open-menu
closeme
Suspicious Sysmon as Execution Parent
calendar
Sep 13, 2023
·
attack.privilege_escalation
attack.t1068
cve.2022.41120
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-38331 Exploitation Attempt - Suspicious Double Extension File
calendar
Sep 7, 2023
·
attack.execution
cve.2023.38331
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process
calendar
Sep 7, 2023
·
detection.emerging_threats
attack.execution
attack.t1203
cve.2023.38331
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-40477 Potential Exploitation - .REV File Creation
calendar
Sep 7, 2023
·
attack.execution
cve.2023.40477
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-40477 Potential Exploitation - WinRAR Application Crash
calendar
Sep 7, 2023
·
attack.execution
cve.2023.40477
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
FoggyWeb Backdoor DLL Loading
calendar
Sep 7, 2023
·
attack.resource_development
attack.t1587
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
calendar
Sep 7, 2023
·
attack.defense_evasion
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor DLL Loading Activity
calendar
Sep 7, 2023
·
attack.persistence
attack.t1574.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36874 Exploitation - Fake Wermgr Execution
calendar
Sep 7, 2023
·
attack.execution
cve.2023.36874
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36874 Exploitation - Fake Wermgr.Exe Creation
calendar
Sep 7, 2023
·
attack.execution
cve.2023.36874
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36874 Exploitation - Uncommon Report.Wer Location
calendar
Sep 7, 2023
·
attack.execution
cve.2023.36874
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Uninstaller Execution
calendar
Sep 1, 2023
·
detection.emerging_threats
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
ADSelfService Exploitation
calendar
Aug 28, 2023
·
cve.2021.40539
detection.emerging_threats
attack.initial_access
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request
calendar
Aug 28, 2023
·
cve.2023.34362
detection.emerging_threats
attack.persistence
attack.t1505.003
·
Share on:
twitter
facebook
linkedin
copy
Potential BlackByte Ransomware Activity
calendar
Aug 28, 2023
·
detection.emerging_threats
attack.execution
attack.defense_evasion
attack.impact
attack.t1485
attack.t1498
attack.t1059.001
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation Attempt Of Undocumented WindowsServer RCE
calendar
Aug 28, 2023
·
detection.emerging_threats
attack.initial_access
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
ProxyLogon Reset Virtual Directories Based On IIS Log
calendar
Aug 28, 2023
·
cve.2021.26858
detection.emerging_threats
attack.initial_access
attack.t1190
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Account Name Change CVE-2021-42287
calendar
Aug 28, 2023
·
cve.2021.42287
detection.emerging_threats
attack.defense_evasion
attack.persistence
attack.t1036
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Devil Bait Potential C2 Communication Traffic
calendar
Aug 23, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-21554 QueueJumper Exploitation
calendar
Aug 18, 2023
·
attack.privilege_escalation
attack.execution
cve.2023.21554
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-31979 CVE-2021-33771 Exploits
calendar
Aug 17, 2023
·
attack.credential_access
attack.t1566
attack.t1203
cve.2021.33771
cve.2021.31979
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Outlook Task/Note Reminder Received
calendar
Aug 17, 2023
·
attack.persistence
attack.t1137
cve.2023.23397
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL RAT Windows User Creation
calendar
Aug 17, 2023
·
attack.persistence
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Encrypted Registry Blob Related To SNAKE Malware
calendar
Aug 17, 2023
·
attack.persistence
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware Registry Persistence
calendar
Aug 17, 2023
·
attack.persistence
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor Activity
calendar
Aug 2, 2023
·
attack.persistence
attack.t1574.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
NotPetya Ransomware Activity
calendar
Jun 21, 2023
·
attack.defense_evasion
attack.t1218.011
attack.t1070.001
attack.credential_access
attack.t1003.001
car.2016-04-002
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Adwind RAT / JRAT
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.005
attack.t1059.007
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Apache Spark Shell Command Injection - Weblogs
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.33891
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
APT PRIVATELOG Image Load Pattern
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1055
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
APT27 - Emissary Panda Activity
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1574.002
attack.g0027
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
APT29 2018 Phishing Campaign CommandLine Indicators
calendar
Jun 20, 2023
·
attack.execution
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
APT29 2018 Phishing Campaign File Indicators
calendar
Jun 20, 2023
·
attack.execution
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
APT31 Judgement Panda Activity
calendar
Jun 20, 2023
·
attack.lateral_movement
attack.credential_access
attack.g0128
attack.t1003.001
attack.t1560.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Arcadyan Router Exploitations
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.20090
cve.2021.20091
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Atlassian Bitbucket Command Injection Via Archive API
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.36804
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Blue Mockingbird
calendar
Jun 20, 2023
·
attack.execution
attack.t1112
attack.t1047
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Cisco ASA FTD Exploit CVE-2020-3452
calendar
Jun 20, 2023
·
attack.t1190
attack.initial_access
cve.2020.3452
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2020.8193
cve.2020.8195
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Citrix Netscaler Attack CVE-2019-19781
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2019.19781
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL Persistence Service Creation
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.persistence
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Anonymous User Process Execution
calendar
Jun 20, 2023
·
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Cleanup Command Execution
calendar
Jun 20, 2023
·
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Service Persistence Execution
calendar
Jun 20, 2023
·
