open-menu
closeme
Axios NPM Compromise Indicators - Windows
calendar
Apr 28, 2026
·
attack.initial-access
attack.t1195.002
attack.execution
attack.command-and-control
attack.t1059.003
attack.t1059.005
attack.t1105
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Csc.EXE Execution Form Potentially Suspicious Parent
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1059.007
attack.t1218.005
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CACTUSTORCH Remote Thread Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1055.012
attack.t1059.005
attack.t1059.007
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
HTML Help HH.EXE Suspicious Child Process
calendar
Apr 28, 2026
·
attack.execution
attack.initial-access
attack.stealth
attack.t1047
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.007
attack.t1218
attack.t1218.001
attack.t1218.010
attack.t1218.011
attack.t1566
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
MMC Loading Script Engines DLLs
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218.014
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote SquiblyTwo Technique Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1047
attack.t1220
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript - PowerShell
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Tampering by Potentially Suspicious Processes
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.defense-impairment
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of BgInfo.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious HH.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.initial-access
attack.stealth
attack.t1047
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.007
attack.t1218
attack.t1218.001
attack.t1218.010
attack.t1218.011
attack.t1566
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of BgInfo.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Windows Shell/Scripting Processes Spawning Suspicious Programs
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1059.001
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
XSL Script Execution Via WMIC.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1047
attack.t1220
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potential Dropper Script Execution Via WScript/CScript/MSHTA
calendar
Apr 27, 2026
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
WScript or CScript Dropper - File
calendar
Apr 27, 2026
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
HackTool - NetExec File Indicators
calendar
Apr 23, 2026
·
attack.execution
attack.lateral-movement
attack.discovery
attack.t1021.002
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
AppLocker Prevented Application or Script from Running
calendar
Dec 24, 2025
·
attack.execution
attack.t1204.002
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.006
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Koadic Execution
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.003
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potential QBot Activity
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scripting in a WMI Consumer
calendar
Nov 24, 2025
·
attack.execution
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Adwind RAT / JRAT
calendar
Aug 12, 2024
·
attack.execution
attack.t1059.005
attack.t1059.007
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Adwind RAT / JRAT File Artifact
calendar
Aug 12, 2024
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Cscript/Wscript Uncommon Script Extension Execution
calendar
Aug 12, 2024
·
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potential APT10 Cloud Hopper Activity
calendar
Aug 12, 2024
·
attack.execution
attack.g0045
attack.t1059.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
calendar
Aug 12, 2024
·
attack.discovery
attack.execution
attack.t1615
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
calendar
Aug 12, 2024
·
attack.discovery
attack.execution
attack.t1615
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Wscript.exe Executing Agreement Javascript in AppData Folder
calendar
Nov 9, 2022
·
attack.execution
attack.t1059
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
to-top