack.command_and_control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
PUA - NPS Tunneling Tool Execution
calendar
Feb 6, 2023
·
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Potential RDP Tunneling Via SSH Plink
calendar
Feb 5, 2023
·
attack.command_and_control
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Plink Port Forwarding
calendar
Feb 5, 2023
·
attack.command_and_control
attack.t1572
attack.lateral_movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Htran/NATBypass Execution
calendar
Feb 4, 2023
·
attack.command_and_control
attack.t1090
attack.s0040
·
Share on:
twitter
facebook
linkedin
copy
PUA - Fast Reverse Proxy (FRP) Execution
calendar
Feb 4, 2023
·
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Port Forwarding Attempt Via SSH
calendar
Feb 3, 2023
·
attack.command_and_control
attack.lateral_movement
attack.t1572
attack.t1021.001
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Renamed Remote Utilities RAT (RURAT) Execution
calendar
Feb 3, 2023
·
attack.defense_evasion
attack.collection
attack.command_and_control
attack.discovery
attack.s0592
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Exploitation Framework Detection
calendar
Feb 1, 2023
·
attack.execution
attack.t1203
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
APT User Agent
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
BabyShark Agent Pattern
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Bitsadmin to Uncommon IP Server Address
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
attack.defense_evasion
attack.persistence
attack.t1197
attack.s0190
·
Share on:
twitter
facebook
linkedin
copy
Chafer Malware URL Pattern
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Cobalt Strike DNS Beaconing
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Malformed UAs in Malleable Profiles
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Communication To Ngrok Tunneling Service
calendar
Feb 1, 2023
·
attack.exfiltration
attack.command_and_control
attack.t1567
attack.t1568.002
attack.t1572
attack.t1090
attack.t1102
attack.s0508
·
Share on:
twitter
facebook
linkedin
copy
Communication To Ngrok Tunneling Service - Linux
calendar
Feb 1, 2023
·
attack.exfiltration
attack.command_and_control
attack.t1567
attack.t1568.002
attack.t1572
attack.t1090
attack.t1102
attack.s0508
·
Share on:
twitter
facebook
linkedin
copy
Crypto Miner User Agent
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Curl Usage on Linux
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Empire UserAgent URI Combo
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Empty User Agent
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Equation Group C2 Communication
calendar
Feb 1, 2023
·
attack.command_and_control
attack.g0020
attack.t1041
·
Share on:
twitter
facebook
linkedin
copy
Exploit Framework User Agent
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Ngrok Usage with Remote Desktop Service
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Potential Download/Upload Activity Using Type Command
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Potential RDP Tunneling Via SSH
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1572
·
Share on:
twitter
facebook
linkedin
copy
PwnDrp Access
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
attack.t1102.001
attack.t1102.003
·
Share on:
twitter
facebook
linkedin
copy
Query Tor Onion Address - DNS Client
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1090.003
·
Share on:
twitter
facebook
linkedin
copy
Raw Paste Service Access
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
attack.t1102.001
attack.t1102.003
attack.defense_evasion
·
Share on:
twitter
facebook
linkedin
copy
RDP to HTTP or HTTPS Target Ports
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1572
attack.lateral_movement
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious C2 Activities
calendar
Feb 1, 2023
·
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Certreq Command to Download
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Cobalt Strike DNS Beaconing - DNS Client
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Cobalt Strike DNS Beaconing - Sysmon
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Curl Change User Agents - Linux
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DNS Query with B64 Encoded String
calendar
Feb 1, 2023
·
attack.exfiltration
attack.t1048.003
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download via CertOC.exe
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Program Location with Network Connections
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious TCP Tunnel Via PowerShell Script
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
Suspicious TeamViewer Domain Access
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious User Agent
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Remote Session
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Telegram Bot API Request
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1102.002
·
Share on:
twitter
facebook
linkedin
copy
Turla ComRAT
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
attack.g0010
·
Share on:
twitter
facebook
linkedin
copy
Windows PowerShell User Agent
calendar
Feb 1, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Windows WebDAV User Agent
calendar
Feb 1, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Malleable (OCSP) Profile
calendar
Jan 31, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Malleable Amazon Browsing Traffic Profile
calendar
Jan 31, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Malleable OneDrive Browsing Traffic Profile
calendar
Jan 31, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Ursnif Malware C2 URL Pattern
calendar
Jan 31, 2023
·
attack.initial_access
attack.t1566.001
attack.execution
attack.t1204.002
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
Ursnif Malware Download URL Pattern
calendar
Jan 31, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
DNS Query From Process with Double File Extension
calendar
Jan 30, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1218
attack.t1218.009
attack.t1071
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Download by Process with Double File Extension
calendar
Jan 30, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1218
attack.t1218.009
attack.t1071
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
File Creation by Process with Double File Extension
calendar
Jan 30, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1218
attack.t1218.009
attack.t1071
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Network Connection From Process with Double File Extension
calendar
Jan 30, 2023
·
attack.defense_evasion
