open-menu
closeme
A Rule Has Been Deleted From The Windows Firewall Exception List
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Activate Suppression of Windows Security Center Notifications
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Active Directory Certificate Services Denied Certificate Enrollment Request
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
AD Object WriteDAC Access
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Add DisallowRun Execution to Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Add or Remove Computer from DC
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1207
·
Share on:
twitter
facebook
linkedin
copy
Add SafeBoot Keys Via Reg Utility
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
All Rules Have Been Deleted From The Windows Firewall Configuration
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Allow RDP Remote Assistance Feature
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
AMSI Bypass Pattern Assembly GetType
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
AMSI Disabled via Registry Modification
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Amsi.DLL Loaded Via LOLBIN Process
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Filter Driver Disallowed On Dev Drive - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ASLR Disabled Via Sysctl or Direct Syscall - Linux
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1685
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
Audit Policy Tampering Via Auditpol
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Audit Policy Tampering Via NT Resource Kit Auditpol
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Audit Rules Deleted Via Auditctl
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.004
·
Share on:
twitter
facebook
linkedin
copy
Auditing Configuration Changes on Linux Host
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AWS CloudTrail Important Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.002
·
Share on:
twitter
facebook
linkedin
copy
AWS Config Disabling Channel/Recorder
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.002
·
Share on:
twitter
facebook
linkedin
copy
AWS GuardDuty Detector Deleted Or Updated
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.t1685.002
·
Share on:
twitter
facebook
linkedin
copy
AWS GuardDuty Important Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AWS Identity Center Identity Provider Change
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
AWS SecurityHub Findings Evasion
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Azure Active Directory Hybrid Health AD FS New Server
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1578
·
Share on:
twitter
facebook
linkedin
copy
Azure Active Directory Hybrid Health AD FS Service Delete
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1578.003
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Only Single Factor Authentication Required
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.defense-impairment
attack.t1078.004
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Azure Firewall Modified or Deleted
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
Azure Firewall Rule Collection Modified or Deleted
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Events Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Azure Network Firewall Policy Modified or Deleted
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Audit Log Configuration Updated
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global Secret Scanning Rule Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global SSH Settings Changed
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.defense-impairment
attack.t1685
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Project Secret Scanning Allowlist Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Exempt Repository Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Rule Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Blackbyte Ransomware Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird - Registry
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Bpfdoor TCP Ports Redirect
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Removed by Non Approved Actor
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Updated by Non Approved Actor
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Certificate-Based Authentication Enabled
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Change the Fax Dll
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Change to Authentication Method
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.defense-impairment
attack.t1556
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Change User Account Associated with the FAX Service
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Change Winevt Channel Access Permission Via Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Changes to Device Registration Policy
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484
·
Share on:
twitter
facebook
linkedin
copy
Chmod Targeting Sensitive Directories
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Cisco Crypto Commands
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1553.004
attack.t1552.004
·
Share on:
twitter
facebook
linkedin
copy
Cisco Disabling Logging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Cisco Dot1x Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1685
attack.t1556.004
·
Share on:
twitter
facebook
linkedin
copy
Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
ClickOnce Trust Prompt Tampering
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
CrashControl CrashDump Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1564
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
cve.2020-1048
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Delete Defender Scan ShellEx Context Menu Registry Key
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Deployment Of The AppX Package Was Blocked By The Policy
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Devcon Execution Disabling VMware VMCI Device
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1543.003
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
DHCP Callout DLL Installation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT Scheduled Task Creation - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Directory Service Restore Mode(DSRM) Registry Value Tampering
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Disable Exploit Guard Network Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Internal Tools or Feature in Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Disable Macro Runtime Scan Scope
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Disable Microsoft Defender Firewall via Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Disable of ETW Trace - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Disable Or Stop Services
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Disable Privacy Settings Experience in Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable PUA Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Security Events Logging Adding Reg Key MiniNt
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Disable Security Tools
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable System Firewall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Disable Tamper Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Defender AV Security Monitoring
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Defender Functionalities Via Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Event Logging Via Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Firewall by Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows IIS HTTP Logging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Security Center Notifications
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Disable-WindowsOptionalFeature Command PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled IE Security Features
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled MFA to Bypass Authentication Mechanisms
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Disabled Volume Snapshots
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled Windows Defender Eventlog
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabling Multi Factor Authentication
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Disabling Security Tools
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Disabling Security Tools - Builtin
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Disabling Windows Defender WMI Autologger Session via Reg.exe
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Dism Remove Online Package
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
DNS-over-HTTPS Enabled by Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1140
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Dropping Of Password Filter DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.002
·
Share on:
