open-menu
closeme
Antivirus Exploitation Framework Detection
calendar
Jun 13, 2025
·
attack.execution
attack.t1203
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Anydesk Temporary Artefact
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Atera Agent Installation
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To AzureWebsites.NET By Non-Browser Process
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
DNS Query To Remote Access Software Domain From Non-Browser App
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
GoToAssist Temporary Installation Artefact
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Inveigh Execution Artefacts
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Hijack Legit RDP Session to Move Laterally
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Installation of TeamViewer Desktop
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Mesh Agent Service Installation
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Mstsc.EXE Execution With Local RDP File
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Amazon SSM Agent Hijacking
calendar
Jun 13, 2025
·
attack.command-and-control
attack.persistence
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential CSharp Streamer RAT Loading .NET Executable Image
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Amazon SSM Agent Hijacking
calendar
Jun 13, 2025
·
attack.command-and-control
attack.persistence
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote Desktop Connection to Non-Domain Host
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Potential SocGholish Second Stage C2 DNS Query
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
QuickAssist Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Anydesk Execution From Suspicious Folder
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Incoming Connection
calendar
Jun 13, 2025
·
attack.persistence
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Piped Password Via CLI
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - AnyDesk Silent Installation
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - GoToAssist Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - LogMeIn Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - MeshAgent Command Execution via MeshCentral
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - NetSupport Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Simple Help Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - UltraViewer Execution
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect Temporary Installation Artefact
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Binary Writes Via AnyDesk
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Mstsc.EXE Execution With Local RDP File
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious TSCON Start as SYSTEM
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
TacticalRMM Service Installation
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Domain Query By Non-TeamViewer Application
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Remote Session
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
Use of UltraVNC Remote Access Software
calendar
Jun 13, 2025
·
attack.command-and-control
attack.t1219.002
·
Share on:
twitter
facebook
linkedin
copy
to-top