attack.command_and_control
attack.t1218
attack.t1218.009
attack.t1071
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Anydesk Temporary Artefact
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Download a File with IMEWDBLD.exe
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
GoToAssist Temporary Installation Artefact
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Installation of TeamViewer Desktop
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SSL Connection
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1573
·
Share on:
twitter
facebook
linkedin
copy
Testing Usage of Uncommonly Used Port
calendar
Jan 27, 2023
·
attack.command_and_control
attack.t1571
·
Share on:
twitter
facebook
linkedin
copy
DNS Query Tor Onion Address - Sysmon
calendar
Jan 17, 2023
·
attack.command_and_control
attack.t1090.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ADSI-Cache Usage By Unknown Tool
calendar
Jan 17, 2023
·
attack.t1001.003
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Registry Key Added: LanmanServer Parameters
calendar
Jan 12, 2023
·
attack.command_and_control
attack.defense_evasion
attack.t1105
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Registry Key Set (MaxMpxCt)
calendar
Jan 12, 2023
·
attack.command_and_control
attack.defense_evasion
attack.t1105
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
AppX Package Installation Attempts Via AppInstaller
calendar
Jan 12, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
AnyDesk Network
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1133
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Operator Bring Your Own Tools
calendar
Jan 8, 2023
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
SplashTop Network
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1133
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
SplashTop Process
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1133
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Cisco Stage Data
calendar
Jan 4, 2023
·
attack.collection
attack.lateral_movement
attack.command_and_control
attack.exfiltration
attack.t1074
attack.t1105
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
Change User Agents with WebRequest
calendar
Jan 4, 2023
·
attack.command_and_control
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
GALLIUM Artefacts - Builtin
calendar
Jan 2, 2023
·
attack.credential_access
attack.command_and_control
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
Netcat The Powershell Version
calendar
Dec 27, 2022
·
attack.command_and_control
attack.t1095
·
Share on:
twitter
facebook
linkedin
copy
RDP Over Reverse SSH Tunnel
calendar
Dec 8, 2022
·
attack.command_and_control
attack.t1572
attack.lateral_movement
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Registry Modification of MaxMpxCt Parameters
calendar
Dec 6, 2022
·
attack.command_and_control
attack.defense_evasion
attack.t1105
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DNS Z Flag Bit Set
calendar
Nov 29, 2022
·
attack.t1095
attack.t1571
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Executable Deployment from Remote Share
calendar
Nov 29, 2022
·
attack.lateral_movement
attack.command_and_control
attack.t1105
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
BITSAdmin Downloading Malicious Binaries
calendar
Nov 9, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
CertUtil Downloading Malicious Binaries
calendar
Nov 9, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Exfiltration and Tunneling Tools Execution
calendar
Oct 28, 2022
·
attack.exfiltration
attack.command_and_control
attack.t1041
attack.t1572
attack.t1071.001
·
Share on:
twitter
facebook
linkedin
copy
PrintBrm ZIP Creation of Extraction
calendar
Oct 28, 2022
·
attack.command_and_control
attack.t1105
attack.defense_evasion
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Replace.exe Usage
calendar
Oct 28, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Diantz Download and Compress Into a CAB File
calendar
Oct 28, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Extrac32 Execution
calendar
Oct 28, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Use of UltraVNC Remote Access Software
calendar
Oct 28, 2022
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Download Activity
calendar
Oct 28, 2022
·
attack.defense_evasion
attack.t1218
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Potential WizardUpdate Malware Infection
calendar
Oct 28, 2022
·
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Notepad Making Network Connection
calendar
Oct 26, 2022
·
attack.command_and_control
attack.execution
attack.defense_evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Script Initiated Connection
calendar
Oct 26, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Script Initiated Connection to Non-Local Network
calendar
Oct 26, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Hijack Legit RDP Session to Move Laterally
calendar
Oct 26, 2022
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote Desktop Connection to Non-Domain Host
calendar
Oct 25, 2022
·
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LDAP-Attributes Used
calendar
Oct 25, 2022
·
attack.t1001.003
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Default Cobalt Strike Certificate
calendar
Oct 25, 2022
·
attack.command_and_control
attack.s0154
·
Share on:
twitter
facebook
linkedin
copy
DNS TXT Answer with Possible Execution Strings
calendar
Oct 25, 2022
·
attack.command_and_control
attack.t1071.004
·
Share on:
twitter
facebook
linkedin
copy
Executable from Webdav
calendar
Oct 25, 2022
·
attack.command_and_control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
New Kind of Network (NKN) Detection
calendar
Oct 25, 2022
·
attack.command_and_control
·
Share on:
twitter
facebook
linkedin
copy
Remote File Copy
calendar
Oct 25, 2022
·
attack.command_and_control
attack.lateral_movement
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Activity from Suspicious IP Addresses
calendar
Oct 25, 2022
·
attack.command_and_control
attack.t1573
·
Share on:
twitter
facebook
linkedin
copy
RDP over Reverse SSH Tunnel WFP
calendar
Oct 14, 2022
·
attack.defense_evasion
attack.command_and_control
attack.lateral_movement
attack.t1090.001
attack.t1090.002
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Activity from Anonymous IP Addresses
calendar
Oct 9, 2022
·
attack.command_and_control
attack.t1573
·
Share on:
twitter
facebook
linkedin
copy
Activity from Infrequent Country
calendar
Oct 9, 2022
·
attack.command_and_control
attack.t1573
·
Share on:
twitter
facebook
linkedin
copy
PortProxy Registry Key
calendar
Oct 9, 2022
·
attack.lateral_movement
attack.defense_evasion
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
to-top