twitter
facebook
linkedin
copy
DumpStack.log Defender Evasion
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage - ProcCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ESXi Syslog Configuration Change Via ESXCLI
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
attack.t1690
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For rpcrt4.dll
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For SCM
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Sysmon Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Tamper In .NET Processes Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging/Processing Option Disabled On IIS Server
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
ETW Trace Evasion Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Eventlog Cleared
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
EVTX Created In Uncommon Location
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
File or Folder Permissions Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Filter Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Firewall Disabled via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
attack.s0108
·
Share on:
twitter
facebook
linkedin
copy
Firewall Rule Deleted Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Firewall Rule Update Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
FlowCloud Registry Markers
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Flush Iptables Ufw Chain
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Folder Removed From Exploit Guard ProtectedFolders List - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - File Creation Activity
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - JavaScript Constrained File Creation
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - Firewall Address Object Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - New Firewall Policy Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Gatekeeper Bypass via Xattr
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.001
·
Share on:
twitter
facebook
linkedin
copy
Github High Risk Configuration Disabled
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Bypass Detected
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
GitHub Repository Archive Status Changed
calendar
Apr 28, 2026
·
attack.persistence
attack.impact
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Github Secret Scanning Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Firewall Modified or Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Group Policy Abuse for Privilege Addition
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CobaltStrike BOF Injection Pattern
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1106
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hacktool - EDR-Freeze Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EDRSilencer Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EDRSilencer Execution - Filter Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - PowerTool Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpEvtMute DLL Load
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpEvtMute Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Stracciatella Execution
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SysmonEnte Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Hide Schedule Task Via Index Value Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HTTP Logging Disabled On IIS Server
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor Enforced Paging Translation Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Event Auditing Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Eventlog Cleared
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From a File
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From an ADS
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Indicator Removal on Host - Clear Mac System Logs
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
Install Root Certificate
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Internet Explorer DisableFirstRunCustomize Enabled
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Configuration Persistence
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1553.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kaspersky Endpoint Security Stopped Via CommandLine - Linux
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Linux Logs Clearing Attempts
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
Load Of RstrtMgr.DLL By A Suspicious Process
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1486
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Load Of RstrtMgr.DLL By An Uncommon Process
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1486
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Logging Configuration Changes on Linux Host
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
LSA PPL Protection Setting Modification via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1689
·
Share on:
twitter
facebook
linkedin
copy
Macro Enabled In A Potentially Suspicious Document
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Defender Tamper Protection Trigger
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash - WER
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Office Protected View Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Modification of IE Registry Settings
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Modify Group Policy Settings
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Modify Group Policy Settings - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Modify System Firewall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
MSSQL Disable Audit Settings
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
NET NGenAssemblyUsageLog Registry Key Tamper
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Netsh Allow Group Policy on Microsoft Defender Firewall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom DB Path Registry Configuration
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom VBScript Registry Configuration
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom WMI Query Registry Configuration
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New Federated Domain Added
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.002
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
New Firewall Rule Added Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
attack.s0246
·
Share on:
twitter
facebook
linkedin
copy
New Module Module Added To IIS Server
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
New Network ACL Entry Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
New Network Route Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.001
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Authority Added
calendar
Apr 28, 2026
·
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Installed Via CertMgr.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Installed Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Non-privileged Usage of Reg or Powershell
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NotPetya Ransomware Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1218.011
attack.t1685.005
attack.credential-access
attack.t1003.001
car.2016-04-002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
NtdllPipe Like Activity Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated PowerShell OneLiner Execution
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059.001
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
OceanLotus Registry Activity
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Office Macros Warning Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Registry Persistence
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - Security
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - System
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-impairment
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Okta MFA Reset or Deactivated
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Okta User Session Start Via An Anonymising Proxy Service
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via New SIP Provider
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1553.003
·
Share on:
twitter
facebook
linkedin
copy
Possible DC Shadow Attack
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1207
·
Share on:
twitter
facebook
linkedin
copy
Possible Shadow Credentials Added
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Script Using NULL Bits
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Using NULL Bits
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Via .NET Reflection
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI COM Server Hijacking
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Attachment Manager Settings Associations Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential Attachment Manager Settings Attachments Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential AutoLogger Sessions Tampering