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Confluence Exploitation CVE-2019-3398
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2019.3398
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Conti NTDS Exfiltration Command
calendar
Jun 20, 2023
·
attack.collection
attack.t1560
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Conti Volume Shadow Listing
calendar
Jun 20, 2023
·
attack.t1587.001
attack.resource_development
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2010-5278 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2010.5278
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-0688 Exchange Exploitation via Web Log
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2020.0688
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-0688 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2020.0688
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-10148 SolarWinds Orion API Auth Bypass
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2020.10148
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2020-5902 F5 BIG-IP Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2020.5902
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-1675 Print Spooler Exploitation
calendar
Jun 20, 2023
·
attack.execution
attack.t1569
cve.2021.1675
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-1675 Print Spooler Exploitation IPC Access
calendar
Jun 20, 2023
·
attack.execution
attack.t1569
cve.2021.1675
cve.2021.34527
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-21972 VSphere Exploitation
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.21972
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-21978 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.21978
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-33766 Exchange ProxyToken Exploitation
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.33766
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
attack.persistence
attack.t1505.003
cve.2021.40539
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-41773 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.41773
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2022-31656 VMware Workspace ONE Access Auth Bypass
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.31656
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2022-31659 VMware Workspace ONE Access RCE
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.31659
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
CVE-2023-23397 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.credential_access
attack.initial_access
cve.2023.23397
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
DarkSide Ransomware Pattern
calendar
Jun 20, 2023
·
attack.execution
attack.t1204
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Defrag Deactivation
calendar
Jun 20, 2023
·
attack.persistence
attack.t1053.005
attack.s0111
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Defrag Deactivation - Security
calendar
Jun 20, 2023
·
attack.persistence
attack.t1053
attack.s0111
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
DEWMODE Webshell Access
calendar
Jun 20, 2023
·
attack.persistence
attack.t1505.003
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
DNS RCE CVE-2020-1350
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
attack.execution
attack.t1569.002
cve.2020.1350
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Droppers Exploiting CVE-2017-11882
calendar
Jun 20, 2023
·
attack.execution
attack.t1203
attack.t1204.002
attack.initial_access
attack.t1566.001
cve.2017.11882
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Elise Backdoor Activity
calendar
Jun 20, 2023
·
attack.g0030
attack.g0050
attack.s0081
attack.execution
attack.t1059.003
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Equation Group DLL_U Export Function Load
calendar
Jun 20, 2023
·
attack.g0020
attack.defense_evasion
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
EvilNum APT Golden Chickens Deployment Via OCX Files
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exchange Exploitation CVE-2021-28480
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.28480
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exchange Exploitation Used by HAFNIUM
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploit for CVE-2015-1641
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1036.005
cve.2015.1641
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploit for CVE-2017-0261
calendar
Jun 20, 2023
·
attack.execution
attack.t1203
attack.t1204.002
attack.initial_access
attack.t1566.001
cve.2017.0261
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploit for CVE-2017-8759
calendar
Jun 20, 2023
·
attack.execution
attack.t1203
attack.t1204.002
attack.initial_access
attack.t1566.001
cve.2017.8759
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploitation of CVE-2021-26814 in Wazuh
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.21978
cve.2021.26814
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploited CVE-2020-10189 Zoho ManageEngine
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
attack.execution
attack.t1059.001
attack.t1059.003
attack.s0190
cve.2020.10189
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploiting CVE-2019-1388
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
cve.2019.1388
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Exploiting SetupComplete.cmd CVE-2019-1378
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
attack.execution
attack.t1059.003
attack.t1574
cve.2019.1378
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Fireball Archer Install
calendar
Jun 20, 2023
·
attack.execution
attack.defense_evasion
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Formbook Process Creation
calendar
Jun 20, 2023
·
attack.resource_development
attack.t1587.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Fortinet CVE-2018-13379 Exploitation
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2018.13379
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Fortinet CVE-2021-22123 Exploitation
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.22123
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
GALLIUM IOCs
calendar
Jun 20, 2023
·
attack.credential_access
attack.command_and_control
attack.t1212
attack.t1071
attack.g0093
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Goofy Guineapig Backdoor IOC
calendar
Jun 20, 2023
·
attack.execution
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Goofy Guineapig Backdoor Potential C2 Communication
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Goofy Guineapig Backdoor Service Creation
calendar
Jun 20, 2023
·
attack.persistence
