open-menu
closeme
HackTool - KrbRelayUp Execution
calendar
Dec 1, 2023
·
attack.credential_access
attack.t1558.003
attack.lateral_movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
New Remote Desktop Connection Initiated Via Mstsc.EXE
calendar
Dec 1, 2023
·
attack.lateral_movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
PDQ Deploy Remote Adminstartion Tool Execution
calendar
Dec 1, 2023
·
attack.execution
attack.lateral_movement
attack.t1072
·
Share on:
twitter
facebook
linkedin
copy
Exploitation Attempt Of CVE-2023-46214 Using Public POC Code
calendar
Nov 27, 2023
·
cve.2023.46214
detection.emerging_threats
attack.lateral_movement
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-46214 Exploitation Attempt
calendar
Nov 27, 2023
·
attack.lateral_movement
attack.t1210
cve.2023.46214
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp
calendar
Nov 14, 2023
·
attack.t1021.003
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
smbexec.py Service Installation
calendar
Nov 10, 2023
·
attack.lateral_movement
attack.execution
attack.t1021.002
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Port Forwarding Activity Via SSH.EXE
calendar
Nov 6, 2023
·
attack.command_and_control
attack.lateral_movement
attack.t1572
attack.t1021.001
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Privilege Escalation via Named Pipe Impersonation
calendar
Nov 2, 2023
·
attack.lateral_movement
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
NTLMv1 Logon Between Client and Server
calendar
Oct 28, 2023
·
attack.defense_evasion
attack.lateral_movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load
calendar
Oct 28, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
Remote PowerShell Session (PS Classic)
calendar
Oct 28, 2023
·
attack.execution
attack.t1059.001
attack.lateral_movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Non PowerShell WSMAN COM Provider
calendar
Oct 28, 2023
·
attack.execution
attack.t1059.001
attack.lateral_movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Possible Exploitation of Exchange RCE CVE-2021-42321
calendar
Oct 26, 2023
·
attack.lateral_movement
attack.t1210
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Copy from Admin Share
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.collection
attack.exfiltration
attack.t1039
attack.t1048
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Rubeus Execution
calendar
Oct 18, 2023
·
attack.credential_access
attack.t1003
attack.t1558.003
attack.lateral_movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
Hermetic Wiper TG Process Patterns
calendar
Oct 18, 2023
·
attack.execution
attack.lateral_movement
attack.t1021.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Binary Suspicious Communication Endpoint
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
MMC Spawning Windows Shell
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Net.exe Execution
calendar
Oct 18, 2023
·
attack.discovery
attack.t1007
attack.t1049
attack.t1018
attack.t1135
attack.t1201
attack.t1069.001
attack.t1069.002
attack.t1087.001
attack.t1087.002
attack.lateral_movement
attack.t1021.002
attack.s0039
·
Share on:
twitter
facebook
linkedin
copy
New Port Forwarding Rule Added Via Netsh.EXE
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.defense_evasion
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD HTTP No Authentication RCE
calendar
Oct 18, 2023
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.lateral_movement
attack.t1068
attack.t1190
attack.t1203
attack.t1021.006
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
Outbound RDP Connections Over Non-Standard Tools
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Password Provided In Command Line Of Net.EXE
calendar
Oct 18, 2023
·
attack.defense_evasion
attack.initial_access
attack.persistence
attack.privilege_escalation
attack.lateral_movement
attack.t1021.002
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Publicly Accessible RDP Service
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Remote PowerShell Session (Network)
calendar
Oct 18, 2023
·
attack.execution
attack.t1059.001
attack.lateral_movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
Remote Task Creation via ATSVC Named Pipe - Zeek
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.persistence
car.2013-05-004
car.2015-04-001
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Add User to Remote Desktop Users Group
calendar
Oct 18, 2023
·
attack.persistence
attack.lateral_movement
attack.t1133
attack.t1136.001
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Epmap Connection
calendar
Oct 18, 2023
·
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outbound Kerberos Connection
calendar
Oct 18, 2023
·
attack.credential_access
attack.t1558
attack.lateral_movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outbound Kerberos Connection - Security
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious WSMAN Provider Image Loads
calendar
Oct 18, 2023
·
attack.execution
attack.t1059.001
attack.lateral_movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Lateral Movement
calendar
Oct 18, 2023
·
attack.g0010
attack.execution
attack.t1059
attack.lateral_movement
attack.t1021.002
attack.discovery
attack.t1083
attack.t1135
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
WannaCry Ransomware Activity
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1210
attack.discovery
attack.t1083