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Potential EventLog File Location Tampering
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Ke3chang/TidePool Malware Activity
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.g0004
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential NetWire RAT Activity - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Custom Protocol Handler
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Event Viewer Events.asp
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Home Page
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Today Page
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Security Descriptors - ScriptBlock
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Execution Policy Tampering
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Execution Policy Tampering - ProcCreation
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potential Privileged System Service Operation - SeLoadDriverPrivilege
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Qakbot Registry Activity
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Secure Deletion with SDelete
calendar
Apr 28, 2026
·
attack.impact
attack.stealth
attack.defense-impairment
attack.t1070.004
attack.t1027.005
attack.t1485
attack.t1553.002
attack.s0195
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Activity Using SeCEdit
calendar
Apr 28, 2026
·
attack.collection
attack.discovery
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.execution
attack.stealth
attack.defense-impairment
attack.t1685.001
attack.t1547.001
attack.t1505.005
attack.t1556.002
attack.t1685
attack.t1574.007
attack.t1564.002
attack.t1546.008
attack.t1546.007
attack.t1547.014
attack.t1547.010
attack.t1547.002
attack.t1557
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Registry File Imported Via Reg.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.lateral-movement
attack.defense-impairment
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With Security Products Via WMIC
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Ursnif Malware Activity - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Windows Defender Tampering Via Wmic.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1047
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Call To Win32_NTEventlogFile Class
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Using Reg.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.impact
attack.defense-impairment
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Via Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.impact
attack.defense-impairment
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious NTFS Symlink Behavior Modification
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious WDAC Policy File Creation
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Powershell Base64 Encoded MpPreference Cmdlet
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Powershell Defender Disable Scan Feature
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Powershell Defender Exclusion
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Powershell Install a DLL in System Directory
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1556.002
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Logging Disabled Via Registry Key Tampering
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1564.001
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script Change Permission Via Set-Acl - PsScript
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Set-Acl On Windows Folder - PsScript
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Write-EventLog Usage
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
PPL Tampering Via WerFaultSecure
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Previously Installed IIS Module Was Removed
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1505.004
·
Share on:
twitter
facebook
linkedin
copy
PUA - CleanWipe Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Python Function Execution Security Warning Disabled In Excel
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Python Function Execution Security Warning Disabled In Excel - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Raccine Uninstall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
RDP Connection Allowed Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed to Zero
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RedMimicry Winnti Playbook Registry Manipulation
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RedSun - Named Pipe Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1055
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - TieringEngineService.exe Detected as EICAR Test File
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1036.005
attack.t1685
attack.privilege-escalation
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Reg Add Suspicious Paths
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Registry Entries For Azorult Malware
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Explorer Policy Modification
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Hide Function from User
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Manipulation via WMI Stdregprov
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.discovery
attack.defense-impairment
attack.t1047
attack.t1112
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript - PowerShell
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification for OCI DLL Redirection
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.defense-impairment
attack.t1112
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification of MS-settings Protocol Handler
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.defense-impairment
attack.t1548.002
attack.t1546.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Via Regini.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Tampering by Potentially Suspicious Processes
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Remote Registry Lateral Movement
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.defense-impairment
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Removal Of AMSI Provider Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Removal Of Index Value to Hide Schedule Task - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Removal of Potential COM Hijacking Registry Keys
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Removal Of SD Value to Hide Schedule Task - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Remove Immutable File Attribute
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Remove Immutable File Attribute - Auditd
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.002
·
Share on:
twitter
facebook
linkedin
copy
Renamed BOINC Client Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering - ProcCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Root Certificate Installed - PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Root Certificate Installed From Susp Locations
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Configuration in Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Execution as Configured in Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
SafeBoot Registry Key Deleted Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect User Database Modification - Security
calendar
Apr 28, 2026
·
cve.2024-1709
detection.emerging-threats
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Scripted Diagnostics Turn Off Check Enabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Process
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Registry Set
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685.001
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Security Eventlog Cleared
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Security Service Disabled Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service Binary in Suspicious Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Key Deleted Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service Startup Type Change Via Wmic.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1047
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service StartupType Change Via PowerShell Set-Service
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service StartupType Change Via Sc.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ShimCache Flush
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Startup/Logon Script Added to Group Policy Object
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Application Allowed Through Exploit Guard
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Eventlog Clear
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Eventlog Clearing or Configuration Change Activity
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.005
attack.t1685.001
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Execution via macOS Script Editor
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1566