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Grafana Path Traversal Exploitation CVE-2021-43798
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.43798
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Greenbug Espionage Group Indicators
calendar
Jun 20, 2023
·
attack.g0049
attack.execution
attack.t1059.001
attack.command_and_control
attack.t1105
attack.defense_evasion
attack.t1036.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Griffon Malware Attack Pattern
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
HAFNIUM Exchange Exploitation Activity
calendar
Jun 20, 2023
·
attack.persistence
attack.t1546
attack.t1053
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Hermetic Wiper TG Process Patterns
calendar
Jun 20, 2023
·
attack.execution
attack.lateral_movement
attack.t1021.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Lazarus Group Activity
calendar
Jun 20, 2023
·
attack.g0032
attack.execution
attack.t1059
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Lazarus System Binary Masquerading
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1036.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
LockerGoga Ransomware Activity
calendar
Jun 20, 2023
·
attack.impact
attack.t1486
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Log4j RCE CVE-2021-44228 Generic
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Log4j RCE CVE-2021-44228 in Fields
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.44228
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL Load By Compromised 3CXDesktopApp
calendar
Jun 20, 2023
·
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
MERCURY APT Activity
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.001
attack.g0069
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Mint Sandstorm - AsperaFaspex Suspicious Process Execution
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Mint Sandstorm - Log4J Wstomcat Process Execution
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Mint Sandstorm - ManageEngine Suspicious Process Execution
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Moriya Rootkit File Created
calendar
Jun 20, 2023
·
attack.persistence
attack.privilege_escalation
attack.t1543.003
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Mustang Panda Dropper
calendar
Jun 20, 2023
·
attack.t1587.001
attack.resource_development
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Activity
calendar
Jun 20, 2023
·
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense_evasion
attack.t1112
attack.command_and_control
attack.t1071.004
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - Security
calendar
Jun 20, 2023
·
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense_evasion
attack.t1112
attack.command_and_control
attack.t1071.004
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - System
calendar
Jun 20, 2023
·
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense_evasion
attack.t1112
attack.command_and_control
attack.t1071.004
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity
calendar
Jun 20, 2023
·
attack.discovery
attack.t1012
attack.defense_evasion
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity - Security
calendar
Jun 20, 2023
·
attack.discovery
attack.t1012
attack.defense_evasion
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Oracle WebLogic Exploit
calendar
Jun 20, 2023
·
attack.t1190
attack.initial_access
attack.persistence
attack.t1505.003
cve.2018.2894
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Oracle WebLogic Exploit CVE-2020-14882
calendar
Jun 20, 2023
·
attack.t1190
attack.initial_access
cve.2020.14882
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Oracle WebLogic Exploit CVE-2021-2109
calendar
Jun 20, 2023
·
attack.t1190
attack.initial_access
cve.2021.2109
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
OWASSRF Exploitation Attempt Using Public POC - Webserver
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
PaperCut MF/NG Exploitation Related Indicators
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
PaperCut MF/NG Potential Exploitation
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor File Indicators
calendar
Jun 20, 2023
·
attack.persistence
attack.t1574.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Possible CVE-2021-1675 Print Spooler Exploitation
calendar
Jun 20, 2023
·
attack.execution
attack.t1569
cve.2021.1675
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential ACTINIUM Persistence Activity
calendar
Jun 20, 2023
·
attack.persistence
attack.t1053
attack.t1053.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential APT FIN7 POWERHOLD Execution
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential APT FIN7 Reconnaissance/POWERTRASH Related Activity
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential APT FIN7 Related PowerShell Script Created
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential APT Mustang Panda Activity Against Australian Gov
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1218.010
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential APT10 Cloud Hopper Activity
calendar
Jun 20, 2023
·
attack.execution
attack.g0045
attack.t1059.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.execution
attack.t1190
attack.t1059
cve.2021.26084
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Baby Shark Malware Activity
calendar
Jun 20, 2023
·
attack.execution
attack.defense_evasion
attack.discovery
attack.t1012
attack.t1059.003
attack.t1059.001
attack.t1218.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential BearLPE Exploitation
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1053.005
car.2013-08-001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Bumblebee Remote Thread Creation
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.execution
attack.t1218.011
attack.t1059.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Centos Web Panel Exploitation Attempt - CVE-2022-44877
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.44877
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL Persistence Service DLL Creation
calendar
Jun 20, 2023
·
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL Persistence Service DLL Load
calendar
Jun 20, 2023
·
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL RAT File Indicators
calendar
Jun 20, 2023
·
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Beaconing Activity - DNS
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Beaconing Activity - Proxy
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Execution
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1218
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp ICO C2 File Download
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Update Activity