attack.defense_evasion
attack.t1222.001
attack.impact
attack.t1486
attack.t1490
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Windows Admin Share Mount Via Net.EXE
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Windows Internet Hosted WebDav Share Mount Via Net.EXE
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Windows Share Mount Via Net.EXE
calendar
Oct 18, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Audit CVE Event
calendar
Oct 17, 2023
·
attack.execution
attack.t1203
attack.privilege_escalation
attack.t1068
attack.defense_evasion
attack.t1211
attack.credential_access
attack.t1212
attack.lateral_movement
attack.t1210
attack.impact
attack.t1499.004
·
Share on:
twitter
facebook
linkedin
copy
Metasploit Or Impacket Service Installation Via SMB PsExec
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1021.002
attack.t1570
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
NTLM Logon
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
OpenSSH Server Listening On Socket
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Outgoing Logon with New Credentials
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.lateral_movement
attack.t1550
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote Desktop Tunneling
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
RDP over Reverse SSH Tunnel WFP
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.command_and_control
attack.lateral_movement
attack.t1090.001
attack.t1090.002
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
RDP to HTTP or HTTPS Target Ports
calendar
Oct 17, 2023
·
attack.command_and_control
attack.t1572
attack.lateral_movement
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious New-PSDrive to Admin Share
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Logon with Explicit Credentials
calendar
Oct 17, 2023
·
attack.t1078
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SysAidServer Child
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
User with Privileges Logon
calendar
Oct 17, 2023
·
attack.defense_evasion
attack.lateral_movement
attack.credential_access
attack.t1558
attack.t1649
attack.t1550
·
Share on:
twitter
facebook
linkedin
copy
Writing Local Admin Share
calendar
Oct 17, 2023
·
attack.lateral_movement
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
AWS STS AssumeRole Misuse
calendar
Oct 12, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS STS GetSessionToken Misuse
calendar
Oct 12, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS Suspicious SAML Activity
calendar
Oct 12, 2023
·
attack.initial_access
attack.t1078
attack.lateral_movement
attack.t1548
attack.privilege_escalation
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
Possible Impacket DCOMExec Connection Attempt - Zeek
calendar
Sep 1, 2023
·
attack.s0357
attack.execution
attack.lateral_movement
attack.t1021
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Apache Threading Error
calendar
Aug 28, 2023
·
attack.initial_access
attack.lateral_movement
attack.t1190
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations in Registry
calendar
Aug 17, 2023
·
attack.execution
attack.privilege_escalation
attack.lateral_movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
CSExec Default Named Pipe
calendar
Aug 7, 2023
·
attack.lateral_movement
attack.t1021.002
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
RemCom Default Named Pipe
calendar
Aug 7, 2023
·
attack.lateral_movement
attack.t1021.002
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Rubeus Execution - ScriptBlock
calendar
Jun 26, 2023
·
attack.credential_access
attack.t1003
attack.t1558.003
attack.lateral_movement
attack.t1550.003
·
Share on:
twitter
facebook
linkedin
copy
SMB Create Remote File Admin Share
calendar
Jun 26, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Successful Overpass the Hash Attempt
calendar
Jun 26, 2023
·
attack.lateral_movement
attack.s0002
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
Remote DCOM/WMI Lateral Movement
calendar
Jun 22, 2023
·
attack.lateral_movement
attack.t1021.003
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Remote Encrypting File System Abuse
calendar
Jun 22, 2023
·
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Remote Printing Abuse for Lateral Movement
calendar
Jun 22, 2023
·
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Remote Registry Lateral Movement
calendar
Jun 22, 2023
·
attack.lateral_movement
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via ATSvc
calendar
Jun 22, 2023
·
attack.lateral_movement
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via ITaskSchedulerService
calendar
Jun 22, 2023
·
attack.lateral_movement
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via SASec
calendar
Jun 22, 2023
·
attack.lateral_movement
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Server Service Abuse
calendar
Jun 22, 2023
·
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Remote Server Service Abuse for Lateral Movement
calendar
Jun 22, 2023
·
attack.lateral_movement
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
External Disk Drive Or USB Storage Device
calendar
Jun 21, 2023
·
attack.t1091
attack.t1200
attack.lateral_movement
attack.initial_access
·
Share on:
twitter
facebook
linkedin
copy
APT31 Judgement Panda Activity
calendar
Jun 20, 2023
·
attack.lateral_movement
attack.credential_access
attack.g0128
attack.t1003.001
