open-menu
closeme
Explorer UAC Bypass Via /NOUACCHECK Parameter
calendar
Aug 10, 2024
·
attack.privilege_escalation
attack.T1548.002
·
Share on:
twitter
facebook
linkedin
copy
KrbRelayUp local privilege escalation.
calendar
Aug 10, 2024
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
SamAccountName Spoofing and Domain Controller Impersonation
calendar
Aug 10, 2024
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
AppInit DLL Installation
calendar
Mar 26, 2024
·
attack.privilege_escalation
attack.persistence
attack.t1546
attack.t1546.010
·
Share on:
twitter
facebook
linkedin
copy
Non-depmod Process Modifying modules.dep
calendar
Mar 26, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1547
attack.t1547.006
·
Share on:
twitter
facebook
linkedin
copy
Non-Microsoft App Package Installation Process
calendar
Mar 26, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1546
attack.t1546.016
·
Share on:
twitter
facebook
linkedin
copy
Package Support Framework (PSF) Advanced Installer Processes
calendar
Mar 26, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1546
attack.t1546.016
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Startup Folder Persistence
calendar
Mar 26, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1547
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Shells Modifying Files in Known Linux Kernel Modules Directories
calendar
Mar 26, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1547
attack.t1547.006
·
Share on:
twitter
facebook
linkedin
copy
Systemd Loading a Linux Kernel Module Using insmod
calendar
Mar 26, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1547
attack.t1547.006
·
Share on:
twitter
facebook
linkedin
copy
Systemd Loading a Linux Kernel Module Using modprobe
calendar
Mar 26, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1547
attack.t1547.006
·
Share on:
twitter
facebook
linkedin
copy
QBot process creation from scheduled task REGSVR32 (regsvr32.exe), -s flag and SYSTEM in the command line
calendar
Feb 23, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
QBot scheduled task REGSVR32 with C$ image path
calendar
Feb 23, 2024
·
attack.persistence
attack.privilege_escalation
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Network Connections Where There Should Not Be (Notepad)
calendar
Sep 1, 2023
·
attack.privilege_escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious 'Admin' Local User Creation with Net Command
calendar
Sep 1, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1136.001
attack.t1136
attack.t1078
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
Find Binary Searching for Executables with Setuid or Setguid Bit (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.privilege_escalation
attack.t1548.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Gamarue DLL Filename (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.privilege_escalation
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Injecting Into Anything (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.privilege_escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Process Executing Sans Command Line (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.privilege_escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Network Connections (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.privilege_escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-3156 Exploitation Attempt
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1068
cve.2021.3156
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-3156 Exploitation Attempt Bruteforcing
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1068
cve.2021.3156
·
Share on:
twitter
facebook
linkedin
copy
Detection of Possible Rotten Potato
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1134
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Disabled Users Failing To Authenticate From Source Using Kerberos
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Failed Logins with Different Accounts from Single Source System
calendar
Apr 21, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Failed NTLM Logins with Different Accounts from Single Source System
calendar
Apr 21, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Invalid Users Failing To Authenticate From Single Source Using NTLM
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Invalid Users Failing To Authenticate From Source Using Kerberos
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Malicious Service Installations
calendar
Apr 21, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1003
attack.t1035
attack.t1050
car.2013-09-005
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
MSI Spawned Cmd and Powershell Spawned Processes
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Multiple Users Failing to Authenticate from Single Process
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Multiple Users Remotely Failing To Authenticate From Single Source
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteScript
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Password Spraying via Explicit Credentials
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Valid Users Failing to Authenticate From Single Source Using Kerberos
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Valid Users Failing to Authenticate from Single Source Using NTLM
calendar
Apr 21, 2023
·
attack.t1110.003
attack.initial_access
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Windows Kernel and 3rd-Party Drivers Exploits Token Stealing
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Commands by SQL Server
calendar
Jan 8, 2023
·
attack.initial_access
attack.persistence
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Injecting into Other Process
calendar
Nov 9, 2022
·
attack.privilege_escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Process Execution sans Command Lines
calendar
Nov 9, 2022
·
attack.privilege_escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
to-top