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1218
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Conti Ransomware Activity
calendar
Jun 20, 2023
·
attack.impact
attack.s0575
attack.t1486
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Conti Ransomware Database Dumping Activity Via SQLCmd
calendar
Jun 20, 2023
·
attack.collection
attack.t1005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-26857 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.t1203
attack.execution
cve.2021.26857
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-27905 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.27905
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-40444 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.execution
attack.t1059
cve.2021.40444
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-41379 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
cve.2021.41379
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-42278 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.credential_access
attack.t1558.003
cve.2021.42278
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2022-21587 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.21587
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2022-26809 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
attack.execution
attack.t1569.002
cve.2022.26809
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2022-29072 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.execution
cve.2022.29072
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2022-46169 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.46169
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-2283 Exploitation
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2023.2283
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-23397 Exploitation Attempt - SMB
calendar
Jun 20, 2023
·
attack.exfiltration
cve.2023.23397
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-23752 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2023.23752
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-25157 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
cve.2023.25157
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-25717 Exploitation Attempt
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2023.25717
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Devil Bait Malware Reconnaissance
calendar
Jun 20, 2023
·
attack.execution
attack.t1218
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Devil Bait Related Indicator
calendar
Jun 20, 2023
·
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Dridex Activity
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.privilege_escalation
attack.t1055
attack.discovery
attack.t1135
attack.t1033
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Dtrack RAT Activity
calendar
Jun 20, 2023
·
attack.impact
attack.t1490
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Emotet Activity
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.001
attack.defense_evasion
attack.t1027
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Emotet Rundll32 Execution
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential EmpireMonkey Activity
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1218.010
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation Attempt From Office Application
calendar
Jun 20, 2023
·
attack.execution
attack.defense_evasion
cve.2021.40444
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Goofy Guineapig Backdoor Activity
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Goofy Guineapig GoolgeUpdate Process Anomaly
calendar
Jun 20, 2023
·
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Ke3chang/TidePool Malware Activity
calendar
Jun 20, 2023
·
attack.g0004
attack.defense_evasion
attack.t1562.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Maze Ransomware Activity
calendar
Jun 20, 2023
·
attack.execution
attack.t1204.002
attack.t1047
attack.impact
attack.t1490
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential MOVEit Transfer CVE-2023-34362 Exploitation
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2023.34362
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential MuddyWater APT Activity
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.execution
attack.g0069
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Operation Triangulation C2 Beaconing Activity - DNS
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Operation Triangulation C2 Beaconing Activity - Proxy
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential OWASSRF Exploitation Attempt - Webserver
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential PlugX Activity
calendar
Jun 20, 2023
·
attack.s0013
attack.defense_evasion
attack.t1574.002
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential POWERTRASH Script Execution
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Qakbot Rundll32 Execution
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential QBot Activity
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Dot Ending File
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Russian APT Credential Theft Activity
calendar
Jun 20, 2023
·
attack.credential_access
attack.t1552.001
attack.t1003.003
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Ryuk Ransomware Activity
calendar
Jun 20, 2023
·
attack.persistence
attack.t1547.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential SNAKE Malware Installation Binary Indicator
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential SNAKE Malware Installation CLI Arguments Indicator
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential SNAKE Malware Persistence Service Execution
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Snatch Ransomware Activity
calendar
Jun 20, 2023
·
attack.execution
attack.t1204
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Child Process Of 3CXDesktopApp
calendar
Jun 20, 2023
·
attack.command_and_control
attack.execution
attack.t1218
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Potential SystemNightmare Exploitation Attempt
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1068
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Ps.exe Renamed SysInternals Tool
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.g0035
attack.t1036.003
car.2013-05-009
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Pulse Connect Secure RCE Attack CVE-2021-22893
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.22893
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Pulse Secure Attack CVE-2019-11510
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2019.11510
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Regsvr32 Calc Pattern