attack.t1566.002
attack.initial-access
attack.t1059
attack.t1059.002
attack.t1204
attack.t1204.001
attack.execution
attack.persistence
attack.t1553
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Invoke-Item From Mount-DiskImage
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1003
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Mount-DiskImage
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Package Installed - Linux
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Path In Keyboard Layout IME File Registry Value
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1003.001
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PROCEXP152.sys File Created In TMP
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RazerInstaller Explorer Subprocess
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1553
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Recursive Takeown
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1222.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Registry Modification From ADS Via Regini.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Installed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Svchost Process Access
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Unblock-File
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Uninstall of Windows Defender Feature via PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious VBoxDrvInst.exe Parameters
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Service Tampering
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1489
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.t1685.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious X509Enrollment - Process Creation
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious X509Enrollment - Ps Script
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1553.004
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals PsSuspend Suspicious Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Syslog Clearing or Removal Via System Utilities
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.006
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Application Crashed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Blocked Executable
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Blocked File Shredding
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Channel Reference Deletion
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Change
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Update
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Altitude Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Sysmon File Executable Creation Detected
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender - PSClassic
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender Remove-MpPreference
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper With Sophos AV Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Taskkill Symantec Endpoint Protection
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Terminal Server Client Connection History Cleared - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
The Windows Defender Firewall Service Failed To Load Group Policy
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Trust Access Disable For VBApplications
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Ufw Force Stop Using Ufw-Init
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Extension In Keyboard Layout IME File Registry Value
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Microsoft Office Trusted Location Added
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Uncommon New Firewall Rule Added In Windows Firewall Exception List
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Crowdstrike Falcon Sensor
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Sysinternals Sysmon
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
User Added To Group With CA Policy Modification Access
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User Removed From Group With CA Policy Modification Access
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.persistence
attack.defense-impairment
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User Shell Folders Registry Modification via CommandLine
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1547.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Blocklist Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
WannaCry Ransomware Activity
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.defense-impairment
attack.t1210
attack.discovery
attack.t1083
attack.t1222.001
attack.impact
attack.t1486
attack.t1490
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Wdigest CredGuard Registry Modification
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Wdigest Enable UseLogonCredential
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Weak Encryption Enabled and Kerberoast
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
WFP Filter Added via Registry
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Win Defender Restored Quarantine File
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
WinDivert Driver Load
calendar
Apr 28, 2026
·
attack.credential-access
attack.collection
attack.defense-impairment
attack.t1599.001
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Windows AMSI Related Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows AppX Deployment Full Trust Package Installation
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1204.002
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Windows AppX Deployment Unsigned Package Installation
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1204.002
attack.t1553.005
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Disabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Related Registry Value Deleted - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Default Domain GPO Modification
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Default Domain GPO Modification via GPME
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.defense-impairment
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Configuration Changes
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Context Menu Removed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Definition Files Removed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion List Modified
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion Registry Key - Write Access Requested
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added - PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exploit Guard Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Firewall Has Been Reset To Its Default Configuration
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Grace Period Expired
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Malware And PUA Scanning Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Malware Detection History Deletion
calendar
Apr 28, 2026
·
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Real-time Protection Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Real-Time Protection Failure/Restart
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Service Disabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Submit Sample Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Threat Detection Service Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Threat Severity Default Action Modified
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Virus Scanning Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Auditing Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Log Access Tampering Via Registry
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.defense-impairment
attack.t1547.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Windows EventLog Autologger Session Registry Modification Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Windows Filtering Platform Blocked Connection From EDR Agent Binary
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Firewall Disabled via PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Firewall Profile Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Windows Firewall Settings Have Been Changed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1686.003
·
Share on:
twitter
facebook
linkedin
copy
Windows Hypervisor Enforced Code Integrity Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows MSIX Package Support Framework AI_STUBS Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.defense-impairment
attack.t1218
attack.t1553.005
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Windows Vulnerable Driver Blocklist Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Winget Admin Settings Modification
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
·
Share on:
twitter
facebook
linkedin
copy
Winlogon AllowMultipleTSSessions Enable
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Write Protect For Storage Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
to-top