attack.t1560.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Logon Scripts - Registry
calendar
Jun 9, 2023
·
attack.t1037.001
attack.persistence
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Potential DCOM InternetExplorer.Application DLL Hijack - Image Load
calendar
Jun 1, 2023
·
attack.lateral_movement
attack.t1021.002
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RDP Redirect Using TSCON
calendar
May 17, 2023
·
attack.lateral_movement
attack.t1563.002
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
PSEXEC Remote Execution File Artefact
calendar
May 15, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.execution
attack.persistence
attack.t1136.002
attack.t1543.003
attack.t1570
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
Remote PowerShell Session (PS Module)
calendar
May 15, 2023
·
attack.execution
attack.t1059.001
attack.lateral_movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
Default Impacket Service Creation Via Registry Keys (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
File Writes Within Admin Shares (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Process Execution from Admin Share (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Admin User Remote Logon
calendar
May 2, 2023
·
attack.lateral_movement
attack.t1078.001
attack.t1078.002
attack.t1078.003
car.2016-04-005
·
Share on:
twitter
facebook
linkedin
copy
Pass the Hash Activity 2
calendar
May 2, 2023
·
attack.lateral_movement
attack.t1550.002
·
Share on:
twitter
facebook
linkedin
copy
RDP Login from Localhost
calendar
May 2, 2023
·
attack.lateral_movement
car.2013-07-002
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Remote WMI ActiveScriptEventConsumers
calendar
May 2, 2023
·
attack.lateral_movement
attack.privilege_escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
Scanner PoC for CVE-2019-0708 RDP RCE Vuln
calendar
May 2, 2023
·
attack.lateral_movement
attack.t1210
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Failed Mounting of Hidden Share
calendar
Apr 21, 2023
·
attack.t1021.002
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Metasploit Or Impacket Service Installation Via SMB PsExec
calendar
Apr 21, 2023
·
attack.lateral_movement
attack.t1021.002
attack.t1570
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Service Creation
calendar
Apr 21, 2023
·
attack.lateral_movement
attack.persistence
attack.execution
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Mstsc.EXE Execution From Uncommon Parent
calendar
Apr 18, 2023
·
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Exe File Event With System Image
calendar
Apr 16, 2023
·
attack.lateral_movement
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations - System
calendar
Apr 14, 2023
·
attack.execution
attack.privilege_escalation
attack.lateral_movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Potential RDP Exploit CVE-2019-0708
calendar
Apr 14, 2023
·
attack.lateral_movement
attack.t1210
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Zerologon Exploitation Using Well-known Tools
calendar
Apr 14, 2023
·
attack.t1210
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Execution Without Parameters
calendar
Mar 16, 2023
·
attack.lateral_movement
attack.t1021.002
attack.t1570
attack.execution
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
First Time Seen Remote Named Pipe
calendar
Mar 14, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Wmiexec Default Powershell Command
calendar
Mar 13, 2023
·
attack.defense_evasion
attack.lateral_movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious UltraVNC Execution
calendar
Mar 9, 2023
·
attack.lateral_movement
attack.g0047
attack.t1021.005
·
Share on:
twitter
facebook
linkedin
copy
Wmiexec Default Output File
calendar
Mar 9, 2023
·
attack.lateral_movement
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Terminal Service Process Spawn
calendar
Mar 5, 2023
·
attack.initial_access
attack.t1190
attack.lateral_movement
attack.t1210
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
T1047 Wmiprvse Wbemcomn DLL Hijack
calendar
Feb 27, 2023
·
attack.execution
attack.t1047
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential Impacket Lateral Movement Activity
calendar
Feb 21, 2023
·
attack.execution
attack.t1047
attack.lateral_movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
RDP Port Forwarding Rule Added Via Netsh.EXE
calendar
Feb 16, 2023
·
attack.lateral_movement
attack.defense_evasion
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
HackTool - WinRM Access Via Evil-WinRM
calendar
Feb 13, 2023
·
attack.lateral_movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
PUA - Radmin Viewer Utility Execution
calendar
Feb 13, 2023
·
attack.execution
attack.lateral_movement
attack.t1072
·
Share on:
twitter
facebook
linkedin
copy
DCOM InternetExplorer.Application Iertutil DLL Hijack - Security
calendar
Feb 7, 2023
·
attack.lateral_movement
attack.t1021.002
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Protected Storage Service Access
calendar
Feb 7, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Wmiprvse Wbemcomn DLL Hijack
calendar
Feb 7, 2023
·
attack.execution
attack.t1047
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Wmiprvse Wbemcomn DLL Hijack - File
calendar
Feb 7, 2023
·
attack.execution
attack.t1047
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
calendar
Feb 6, 2023
·
attack.defense_evasion
attack.lateral_movement
