open-menu
closeme
Allow RDP Remote Assistance Feature
calendar
Nov 26, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Security Center Notifications
calendar
Nov 26, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Logging Disabled Via Registry Key Tampering
calendar
Nov 26, 2025
·
attack.defense-evasion
attack.t1564.001
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Disable Security Events Logging Adding Reg Key MiniNt
calendar
Nov 24, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.002
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From a File
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Imports Registry Key From an ADS
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Registry Entries For Azorult Malware
calendar
Nov 24, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Via Regini.EXE
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
ShimCache Flush
calendar
Nov 24, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Registry Modification From ADS Via Regini.EXE
calendar
Nov 24, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Suspicious VBoxDrvInst.exe Parameters
calendar
Nov 24, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
calendar
Nov 23, 2025
·
attack.persistence
attack.defense-evasion
attack.lateral-movement
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed
calendar
Nov 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification Attempt Via VBScript - PowerShell
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
Registry Tampering by Potentially Suspicious Processes
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.execution
attack.t1112
attack.t1059.005
·
Share on:
twitter
facebook
linkedin
copy
RDP Sensitive Settings Changed to Zero
calendar
Nov 21, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Office Macros Warning Disabled
calendar
Nov 13, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Trust Access Disable For VBApplications
calendar
Nov 13, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Ursnif Malware Activity - Registry
calendar
Nov 13, 2025
·
attack.persistence
attack.defense-evasion
attack.execution
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Modification of IE Registry Settings
calendar
Nov 10, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird - Registry
calendar
Nov 10, 2025
·
attack.defense-evasion
attack.execution
attack.persistence
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential NetWire RAT Activity - Registry
calendar
Nov 10, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Activate Suppression of Windows Security Center Notifications
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Add DisallowRun Execution to Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Blackbyte Ransomware Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.execution
attack.t1112
attack.t1047
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Change the Fax Dll
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Change User Account Associated with the FAX Service
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
ClickOnce Trust Prompt Tampering
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
CrashControl CrashDump Disabled
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1564
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DHCP Callout DLL Installation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Disable Internal Tools or Feature in Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DNS-over-HTTPS Enabled by Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1140
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enable LM Hash Storage - ProcCreation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For rpcrt4.dll
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For SCM
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Sysmon Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562
·
Share on:
twitter
facebook
linkedin
copy
FlowCloud Registry Markers
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Macro Enabled In A Potentially Suspicious Document
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NET NGenAssemblyUsageLog Registry Key Tamper
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom DB Path Registry Configuration
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom VBScript Registry Configuration
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New BgInfo.EXE Custom WMI Query Registry Configuration
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Non-privileged Usage of Reg or Powershell
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
OceanLotus Registry Activity
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Registry Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - System
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Custom Protocol Handler
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Home Page
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook Today Page
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Qakbot Registry Activity
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
calendar
Oct 23, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Registry File Imported Via Reg.EXE
calendar
Oct 23, 2025
·
attack.persistence
attack.t1112
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Using Reg.EXE
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.impact
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Desktop Background Change Via Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.impact
attack.t1112
attack.t1491.001
·
Share on:
twitter
facebook
linkedin
copy
RedMimicry Winnti Playbook Registry Manipulation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Reg Add Suspicious Paths
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Registry Explorer Policy Modification
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Hide Function from User
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Registry Manipulation via WMI Stdregprov
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.defense-evasion
attack.discovery
attack.t1047
attack.t1112
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Remote Registry Lateral Movement
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.lateral-movement
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Removal of Potential COM Hijacking Registry Keys
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
RestrictedAdminMode Registry Value Tampering - ProcCreation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Configuration in Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Run Once Task Execution as Configured in Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Process
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.002
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Security Event Logging Disabled via MiniNt Registry Key - Registry Set
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1562.002
attack.t1112
car.2022-03-001
·
Share on:
twitter
facebook
linkedin
copy
Service Binary in Suspicious Folder
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Channel Reference Deletion
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Terminal Server Client Connection History Cleared - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1070
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Microsoft Office Trusted Location Added
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Wdigest CredGuard Registry Modification
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Wdigest Enable UseLogonCredential
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Log Access Tampering Via Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1547.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
calendar
Jun 12, 2025
·
attack.persistence
attack.execution
attack.defense-evasion
attack.t1112
cve.2020-1048
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Event Viewer Events.asp
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Winlogon AllowMultipleTSSessions Enable
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enabling RDP service via reg.exe command execution
calendar
Aug 10, 2024
·
attack.defense_evasion
attack.lateral_movement
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
to-top