open-menu
closeme
Suspicious Sysmon as Execution Parent
calendar
Sep 13, 2023
·
attack.privilege_escalation
attack.t1068
cve.2022.41120
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploiting CVE-2019-1388
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
cve.2019.1388
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploiting SetupComplete.cmd CVE-2019-1378
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
attack.execution
attack.t1059.003
attack.t1574
cve.2019.1378
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-41379 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
cve.2021.41379
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential SystemNightmare Exploitation Attempt
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Process Explorer Driver Creation By Non-Sysinternals Binary
calendar
May 5, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Process Monitor Driver Creation By Non-Sysinternals Binary
calendar
May 5, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-3156 Exploitation Attempt
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1068
cve.2021.3156
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-3156 Exploitation Attempt Bruteforcing
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1068
cve.2021.3156
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteScript
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Windows Kernel and 3rd-Party Drivers Exploits Token Stealing
calendar
Apr 21, 2023
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Audit CVE Event
calendar
Apr 14, 2023
·
attack.execution
attack.t1203
attack.privilege_escalation
attack.t1068
attack.defense_evasion
attack.t1211
attack.credential_access
attack.t1212
attack.lateral_movement
attack.t1210
attack.impact
attack.t1499.004
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Load
calendar
Apr 12, 2023
·
attack.privilege_escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Load By Name
calendar
Apr 12, 2023
·
attack.privilege_escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SysmonEOP Execution
calendar
Feb 4, 2023
·
cve.2022.41120
attack.t1068
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
Buffer Overflow Attempts
calendar
Feb 1, 2023
·
attack.t1068
attack.privilege_escalation
·
Share on:
twitter
facebook
linkedin
copy
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Possible Coin Miner CPU Priority Param
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1068
attack.t1548.003
cve.2019.14287
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287 - Builtin
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1068
attack.t1548.003
cve.2019.14287
·
Share on:
twitter
facebook
linkedin
copy
Usage Of Malicious POORTRY Signed Driver
calendar
Feb 1, 2023
·
attack.privilege_escalation
attack.t1543
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Dell BIOS Update Driver Load
calendar
Feb 1, 2023
·
attack.privilege_escalation
cve.2021.21551
attack.t1543
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Nimbuspwn Exploitation
calendar
Jan 23, 2023
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteShellCommand - Auditd
calendar
Nov 27, 2022
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD HTTP No Authentication RCE
calendar
Oct 25, 2022
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.lateral_movement
attack.t1068
attack.t1190
attack.t1203
attack.t1021.006
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteScript
calendar
Oct 25, 2022
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteShellCommand
calendar
Oct 25, 2022
·
attack.privilege_escalation
attack.initial_access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
KrbRelayUp local privilege escalation.
calendar
Apr 27, 2022
·
attack.privilege_escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Exploitation of 7zip vulnerability - CVE-2022-29072
calendar
Apr 25, 2022
·
attack.Exploitation for Privilege Escalation
attack.T1068
·
Share on:
twitter
facebook
linkedin
copy
to-top