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Rundll32 Exports Execution
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Rundll32 Fake DLL Extension Execution
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Rejetto HTTP File Server RCE
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
attack.t1505.003
cve.2014.6287
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
REvil Kaseya Incident Malware Patterns
calendar
Jun 20, 2023
·
attack.execution
attack.t1059
attack.g0115
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Rhadamanthys Stealer Module Launch Via Rundll32.EXE
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1218.011
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Rorschach Ransomware Execution Activity
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.003
attack.t1059.001
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Serv-U Exploitation CVE-2021-35211 by DEV-0322
calendar
Jun 20, 2023
·
attack.persistence
attack.t1136.001
cve.2021.35211
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Sitecore Pre-Auth RCE CVE-2021-42237
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.42237
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware CommandLine Indicator
calendar
Jun 20, 2023
·
attack.persistence
attack.t1574.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware File Indicator Creation
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1036.005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware Potential C2 Communication
calendar
Jun 20, 2023
·
attack.command_and_control
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
SNAKE Malware Covert Store Registry Key
calendar
Jun 20, 2023
·
attack.persistence
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
SNAKE Malware Installer Name Indicators
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
SNAKE Malware Kernel Driver File Indicator
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
SNAKE Malware Service Persistence
calendar
Jun 20, 2023
·
attack.persistence
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
SNAKE Malware WerFault Persistence File Creation
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Sofacy Trojan Loader Activity
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.execution
attack.g0007
attack.t1059.003
attack.t1218.011
car.2013-10-002
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Solarwinds SUPERNOVA Webshell Access
calendar
Jun 20, 2023
·
attack.persistence
attack.t1505.003
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
SonicWall SSL/VPN Jarrewrite Exploitation
calendar
Jun 20, 2023
·
attack.t1190
attack.initial_access
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
SOURGUM Actor Behaviours
calendar
Jun 20, 2023
·
attack.t1546
attack.t1546.015
attack.persistence
attack.privilege_escalation
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Successful Exchange ProxyShell Attack
calendar
Jun 20, 2023
·
attack.initial_access
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PrinterPorts Creation (CVE-2020-1048)
calendar
Jun 20, 2023
·
attack.persistence
attack.execution
attack.t1059.001
cve.2020.1048
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RazerInstaller Explorer Subprocess
calendar
Jun 20, 2023
·
attack.privilege_escalation
attack.t1553
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious VBScript UN2452 Pattern
calendar
Jun 20, 2023
·
attack.persistence
attack.t1547.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
TAIDOOR RAT DLL Load
calendar
Jun 20, 2023
·
attack.execution
attack.t1055.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
TerraMaster TOS CVE-2020-28188
calendar
Jun 20, 2023
·
attack.t1190
attack.initial_access
cve.2020.28188
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Trickbot Malware Activity
calendar
Jun 20, 2023
·
attack.execution
attack.t1559
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
TropicTrooper Campaign November 2018
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Commands May 2020
calendar
Jun 20, 2023
·
attack.g0010
attack.execution
attack.t1059.001
attack.t1053.005
attack.t1027
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Lateral Movement
calendar
Jun 20, 2023
·
attack.g0010
attack.execution
attack.t1059
attack.lateral_movement
attack.t1021.002
attack.discovery
attack.t1083
attack.t1135
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC2452 PowerShell Pattern
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.001
attack.t1047
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC2452 Process Creation Patterns
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Barracuda ESG Exploitation Indicators
calendar
Jun 20, 2023
·
attack.execution
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Download Compressed Files From Temp.sh Using Wget
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1140
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Download Tar File From Untrusted Direct IP Via Wget
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1140
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Email Exfiltration File Pattern
calendar
Jun 20, 2023
·
attack.execution
attack.persistence
attack.defense_evasion
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Potential SEASPY Execution
calendar
Jun 20, 2023
·
attack.execution
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - SSL Certificate Exfiltration Via Openssl
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1140
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
VMware vCenter Server File Upload CVE-2021-22005
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2021.22005
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
WannaCry Ransomware Activity
calendar
Jun 20, 2023
·
attack.lateral_movement
attack.t1210
attack.discovery
attack.t1083
attack.defense_evasion
attack.t1222.001
attack.impact
attack.t1486
attack.t1490
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Winnti Malware HK University Campaign
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1574.002
attack.g0044
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Winnti Pipemon Characteristics
calendar
Jun 20, 2023
·
attack.defense_evasion
attack.t1574.002
attack.g0044
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
Zimbra Collaboration Suite Email Server Unauthenticated RCE
calendar
Jun 20, 2023
·
attack.initial_access
attack.t1190
cve.2022.27925
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
ZxShell Malware
calendar
Jun 20, 2023
·
attack.execution
attack.t1059.003
attack.defense_evasion
attack.t1218.011
attack.s0412
attack.g0001
detection.emerging_threats
·
Share on:
twitter
facebook
linkedin
copy
to-top