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential MSTSC Shadowing Activity
calendar
Feb 5, 2023
·
attack.lateral_movement
attack.t1563.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Plink Port Forwarding
calendar
Feb 5, 2023
·
attack.command_and_control
attack.t1572
attack.lateral_movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Access to ADMIN$ Share
calendar
Feb 1, 2023
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations - Security
calendar
Feb 1, 2023
·
attack.execution
attack.privilege_escalation
attack.lateral_movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Mimikatz Use
calendar
Feb 1, 2023
·
attack.s0002
attack.lateral_movement
attack.credential_access
car.2013-07-001
car.2019-04-004
attack.t1003.002
attack.t1003.004
attack.t1003.001
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
Pandemic Registry Key
calendar
Feb 1, 2023
·
attack.lateral_movement
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Enable Windows Remote Management
calendar
Jan 27, 2023
·
attack.lateral_movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
Execute Invoke-command on Remote Host
calendar
Jan 27, 2023
·
attack.lateral_movement
attack.t1021.006
·
Share on:
twitter
facebook
linkedin
copy
Enabling RDP service via reg.exe command execution
calendar
Jan 8, 2023
·
attack.defense_evasion
attack.lateral_movement
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Execution of ZeroLogon PoC executable
calendar
Jan 8, 2023
·
attack.execution
attack.lateral_movement
attack.T1210
·
Share on:
twitter
facebook
linkedin
copy
Potential Qbot SMB DLL Lateral Movement
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1570
·
Share on:
twitter
facebook
linkedin
copy
Potential SMB DLL Lateral Movement
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1570
·
Share on:
twitter
facebook
linkedin
copy
AnyDesk Network
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1133
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
SplashTop Network
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1133
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
SplashTop Process
calendar
Jan 8, 2023
·
attack.lateral_movement
attack.t1133
attack.command_and_control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Cisco Stage Data
calendar
Jan 4, 2023
·
attack.collection
attack.lateral_movement
attack.command_and_control
attack.exfiltration
attack.t1074
attack.t1105
attack.t1560.001
·
Share on:
twitter
facebook
linkedin
copy
First Time Seen Remote Named Pipe - Zeek
calendar
Dec 27, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PsExec Execution - Zeek
calendar
Dec 27, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
PSExec and WMI Process Creations Block
calendar
Dec 27, 2022
·
attack.execution
attack.lateral_movement
attack.t1047
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Potential DCOM InternetExplorer.Application DLL Hijack
calendar
Dec 18, 2022
·
attack.lateral_movement
attack.t1021.002
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
RDP Over Reverse SSH Tunnel
calendar
Dec 8, 2022
·
attack.command_and_control
attack.t1572
attack.lateral_movement
attack.t1021.001
car.2013-07-002
·
Share on:
twitter
facebook
linkedin
copy
Executable Deployment from Remote Share
calendar
Nov 29, 2022
·
attack.lateral_movement
attack.command_and_control
attack.t1105
attack.t1021
·
Share on:
twitter
facebook
linkedin
copy
Mimikatz through Windows Remote Management
calendar
Oct 26, 2022
·
attack.credential_access
attack.execution
attack.t1003.001
attack.t1059.001
attack.lateral_movement
attack.t1021.006
attack.s0002
·
Share on:
twitter
facebook
linkedin
copy
DCERPC SMB Spoolss Named Pipe
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Denied Access To Remote Desktop
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.001
·
Share on:
twitter
facebook
linkedin
copy
Impacket PsExec Execution
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Persistence and Execution at Scale via GPO Scheduled Task
calendar
Oct 25, 2022
·
attack.persistence
attack.lateral_movement
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Remote Service Activity via SVCCTL Named Pipe
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.persistence
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Task Creation via ATSVC Named Pipe
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.persistence
car.2013-05-004
car.2015-04-001
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PsExec Execution
calendar
Oct 25, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Remote File Copy
calendar
Oct 25, 2022
·
attack.command_and_control
attack.lateral_movement
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Metasploit SMB Authentication
calendar
Oct 14, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Register new Logon Process by Rubeus
calendar
Oct 14, 2022
·
attack.lateral_movement
attack.privilege_escalation
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
PortProxy Registry Key
calendar
Oct 9, 2022
·
attack.lateral_movement
attack.defense_evasion
attack.command_and_control
attack.t1090
·
Share on:
twitter
facebook
linkedin
copy
SMB Spoolss Name Piped Usage
calendar
Oct 9, 2022
·
attack.lateral_movement
attack.t1021.002
·
Share on:
twitter
facebook
linkedin
copy
Abuse of the Windows Server Update Services (WSUS) for lateral movement.
calendar
Oct 7, 2022
·
attack.execution
attack.lateral_movement
attack.T1210
·
Share on:
twitter
facebook
linkedin
copy
to-top